The Breach News

Fraudsters Infiltrate as ‘Ideal Borrowers,’ Leading to Significant Losses

Fraud Losses Reach Alarming Levels as Synthetic Identities Exploit Lending Systems Suparna Goswami (gsuparna) • October 16, 2025 Image: Shutterstock Auto lenders generally assess risk based on credit scores, positing that higher scores indicate lower potential for fraud. However, a recent report from TransUnion reveals a concerning trend: Superprime borrowers—those…

Read MoreFraudsters Infiltrate as ‘Ideal Borrowers,’ Leading to Significant Losses

CISA and FBI Issue Warnings on Exploited Vulnerabilities and Growing HiatusRAT Campaign

Recent Cybersecurity Alerts: CISA Highlights New Vulnerabilities; FBI Warns on IoT Threats The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced on Monday the addition of two significant vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, underscoring the active exploitation of these security flaws across various platforms. This proactive measure…

Read MoreCISA and FBI Issue Warnings on Exploited Vulnerabilities and Growing HiatusRAT Campaign

US Cyber Command Associates ‘MuddyWater’ Hacking Group with Iranian Intelligence

U.S. Cyber Command Links MuddyWater Group to Iranian Intelligence Activities On Wednesday, U.S. Cyber Command (USCYBERCOM) officially identified the MuddyWater cyber group as linked to Iran’s intelligence framework, shedding light on their sophisticated tactics and tools employed to infiltrate target networks. This announcement comes amid growing concerns over the escalating…

Read MoreUS Cyber Command Associates ‘MuddyWater’ Hacking Group with Iranian Intelligence

NK’s Notorious Chollima Exploits BeaverTail and OtterCookie Malware in Employment Scam

A recent report from Cisco Talos reveals that the North Korea-linked hacking group Famous Chollima is leveraging the job market to conduct cyberattacks. The group is utilizing fraudulent job postings to ensnare victims into downloading malicious software that enables the theft of cryptocurrency and user credentials. Merging Malware Threats Two…

Read MoreNK’s Notorious Chollima Exploits BeaverTail and OtterCookie Malware in Employment Scam

Exploring Silverfort’s Comprehensive Identity Protection Platform

Understanding Silverfort’s Unified Identity Protection Platform: A Comprehensive Overview In today’s evolving cybersecurity landscape, protecting an organization against identity-based attacks has become paramount. Silverfort has emerged as a key player with its Unified Identity Protection Platform, the first of its kind available in the market. This innovative platform leverages patented…

Read MoreExploring Silverfort’s Comprehensive Identity Protection Platform

Imprivata Acquires Verosint to Enhance Real-Time Identity Risk Detection

Next-Generation Technologies & Secure Development, Privileged Access Management, Security Operations Risk Scoring to Enable Real-Time Action by Imprivata on Suspicious Access Attempts Michael Novinson (MichaelNovinson) • October 15, 2025 Fran Rosch, CEO, Imprivata (Image: Imprivata) Imprivata has acquired Verosint, a startup specializing in identity threat detection and response. This strategic…

Read MoreImprivata Acquires Verosint to Enhance Real-Time Identity Risk Detection

Sensitive Customer Information Exposed in Mango Data Breach: What We Know So Far

Mango Faces Data Breach, Exposing Customer Information Mango, a global retail leader with over 2,500 branches in more than 120 countries, has recently experienced a data breach involving a third-party service provider, compromising sensitive customer information. The extent of the breach has not been fully disclosed, but Mango issued alerts…

Read MoreSensitive Customer Information Exposed in Mango Data Breach: What We Know So Far

BeyondTrust Releases Urgent Patch for Critical Vulnerability in PRA and RS Products

Critical Vulnerability Discovered in BeyondTrust Products BeyondTrust has announced a significant security vulnerability affecting its Privileged Remote Access (PRA) and Remote Support (RS) products. This flaw, designated as CVE-2024-12356 and assigned a high CVSS score of 9.8, poses a serious risk of arbitrary command execution, potentially allowing unauthenticated attackers to…

Read MoreBeyondTrust Releases Urgent Patch for Critical Vulnerability in PRA and RS Products