The Breach News

Lazarus Group Aims at Blockchain Professionals with Phony Video Conferencing and Job Scams

A recent report from Group-IB has drawn attention to the ongoing cyber campaign led by North Korea’s Lazarus Group, referred to as the “Eager Crypto Beavers” initiative. This group utilizes advanced strategies, including deceptive job postings and malicious video conferencing software, to spread malware effectively. The Lazarus Group, infamous for…

Read MoreLazarus Group Aims at Blockchain Professionals with Phony Video Conferencing and Job Scams

Feeld Dating App’s Lenient Security Exposes Private Data to Public Scrutiny – DataBreaches.net

In a recent disclosure, the Feeld dating app has come under scrutiny due to significant vulnerabilities that have compromised the privacy of its users. Reports indicate that sensitive user data has become unexpectedly accessible, raising alarms about the app’s security protocols. As a platform designed to facilitate connections between individuals…

Read MoreFeeld Dating App’s Lenient Security Exposes Private Data to Public Scrutiny – DataBreaches.net

Ivanti Issues Critical Security Updates for Endpoint Manager Vulnerabilities

Ivanti has announced the release of critical software updates aimed at addressing numerous security vulnerabilities within its Endpoint Manager (EPM) software. Among these flaws, 10 have been classified as critical, posing significant risks that could potentially lead to remote code execution. The updates are particularly crucial for users of EPM…

Read MoreIvanti Issues Critical Security Updates for Endpoint Manager Vulnerabilities

Cybercriminals Leverage Trendy Software Searches to Distribute FakeBat Malware

New Surge in Malware Infections Linked to FakeBat Loader Cybersecurity experts have reported a notable increase in malware infections attributable to malvertising campaigns that deploy a loader known as FakeBat. This malicious software targets individuals seeking popular business applications, a strategy that appears to be opportunistically designed to ensnare unsuspecting…

Read MoreCybercriminals Leverage Trendy Software Searches to Distribute FakeBat Malware

Trust, Teams, and Tragedy: The Ongoing Danger of Insider Threats

The perception of cybersecurity threats often conjures images of shadowy figures hunched over screens, orchestrating complex attacks from afar. While external hackers are frequently in the spotlight, internal threats, including employees or contractors, pose a significant challenge. Surprisingly, individuals within your organization can be among the most considerable risk factors…

Read MoreTrust, Teams, and Tragedy: The Ongoing Danger of Insider Threats

Microsoft Releases Patches for 79 Vulnerabilities, Featuring 3 Actively Exploited Windows Issues

Microsoft Addresses Critical Vulnerabilities in September 2024 Patch Tuesday Update On Tuesday, September 10, 2024, Microsoft announced the identification of three significant security vulnerabilities affecting the Windows operating system, which are now under active exploitation. This disclosure was part of the company’s monthly Patch Tuesday update, highlighting the urgent need…

Read MoreMicrosoft Releases Patches for 79 Vulnerabilities, Featuring 3 Actively Exploited Windows Issues

Styx Stealer Developer’s OPSEC Breach Exposes Client List and Profit Information

In a notable lapse in operational security (OPSEC), the operator behind the Styx Stealer information theft tool inadvertently leaked sensitive details from their own computer. This data breach exposed client information, profit margins, nicknames, phone numbers, and email addresses. Styx Stealer, emerged in April 2024, is considered a variant of…

Read MoreStyx Stealer Developer’s OPSEC Breach Exposes Client List and Profit Information

Vastaamo Data Leak Victims Pursue Increased Compensation – DataBreaches.net

Thousands of Vastaamo Leak Victims Seek Enhanced Compensation In a significant development regarding the Vastaamo data breach, thousands of victims are actively pursuing higher compensation for the personal data exposed during the incident. This breach, which came to light in late 2020, involved the unauthorized disclosure of sensitive patient information…

Read MoreVastaamo Data Leak Victims Pursue Increased Compensation – DataBreaches.net