The Breach News

CISA Alerts on Threat Actors Using F5 BIG-IP Cookies for Network Reconnaissance

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding malicious actors exploiting unencrypted persistent cookies from the F5 BIG-IP Local Traffic Manager (LTM) module for reconnaissance within target networks. This technique enables attackers to identify additional non-internet-facing devices, raising significant concerns about potential vulnerabilities in those systems.…

Read MoreCISA Alerts on Threat Actors Using F5 BIG-IP Cookies for Network Reconnaissance

Pakistan-Linked Hackers Target Indian Power Company Using ReverseRat

New research reveals a sophisticated cyber campaign orchestrated by an actor with suspected connections to Pakistan, targeting government and energy sectors in South and Central Asia. The threat actor has primarily focused on deploying a remote access Trojan on compromised Windows systems, aimed at infiltrating sensitive networks. According to a…

Read MorePakistan-Linked Hackers Target Indian Power Company Using ReverseRat

Wipers Deployed by Russia’s Ruthless Hackers Cause Havoc in Ukraine

One of the most formidable hacking entities globally, the Russian state-backed group known as Sandworm, has executed a series of destructive cyberattacks amid the ongoing conflict with Ukraine, according to recent findings released by cybersecurity researchers. In April, Sandworm specifically targeted a Ukrainian university with dual wipers—malicious software designed to…

Read MoreWipers Deployed by Russia’s Ruthless Hackers Cause Havoc in Ukraine

Microsoft and Okta Acknowledge Breach Linked to LAPSUS$ Extortion Group

On Tuesday, Microsoft publicly acknowledged that the LAPSUS$ hacking group had achieved “limited access” to its systems, coinciding with a revelation from Okta, an identity authentication services provider, indicating that nearly 2.5% of its customer base may have been affected by the breach. Microsoft’s Threat Intelligence Center (MSTIC) confirmed that…

Read MoreMicrosoft and Okta Acknowledge Breach Linked to LAPSUS$ Extortion Group

OTsec India Organizers Offer Insights on Operational Technology Security

Governance & Risk Management, Operational Technology (OT) OTsec India Steering Committee Examines Cyberthreats, Compliance Challenges, and Innovation Opportunities Joshua Cunningham-Marsh, Matthew Robertson • November 6, 2025 The OTsec India Summit is a pivotal two-day event bringing together over 200 leaders in IT and OT security from India’s essential infrastructure and…

Read MoreOTsec India Organizers Offer Insights on Operational Technology Security

Local Authority Accidentally Reveals Hundreds of Consultation Respondents’ Information – PublicTechnology

Local Authority Unintentionally Exposes Hundreds of Consultation Respondents’ Information In a significant breach of privacy, a local authority has inadvertently released personal details of hundreds of individuals who provided responses to a public consultation. This incident has raised serious concerns regarding data protection and the safeguarding of sensitive information in…

Read MoreLocal Authority Accidentally Reveals Hundreds of Consultation Respondents’ Information – PublicTechnology

Exploitation of Critical Veeam Vulnerability Fuels Spread of Akira and Fog Ransomware

Recent cybersecurity reports indicate that threat actors are actively exploiting a critical security vulnerability in Veeam Backup & Replication software to deploy ransomware variants such as Akira and Fog. Sophos, a recognized cybersecurity vendor, has noted ongoing attacks that utilize compromised VPN credentials alongside the CVE-2024-40711 vulnerability to gain unauthorized…

Read MoreExploitation of Critical Veeam Vulnerability Fuels Spread of Akira and Fog Ransomware

Caution! Zyxel Firewalls and VPNs Targeted by Active Cyberattacks

Zyxel Networks, a Taiwanese provider of networking equipment, has issued a critical alert regarding a series of attacks targeting select security appliances, specifically firewalls and VPN servers. This warning highlights a sophisticated threat actor employing targeted strategies against devices with remote management or SSL VPN functionalities enabled. According to Zyxel,…

Read MoreCaution! Zyxel Firewalls and VPNs Targeted by Active Cyberattacks

Cavalry Werewolf Compromises Russian Government with New ShellNET Backdoor

Cybersecurity experts at Doctor Web have identified a targeted cyberattack directed at a Russian government-owned entity by a hacker group identified as Cavalry Werewolf. This operation came to light in July 2025, when the organization recognized spam emails originating from its corporate address, prompting an extensive internal inquiry. Doctor Web’s…

Read MoreCavalry Werewolf Compromises Russian Government with New ShellNET Backdoor