The Breach News

Commvault Introduces New Hyperscale Solutions to Strengthen On-Site Cyber Resilience

Commvault, a prominent player in cyber resilience and data protection solutions for hybrid cloud environments, has recently expanded its HyperScale portfolio with the introduction of HyperScale Edge and HyperScale Flex. These solutions aim to address the growing data security concerns of modern enterprises operating in remote offices and edge environments—locations…

Read MoreCommvault Introduces New Hyperscale Solutions to Strengthen On-Site Cyber Resilience

OttoKit WordPress Plugin Admin Creation Vulnerability Actively Being Exploited

A newly uncovered, high-severity vulnerability affects the OttoKit plugin for WordPress, formerly known as SureTriggers. This flaw has reportedly been exploited within mere hours of its public disclosure, posing a significant risk to website security. Identified as CVE-2025-3102, this vulnerability carries a CVSS score of 8.1 due to an authorization…

Read MoreOttoKit WordPress Plugin Admin Creation Vulnerability Actively Being Exploited

GuLoader Malware Targets E-Commerce Sector Using Harmful NSIS Executables

Cybersecurity firm Trellix recently reported a sustained malware campaign targeting e-commerce sectors in South Korea and the United States, attributed to a new wave of GuLoader attacks. This malware campaign signifies a shift in tactics from the previously used malware-laden Microsoft Word documents to NSIS executable files for malware deployment.…

Read MoreGuLoader Malware Targets E-Commerce Sector Using Harmful NSIS Executables

When Giving Up Isn’t an Option

Critical Infrastructure Security, Governance & Risk Management, Operational Technology (OT) Enhancing OT Cybersecurity Skills Through Education and Collaboration Brandy Harris • September 3, 2025 Image: Shutterstock As the cybersecurity landscape evolves, many professionals entering the field find their training predominantly focused on IT systems, safeguarding data centers, and managing corporate…

Read MoreWhen Giving Up Isn’t an Option

Salesloft Drift Breach Linked to GitHub Security Breach and Compromised OAuth Tokens

Recent data breaches have raised concerns about security within popular applications, particularly the use of the Salesloft Drift application to compromise Salesforce data. In an important update, Salesloft has reported that the security incident has been addressed, with containment measures and customer protections now in effect. To investigate the breach,…

Read MoreSalesloft Drift Breach Linked to GitHub Security Breach and Compromised OAuth Tokens

Coordinated Cyber Attack Involves Exploitation of Multiple SSRF Vulnerabilities by Over 400 IPs

Surge in Server-Side Request Forgery Exploits Detected Across Multiple Platforms GreyNoise, a threat intelligence firm, has issued an alarming warning regarding a “coordinated surge” in the exploitation of Server-Side Request Forgery (SSRF) vulnerabilities across various platforms. This uptick, first identified on March 9, 2025, is particularly notable for involving at…

Read MoreCoordinated Cyber Attack Involves Exploitation of Multiple SSRF Vulnerabilities by Over 400 IPs

The Overlooked Risks of Temporary Accounts in Cybersecurity

Understanding Ephemeral Accounts in Cybersecurity In the realm of cybersecurity audits, particularly those regarding compliance and cyber insurance, emphasis is placed on analyzing group memberships to discern access levels. This scrutiny typically reveals individuals with elevated privileges, including roles such as Domain Admin, Enterprise Admin, Local Administrator, Global Admin in…

Read MoreThe Overlooked Risks of Temporary Accounts in Cybersecurity

Palo Alto Networks Alerts Users to Brute-Force Attacks on PAN-OS GlobalProtect Gateways

Palo Alto Networks has alerted the cybersecurity community regarding ongoing brute-force login attempts directed at PAN-OS GlobalProtect gateways. This warning follows recent observations from threat hunters who noted an increase in suspicious login scanning activity targeting the company’s devices. A spokesperson from Palo Alto Networks commented that evidence exists of…

Read MorePalo Alto Networks Alerts Users to Brute-Force Attacks on PAN-OS GlobalProtect Gateways

VMware Discovers No Signs of 0-Day Vulnerabilities in Current ESXiArgs Ransomware Attacks

VMware Addresses Ransomware Attacks Targeting ESXi Servers On Monday, VMware announced that it has not detected any activity regarding the exploitation of an undisclosed zero-day vulnerability in its software amid a global wave of ransomware assaults. The company clarified that reports indicate attackers are primarily targeting End of General Support…

Read MoreVMware Discovers No Signs of 0-Day Vulnerabilities in Current ESXiArgs Ransomware Attacks