The Breach News

Sensitive Customer Data Exposed in Wealthsimple Security Breach

Wealthsimple Reports Security Breach Affecting Customers’ Personal Information Wealthsimple, a prominent FinTech company, has disclosed a security incident that compromised the personal information of certain customers following a breach on August 30. The firm has confirmed that significantly fewer than one percent of its 3 million clients were affected, which…

Read MoreSensitive Customer Data Exposed in Wealthsimple Security Breach

ASUS Acknowledges Serious Vulnerability in AiCloud Routers; Users Advised to Update Firmware Promptly

ASUS has revealed a significant security vulnerability affecting its routers with AiCloud functionality, exposing them to potential remote attacks that can lead to unauthorized execution of commands. This issue, designated as CVE-2025-2492, has attained a critical CVSS score of 9.2 out of 10, indicating a severe level of risk for…

Read MoreASUS Acknowledges Serious Vulnerability in AiCloud Routers; Users Advised to Update Firmware Promptly

Record-Breaking HTTP DDoS Attack Surges to 71 Million Requests Per Second

Cloudflare Discovers Record-Breaking DDoS Attack In a significant cybersecurity breach, Cloudflare announced on Monday that it successfully mitigated a massive distributed denial-of-service (DDoS) attack, which reached an unprecedented peak of over 71 million requests per second (RPS). This attack, labeled a “hyper-volumetric” DDoS assault, eclipses the previous record of 46…

Read MoreRecord-Breaking HTTP DDoS Attack Surges to 71 Million Requests Per Second

Hackers Transform Red Team AI Tool into Citrix Exploit Engine

Artificial Intelligence & Machine Learning, Next-Generation Technologies & Secure Development, The Future of AI & Cybersecurity HexStrike-AI Integrates LLMs with Over 150 Security Tools Rashmi Ramesh (rashmiramesh_) • September 5, 2025 Image: Shutterstock In a troubling development, hackers have swiftly adopted an open-source offensive security framework to exploit vulnerabilities in…

Read MoreHackers Transform Red Team AI Tool into Citrix Exploit Engine

Medusa Ransomware Employs Malicious Driver to Bypass Anti-Malware Using Stolen Certificates

Recent reports indicate that the Medusa ransomware-as-a-service (RaaS) group is employing a malicious driver named ABYSSWORKER in a sophisticated attack utilizing a bring your own vulnerable driver (BYOVD) strategy aimed at sabotaging anti-malware systems. According to Elastic Security Labs, a recent incident involving Medusa ransomware utilized a loader that had…

Read MoreMedusa Ransomware Employs Malicious Driver to Bypass Anti-Malware Using Stolen Certificates

Third-Party Salesforce Breach Affects Proofpoint, Tenable, and CyberArk – CRN Magazine

Proofpoint, Tenable, CyberArk Targeted in Salesforce Data Breach In a significant cybersecurity incident, Proofpoint, Tenable, and CyberArk have reportedly been affected by a breach stemming from a third-party vulnerability within Salesforce. This breach highlights the ongoing risks associated with third-party integrations in cloud-based platforms, raising concerns among organizations that rely…

Read MoreThird-Party Salesforce Breach Affects Proofpoint, Tenable, and CyberArk – CRN Magazine

Hackers Exploit Russian Bulletproof Host Proton66 for Worldwide Attacks and Malware Distribution

Recent cybersecurity research has revealed a significant increase in cyber threats linked to the Russian bulletproof hosting service, Proton66. Analysts have documented a variety of malicious activities that include mass scanning, credential brute-forcing, and exploitation attempts emanating from this provider, with the uptick in activity noted since January 8, 2025.…

Read MoreHackers Exploit Russian Bulletproof Host Proton66 for Worldwide Attacks and Malware Distribution

Chinese Hackers Target South American Diplomats Using ShadowPad

Cyber Espionage Suspected in South American Diplomatic Attacks On Monday, Microsoft announced it has linked a China-based cyber espionage group to a series of attacks targeting diplomatic organizations in South America. The tech conglomerate’s Security Intelligence team is closely monitoring this group under the identifier DEV-0147. They characterized the recent…

Read MoreChinese Hackers Target South American Diplomats Using ShadowPad

Shift5 Secures $75M for Cybersecurity Initiatives in Defense and Transportation

Government, Industry Specific, Next-Generation Technologies & Secure Development Startup Secures $75M to Expand Dual-Use Technology Against GPS Jamming Threats Michael Novinson (MichaelNovinson) • September 4, 2025 Ronak Shah, co-CTO of Shift5 (Image: Shift5) A cybersecurity startup focused on military and transportation security has successfully raised $75 million in funding aimed…

Read MoreShift5 Secures $75M for Cybersecurity Initiatives in Defense and Transportation