The Breach News

Toyota Faces Data Crisis as Hackers Release 240GB of Customer Information – Yahoo! Voices

Recently, Toyota has faced a significant data breach, which has resulted in the leak of an alarming 240GB of customer information. This incident underscores the growing cybersecurity threats that businesses are currently exposed to. As one of the world’s leading automotive manufacturers, Toyota has been a prime target for cybercriminals,…

Read MoreToyota Faces Data Crisis as Hackers Release 240GB of Customer Information – Yahoo! Voices

New PG_MEM Malware Targets PostgreSQL Databases for Cryptocurrency Mining

Cybersecurity experts have recently uncovered a new strain of malware known as PG_MEM, specifically designed to mine cryptocurrency by exploiting vulnerabilities in PostgreSQL database instances. This malicious software employs brute-force tactics, wherein attackers repeatedly attempt to guess the database credentials, typically targeting systems with weak passwords. According to Assaf Morag,…

Read MoreNew PG_MEM Malware Targets PostgreSQL Databases for Cryptocurrency Mining

19-jarige Amersfoorter voor de vierde keer aangehouden voor phishing – DataBreaches.net

In a concerning development for cybersecurity in the Netherlands, a 19-year-old resident of Amersfoort has been apprehended for his involvement in phishing activities for the fourth time. This continued behavior indicates a troubling pattern, underscoring the challenges many organizations face in the realm of cybersecurity. The young individual’s repeated offenses…

Read More19-jarige Amersfoorter voor de vierde keer aangehouden voor phishing – DataBreaches.net

Urgent: GitLab Addresses Critical Vulnerability Enabling Unauthorized Execution of Pipeline Jobs

GitLab Issues Urgent Security Update Following Discovery of Critical Vulnerability On Wednesday, GitLab announced the release of crucial security updates aimed at addressing 17 vulnerabilities, among which is a critical flaw that permits an attacker to execute pipeline jobs as an arbitrary user. This vulnerability, designated CVE-2024-6678, carries a CVSS…

Read MoreUrgent: GitLab Addresses Critical Vulnerability Enabling Unauthorized Execution of Pipeline Jobs

PEAKLIGHT Downloader Used in Attacks Targeting Windows through Malicious Movie Downloads

New Cyber Threat Uncovered: Sophisticated Malware Dropper Targeting Windows Systems Cybersecurity experts have recently identified a previously unknown dropper that acts as a gateway for deploying advanced malware with the ultimate aim of compromising Windows systems. This discovery marks a significant development in the ongoing fight against cyber threats, particularly…

Read MorePEAKLIGHT Downloader Used in Attacks Targeting Windows through Malicious Movie Downloads

Chinese DragonRank Hackers Target Global Windows Servers for SEO Fraud Exploits

DragonRank Hacking Group Compromises Global Windows Servers: A Threat to Cybersecurity A cybercriminal organization known as DragonRank has recently been identified as having breached over 30 Windows servers around the world, including in Thailand, India, Korea, Belgium, the Netherlands, and China. This Chinese-speaking hacking group is primarily focused on exploiting…

Read MoreChinese DragonRank Hackers Target Global Windows Servers for SEO Fraud Exploits

Ransomware Attacks Are Increasing Costs to Millions for Schools and Educational Institutions

As the new academic year begins, educational institutions are grappling with an alarming surge in ransomware attacks that threaten their operational integrity. A recent report from Sophos highlights the intensifying strain on IT infrastructure across universities, colleges, and schools of all sizes. The report emphasizes that institutions are facing escalating…

Read MoreRansomware Attacks Are Increasing Costs to Millions for Schools and Educational Institutions

Ransomware Masquerading as a Game: The Kransom Attack via DLL Side-Loading

The Kransom ransomware has been found embedded within the StarRail gaming application, employing DLL side-loading tactics alongside a legitimate certificate from COGNOSPHERE PTE. LTD. This malware successfully evades detection while delivering its encrypted payload. Analysts can study this threat within the interactive sandbox provided by ANY.RUN. Investigators at ANY.RUN have…

Read MoreRansomware Masquerading as a Game: The Kransom Attack via DLL Side-Loading

Future-Proofing Against Evolving Attacks: Safeguarding Your Users’ Identities

The FBI and CISA Release Advisory Addressing New Ransomware Threats The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) have issued a joint advisory aimed at mitigating the rising threat of ransomware attacks, as part of their ongoing #StopRansomware initiative. Released on August 29, 2023, the advisory, identified as…

Read MoreFuture-Proofing Against Evolving Attacks: Safeguarding Your Users’ Identities