The Breach News

Security Vulnerabilities in CocoaPods Risk iOS and macOS Apps to Supply Chain Attacks

A significant security vulnerability has been discovered within the CocoaPods dependency manager, critical for Swift and Objective-C Cocoa projects. This flaw has the potential to facilitate software supply chain attacks, posing serious threats to downstream users. Researchers from E.V.A Information Security reported that these vulnerabilities could allow malicious actors to…

Read MoreSecurity Vulnerabilities in CocoaPods Risk iOS and macOS Apps to Supply Chain Attacks

New Mispadu Banking Trojan Takes Advantage of Windows SmartScreen Vulnerability

The Mispadu banking Trojan has been identified as leveraging a recently patched vulnerability in Windows SmartScreen to target users in Mexico. This malware, which first appeared in 2019, has evolved into a new variant that cybercriminals are utilizing to gain unlawful access to sensitive information. According to a report from…

Read MoreNew Mispadu Banking Trojan Takes Advantage of Windows SmartScreen Vulnerability

Attackers Leverage Critical Zimbra Vulnerability Through CC’d Email Addresses

Attackers are leveraging a serious vulnerability in Zimbra mail servers, which are commonly used by medium and large organizations, to carry out remote code execution attacks. This flaw, designated as CVE-2024-45519, allows attackers to execute malicious commands if an administrator has altered the default settings to enable the postjournal service.…

Read MoreAttackers Leverage Critical Zimbra Vulnerability Through CC’d Email Addresses

Detection, Prevention, and Notification of Data Breaches

Please complete the fields below: Select CountryUnited StatesCanadaIndiaAfghanistanAlbaniaAlgeriaAmerican SamoaAndorraAngolaAnguillaAntigua & BarbudaArgentinaArmeniaArubaAustraliaAustriaAzerbaijanBahamasBahrainBangladeshBarbadosBelarusBelgiumBelizeBeninBermudaBhutanBoliviaBosnia & HerzegovinaBotswanaBrazilBritish Virgin IslandsBruneiBulgariaBurkina FasoBurundiCambodiaCameroonCape VerdeCayman IslandsCentral African RepublicChadChileChinaColombiaComorosCook IslandsCosta RicaCôte d’IvoireCroatiaCubaCyprusCzechiaDemocratic Republic of the CongoDenmarkDjiboutiDominicaDominican RepublicEcuadorEgyptEl SalvadorEquatorial GuineaEritreaEstoniaEswatiniEthiopiaFaroe IslandsFijiFinlandFranceFrench GuianaFrench PolynesiaGabonGambiaGeorgiaGermanyGhanaGibraltarGreeceGreenlandGrenadaGuadeloupeGuamGuatemalaGuineaGuinea-BissauGuyanaHaitiHondurasHong KongHungaryIcelandIndonesiaIranIraqIrelandIsraelItalyJamaicaJapanJordanKazakhstanKenyaKiribatiKosovoKuwaitKyrgyzstanLaosLatviaLebanonLesothoLiberiaLibyaLiechtensteinLithuaniaLuxembourgMacaoMadagascarMalawiMalaysiaMaldivesMaliMaltaMarshall IslandsMartiniqueMauritaniaMauritiusMayotteMexicoMicronesiaMoldovaMonacoMongoliaMontserratMoroccoMozambiqueMyanmar (Burma)NamibiaNauruNepalNetherlandsNew CaledoniaNew ZealandNicaraguaNigerNigeriaNiueNorth MacedoniaNorthern Mariana IslandsNorwayOmanPakistanPalauPanamaPapua New GuineaParaguayPeruPhilippinesPolandPortugalPuerto RicoQatarRomaniaRussiaRwandaSamoaSan MarinoSão Tomé & PríncipeSaudi ArabiaSenegalSerbiaSeychellesSierra LeoneSingaporeSlovakiaSloveniaSolomon…

Read MoreDetection, Prevention, and Notification of Data Breaches

Fortnum & Mason Data Breach Exposes Personal Details of 23,000 Customers

Data Breach at Fortnum & Mason Exposes Customer Information In a significant cybersecurity incident, Fortnum & Mason, the esteemed British food retailer known as the "Queen’s grocer," has reported unauthorized access to the personal data of approximately 23,000 customers. This breach stems from a vulnerability in a survey form hosted…

Read MoreFortnum & Mason Data Breach Exposes Personal Details of 23,000 Customers

Internet Archive Hit by Another Breach Due to Unrotated API Tokens Exploited by Hackers

The Internet Archive has recently experienced another cyber intrusion, marking the third significant security breach in October 2024. On October 20, threat actors managed to exploit unrotated API tokens, gaining unauthorized access to the organization’s Zendesk support platform and potentially exposing sensitive user information. This breach follows two earlier attacks…

Read MoreInternet Archive Hit by Another Breach Due to Unrotated API Tokens Exploited by Hackers

Chinese Hackers Utilizing Zero-Day Vulnerability in Cisco Switches to Distribute Malware

Recent reports indicate that a cyber espionage group with connections to China, known as Velvet Ant, has been exploiting a zero-day vulnerability in Cisco’s NX-OS Software utilized in their switching devices to execute malware. This security gap, identified as CVE-2024-20399 with a CVSS score of 6.0, involves a command injection…

Read MoreChinese Hackers Utilizing Zero-Day Vulnerability in Cisco Switches to Distribute Malware

Patchwork Utilizes Romance Scam Tactics to Deploy VajraSpy Malware on Android Devices

Malware Alert: Romance Scams Target Android Users in South Asia A sophisticated cyber threat, linked to the threat actor known as Patchwork, has emerged, predominantly targeting victims in Pakistan and India through deceptive romance scams. This illicit scheme has reportedly utilized a remote access trojan (RAT) named VajraSpy, specifically designed…

Read MorePatchwork Utilizes Romance Scam Tactics to Deploy VajraSpy Malware on Android Devices

69,000 Bitcoins Bound for US Treasury as Seizing Agent Remains in Jail

In a notable case beginning in November 2020, an individual known only as “Individual X” engaged with an IRS agent, Tigran Gambaryan, alongside prosecutors from the U.S. Attorney’s office in San Francisco. This unnamed party entered a Bitcoin private key into Gambaryan’s laptop, facilitating the transfer of 69,370 bitcoins from…

Read More69,000 Bitcoins Bound for US Treasury as Seizing Agent Remains in Jail