The Breach News

US Investment in Spyware is Soaring

The recent report emphasizes the significant yet often overlooked role of resellers and brokers in the spyware supply chain, describing this group as “a notably under-researched set of actors.” These intermediaries are said to obscure the relationships among vendors, suppliers, and buyers, frequently facilitating connections to emerging regional markets. Sarah…

Read MoreUS Investment in Spyware is Soaring

China’s Cybersecurity Authority Fines Dior for Breach of Customer Data Transfer Regulations

On September 10, the Cyberspace Administration of China announced administrative sanctions against Dior’s Shanghai branch, a luxury brand owned by LVMH. This action stems from the unauthorized transfer of customers’ personal data to the company’s headquarters in France, highlighting significant compliance lapses in data protection practices. The investigation into Dior…

Read MoreChina’s Cybersecurity Authority Fines Dior for Breach of Customer Data Transfer Regulations

SpotBugs Access Token Theft Found to Be the Main Cause of GitHub Supply Chain Attack

A sophisticated supply chain attack initially aimed at Coinbase has now been linked to a wider campaign targeting users of the “tj-actions/changed-files” GitHub Action. This breach is believed to have originated from the theft of a personal access token (PAT) connected to the SpotBugs project, unveiled by Palo Alto Networks’…

Read MoreSpotBugs Access Token Theft Found to Be the Main Cause of GitHub Supply Chain Attack

US Federal Authorities Indict Hacker Behind LockerGoga and MegaCortex Ransomware Attacks

Fraud Management & Cybercrime, Ransomware State Department Offers Up to $10M for Information on Cybercriminal Volodymyr Tymoshchuk David Perera (@daveperera) • September 9, 2025 Image: US Department of State/Shutterstock/ISMG Federal prosecutors announced the indictment of a hacker linked to the LockerGoga and MegaCortex ransomware strains, presenting a seven-count criminal case…

Read MoreUS Federal Authorities Indict Hacker Behind LockerGoga and MegaCortex Ransomware Attacks

Cindy Cohn Steps Down from EFF, But Continues to Champion Digital Rights

Cindy Cohn Steps Down as EFF Executive Director After 25 Years of Advocacy Cindy Cohn, a prominent defender of digital rights, announced her departure from the role of executive director at the Electronic Frontier Foundation (EFF) on Tuesday. Having led the San Francisco-based nonprofit since 2015, Cohn’s resignation marks the…

Read MoreCindy Cohn Steps Down from EFF, But Continues to Champion Digital Rights

Edelson Lechtzin LLP Investigates Data Breach Claims for Cornwell Quality Tools Customers

NEWTOWN, Pa., Sept. 9, 2025 /PRNewswire/ — The law firm Edelson Lechtzin LLP is currently investigating data privacy concerns stemming from a breach at Cornwell Quality Tools. The firm reported that Cornwell became aware of unauthorized data access around December 20, 2024. Business owners and individuals affected by this incident…

Read MoreEdelson Lechtzin LLP Investigates Data Breach Claims for Cornwell Quality Tools Customers

Microsoft Acknowledges EncryptHub, the Hacker Connected to Over 618 Breaches, for Revealing Windows Vulnerabilities

Microsoft recently acknowledged an individual operating under the EncryptHub alias for uncovering and reporting two significant security vulnerabilities in Windows. This acknowledgment depicts a complex profile of a person straddling a legitimate cybersecurity career while engaging in cybercriminal activities. According to a detailed analysis by Outpost24 KrakenLabs, the individual behind…

Read MoreMicrosoft Acknowledges EncryptHub, the Hacker Connected to Over 618 Breaches, for Revealing Windows Vulnerabilities