The Breach News

Prilex PoS Malware Adapts to Intercept Contactless Payments and Steal NFC Card Data

A new variant of the advanced point-of-sale (PoS) malware known as Prilex has emerged from Brazilian cybercriminals, introducing capabilities to disrupt contactless payment transactions. This follows the trend of malware evolution, as Prilex has shifted focus from ATM targeting to sophisticated PoS infiltration since its inception in 2014. According to…

Read MorePrilex PoS Malware Adapts to Intercept Contactless Payments and Steal NFC Card Data

Integrating Cybersecurity and Biosecurity through Threat Modeling

Endpoint Security, Geo Focus: Australia, Geo-Specific A Structured Approach to Address Vulnerabilities in Synthetic Biology Laboratories Maryam Shoraka • September 3, 2025 The rapid development of synthetic biology offers significant societal benefits, from bacteria engineered to degrade environmental pollutants to synthetic microbes that can create vital medicines. However, these advancements…

Read MoreIntegrating Cybersecurity and Biosecurity through Threat Modeling

Blind Eagle Exploits NTLM Vulnerability in Colombian Institutions with RATs and GitHub-Centric Tactics

Since November 2024, threat actor Blind Eagle has executed a series of sophisticated campaigns primarily aimed at Colombian institutions and government bodies. These operations have demonstrated a high rate of infection, targeting critical infrastructure and private organizations alike. According to Check Point’s recent analysis, the campaigns resulted in more than…

Read MoreBlind Eagle Exploits NTLM Vulnerability in Colombian Institutions with RATs and GitHub-Centric Tactics

Commvault Introduces New Hyperscale Solutions to Strengthen On-Site Cyber Resilience

Commvault, a prominent player in cyber resilience and data protection solutions for hybrid cloud environments, has recently expanded its HyperScale portfolio with the introduction of HyperScale Edge and HyperScale Flex. These solutions aim to address the growing data security concerns of modern enterprises operating in remote offices and edge environments—locations…

Read MoreCommvault Introduces New Hyperscale Solutions to Strengthen On-Site Cyber Resilience

OttoKit WordPress Plugin Admin Creation Vulnerability Actively Being Exploited

A newly uncovered, high-severity vulnerability affects the OttoKit plugin for WordPress, formerly known as SureTriggers. This flaw has reportedly been exploited within mere hours of its public disclosure, posing a significant risk to website security. Identified as CVE-2025-3102, this vulnerability carries a CVSS score of 8.1 due to an authorization…

Read MoreOttoKit WordPress Plugin Admin Creation Vulnerability Actively Being Exploited

GuLoader Malware Targets E-Commerce Sector Using Harmful NSIS Executables

Cybersecurity firm Trellix recently reported a sustained malware campaign targeting e-commerce sectors in South Korea and the United States, attributed to a new wave of GuLoader attacks. This malware campaign signifies a shift in tactics from the previously used malware-laden Microsoft Word documents to NSIS executable files for malware deployment.…

Read MoreGuLoader Malware Targets E-Commerce Sector Using Harmful NSIS Executables

When Giving Up Isn’t an Option

Critical Infrastructure Security, Governance & Risk Management, Operational Technology (OT) Enhancing OT Cybersecurity Skills Through Education and Collaboration Brandy Harris • September 3, 2025 Image: Shutterstock As the cybersecurity landscape evolves, many professionals entering the field find their training predominantly focused on IT systems, safeguarding data centers, and managing corporate…

Read MoreWhen Giving Up Isn’t an Option

Salesloft Drift Breach Linked to GitHub Security Breach and Compromised OAuth Tokens

Recent data breaches have raised concerns about security within popular applications, particularly the use of the Salesloft Drift application to compromise Salesforce data. In an important update, Salesloft has reported that the security incident has been addressed, with containment measures and customer protections now in effect. To investigate the breach,…

Read MoreSalesloft Drift Breach Linked to GitHub Security Breach and Compromised OAuth Tokens

Coordinated Cyber Attack Involves Exploitation of Multiple SSRF Vulnerabilities by Over 400 IPs

Surge in Server-Side Request Forgery Exploits Detected Across Multiple Platforms GreyNoise, a threat intelligence firm, has issued an alarming warning regarding a “coordinated surge” in the exploitation of Server-Side Request Forgery (SSRF) vulnerabilities across various platforms. This uptick, first identified on March 9, 2025, is particularly notable for involving at…

Read MoreCoordinated Cyber Attack Involves Exploitation of Multiple SSRF Vulnerabilities by Over 400 IPs