The Breach News

Severe Vulnerability (CVSS Score 10) Allows Hackers to Take Control of Oracle Identity Manager

A serious vulnerability has been uncovered in Oracle’s enterprise identity management system, posing risks of severe exploitation by remote, unauthenticated attackers. This flaw, identified as CVE-2017-10151, has been given the highest possible CVSS score of 10, indicating it is both critical and easily exploitable without the need for any user…

Read MoreSevere Vulnerability (CVSS Score 10) Allows Hackers to Take Control of Oracle Identity Manager

Alert: 3 Major Vulnerabilities Put ownCloud Users at Risk of Data Breaches

Recent advisories from the maintainers of ownCloud have revealed three critical vulnerabilities within their open-source file-sharing software that could lead to unauthorized access, data modification, and exposure of sensitive information. These vulnerabilities pose significant risks to users and require immediate attention. The first flaw, identified as CVE-2023-49103, boasts a CVSS…

Read MoreAlert: 3 Major Vulnerabilities Put ownCloud Users at Risk of Data Breaches

ALERT: Hackers Deploy Hidden Backdoor on Thousands of Microsoft SQL Servers

Malicious Campaign Targeting MS-SQL Servers Discovered by Researchers Cybersecurity experts have identified a prolonged malicious campaign that has been active since May 2018, focusing on Windows machines equipped with MS-SQL servers. The campaign, named “Vollgar” after the Vollar cryptocurrency it mines, is aimed at deploying backdoors and diverse malware, including…

Read MoreALERT: Hackers Deploy Hidden Backdoor on Thousands of Microsoft SQL Servers

Forever 21 Alerts Shoppers to Payment Card Breach at Certain Locations

In a troubling development for the retail sector, Forever 21 has announced a payment card data breach affecting its customers. The Los Angeles-based fast-fashion retailer revealed that hackers managed to access payment card information from various store locations, posing a significant cybersecurity risk. The incident was brought to light earlier…

Read MoreForever 21 Alerts Shoppers to Payment Card Breach at Certain Locations

LastPass 2022 Breach Resulted in Prolonged Cryptocurrency Theft, According to TRM Labs

Dec 25, 2025Ravie LakshmananData Breach / Financial Crime Recent findings from TRM Labs reveal that encrypted vault backups compromised in the 2022 LastPass data breach have been exploited by cybercriminals to access crypto assets, particularly due to the use of weak master passwords. This criminal activity has reportedly persisted into…

Read MoreLastPass 2022 Breach Resulted in Prolonged Cryptocurrency Theft, According to TRM Labs

Dark Nexus: Newly Discovered IoT Botnet Malware Identified in the Wild

Emergence of the Dark_Nexus IoT Botnet: A New Threat to Cybersecurity Cybersecurity experts have unveiled a sophisticated new IoT botnet known as “dark_nexus,” which is leveraging compromised smart devices to launch distributed denial-of-service (DDoS) attacks. This emerging threat can be triggered on demand through platforms offering DDoS-for-hire services, placing numerous…

Read MoreDark Nexus: Newly Discovered IoT Botnet Malware Identified in the Wild