The Breach News

GLOBAL GROUP Ransomware Alleges Breach of Media Conglomerate Albavisión

The ransomware collective known as GLOBAL GROUP has claimed responsibility for a significant security breach at Albavisión, a prominent Spanish-language media conglomerate headquartered in Miami, Florida. According to the group, they have successfully extracted 400 GB of sensitive data from the company. Having emerged in early June 2025, GLOBAL GROUP…

Read MoreGLOBAL GROUP Ransomware Alleges Breach of Media Conglomerate Albavisión

Corelight Leverages Generative AI for Enhanced Threat Detection

Artificial Intelligence & Machine Learning, Network Detection & Response, Next-Generation Technologies & Secure Development Enhancements in SaaS Target Network Detection and Response for Smaller Security Teams Michael Novinson (@MichaelNovinson) • July 28, 2025 Brian Dye, CEO of Corelight (Image: Corelight) In a recent address, Corelight CEO Brian Dye highlighted the…

Read MoreCorelight Leverages Generative AI for Enhanced Threat Detection

Severe Vulnerability in Wing FTP Server (CVE-2025-47812) Under Active Exploitation

July 11, 2025
Cyber Attack / Vulnerability Alert

A recently uncovered critical security vulnerability affecting Wing FTP Server is currently being exploited, as reported by Huntress. Known as CVE-2025-47812 (CVSS score: 10.0), this flaw involves improper handling of null (‘\0’) bytes within the server’s web interface, leading to potential remote code execution. The issue has been resolved in version 7.4.4. According to CVE.org’s advisory, “The user and admin web interfaces mishandle ‘\0’ bytes, allowing for the injection of arbitrary Lua code into user session files.” This can enable the execution of arbitrary system commands with the privileges of the FTP service, which defaults to root or SYSTEM. Alarmingly, the vulnerability can also be exploited through anonymous FTP accounts. A detailed analysis of this security issue became public in late June 2025, thanks to RCE Security researcher Julien Ahrens.

Critical Security Flaw in Wing FTP Server Under Active Attack On July 11, 2025, cybersecurity firm Huntress reported that a serious vulnerability in the Wing FTP Server, classified as CVE-2025-47812, is currently being exploited in the wild. This flaw bears a maximum CVSS score of 10.0, indicating its critical nature,…

Read More

Severe Vulnerability in Wing FTP Server (CVE-2025-47812) Under Active Exploitation

July 11, 2025
Cyber Attack / Vulnerability Alert

A recently uncovered critical security vulnerability affecting Wing FTP Server is currently being exploited, as reported by Huntress. Known as CVE-2025-47812 (CVSS score: 10.0), this flaw involves improper handling of null (‘\0’) bytes within the server’s web interface, leading to potential remote code execution. The issue has been resolved in version 7.4.4. According to CVE.org’s advisory, “The user and admin web interfaces mishandle ‘\0’ bytes, allowing for the injection of arbitrary Lua code into user session files.” This can enable the execution of arbitrary system commands with the privileges of the FTP service, which defaults to root or SYSTEM. Alarmingly, the vulnerability can also be exploited through anonymous FTP accounts. A detailed analysis of this security issue became public in late June 2025, thanks to RCE Security researcher Julien Ahrens.

Pro-Ukrainian Hackers Claim Responsibility for Disrupting Russian Air Travel

Aeroflot Faces Major Disruption Following Suspected Cyberattack On Monday, Aeroflot, Russia’s largest airline, experienced significant operational disruptions, cancelling approximately 40 flights due to what the airline referred to as a “technical failure.” However, multiple reports, aided by statements from Russian lawmakers and pro-Ukrainian hackers, have suggested that the root cause…

Read MorePro-Ukrainian Hackers Claim Responsibility for Disrupting Russian Air Travel

Russia’s National Airline Halts Flights Following Cyber Attack

Critical Infrastructure Security, Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Aeroflot Targeted by Belarusian Hackers Using Wiper Malware Mathew J. Schwartz (euroinfosec) • July 28, 2025 Image: Media_works/Shutterstock Aeroflot, Russia’s state-owned airline, has canceled numerous flights following a cyberattack attributed to a Belarusian hacking collective. The group, known as…

Read MoreRussia’s National Airline Halts Flights Following Cyber Attack

Enhancing Your CTEM Program: The Critical Role of Adversarial Exposure Validation (AEV)

Data Breach Notification, Data Security, Incident & Breach Response Seemant Sehgal • July 16, 2025 With 25 years of experience in the cybersecurity sector, I have witnessed firsthand the evolution of vulnerability management (VM) from traditional scanning methods to integrated cloud solutions. Historically, VM has been central to enterprise cybersecurity…

Read MoreEnhancing Your CTEM Program: The Critical Role of Adversarial Exposure Validation (AEV)