The Breach News

German and South Korean Agencies Caution Against Kimsuky’s Growing Cyber Attack Techniques

Cyber Threat Alert: Kimsuky Group Targets Gmail Inboxes Using Rogue Browser Extensions Recent advisories from government agencies in Germany and South Korea have highlighted a concerning wave of cyberattacks attributed to a North Korean threat actor known as Kimsuky. This group has been leveraging malicious browser extensions to infiltrate users’…

Read MoreGerman and South Korean Agencies Caution Against Kimsuky’s Growing Cyber Attack Techniques

Explosive Revelation: Whistleblower Exposes Social Security Data

Artificial Intelligence & Machine Learning, Government, Industry Specific Also: Netskope’s High-Stakes IPO, How AI Sovereignty Threatens Our Shared Reality Anna Delaney (annamadeline) • August 29, 2025 Clockwise, from top left: Anna Delaney, Tony Morbin, Chris Riotta, and Michael Novinson This week’s update features a discussion among four editors from ISMG…

Read MoreExplosive Revelation: Whistleblower Exposes Social Security Data

CISA Alerts About Vulnerability in CentreStack’s Hard-Coded MachineKey That Allows RCE Attacks

On April 8, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a significant security vulnerability in Gladinet CentreStack to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation occurring in the digital landscape. This critical flaw is identified as CVE-2025-30406 and carries a CVSS score of 9.0, underscoring…

Read MoreCISA Alerts About Vulnerability in CentreStack’s Hard-Coded MachineKey That Allows RCE Attacks

Google Issues Urgent Warning to All Gmail Users Amid Rising Cyber Threats – NationalWorld

Google Issues Urgent Cybersecurity Alert for Gmail Users Amid Rising Threat Landscape In a notable development within the cybersecurity realm, Google has issued an urgent warning for all Gmail users, highlighting a significant surge in cyber threats targeting the widely utilized email platform. This alert underscores the vulnerability of users…

Read MoreGoogle Issues Urgent Warning to All Gmail Users Amid Rising Cyber Threats – NationalWorld

Chinese Hackers Exploit SAP RCE Vulnerability CVE-2025-31324 to Deploy Golang-Based SuperShell

A recent report has identified a China-linked threat actor, referred to as Chaya_004, actively exploiting a critical vulnerability in SAP NetWeaver. This attack leverages the flaw CVE-2025-31324, which has been assigned a maximum CVSS score of 10.0. The malicious activity linked to this actor has been ongoing since April 29,…

Read MoreChinese Hackers Exploit SAP RCE Vulnerability CVE-2025-31324 to Deploy Golang-Based SuperShell

Operation Soft Cell: Chinese Hackers Compromise Telecom Providers in the Middle East

Cyber Attacks Target Middle East Telecommunications Amid Ongoing Espionage Campaign Telecommunication companies in the Middle East have recently become the focus of a series of cyber attacks that began in the first quarter of 2023. These attacks have been tied to a Chinese cyber espionage group linked to a protracted…

Read MoreOperation Soft Cell: Chinese Hackers Compromise Telecom Providers in the Middle East

Nevada Dental Practice Alerts 1.2 Million Patients of Data Breach

3rd Party Risk Management, Cybercrime, Fraud Management & Cybercrime Absolute Dental Reports Data Breach Linked to Third-Party Services Marianne Kolbasuk McGee (HealthInfoSec) • August 29, 2025 Image: Absolute Dental Absolute Dental, a dental practice operating over 50 locations in Nevada, has informed more than 1.2 million individuals about a data…

Read MoreNevada Dental Practice Alerts 1.2 Million Patients of Data Breach

PipeMagic Trojan Leverages Windows Zero-Day Flaw to Launch Ransomware Attacks

Microsoft has disclosed that a recently patched security vulnerability within the Windows Common Log File System (CLFS) was actively exploited as a zero-day in targeted ransomware attacks against several entities. This flaw, identified as CVE-2025-29824, was employed to escalate privileges, thus granting attackers SYSTEM-level access. The affected organizations span multiple…

Read MorePipeMagic Trojan Leverages Windows Zero-Day Flaw to Launch Ransomware Attacks