The Breach News

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Compromise Universities

In a significant cybersecurity breach, the ShinyHunters group has exploited a previously unaddressed vulnerability in Oracle PeopleSoft to infiltrate enterprise systems. Their campaign has primarily targeted universities, leveraging the exploit to extract sensitive data while demanding ransom payments for its confidentiality. The operation was observed between May 27 and June…

Read MoreShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Compromise Universities

LibSSH Vulnerability Enables Hackers to Seize Control of Servers Without a Password

A critical vulnerability has emerged in the Secure Shell (SSH) library, Libssh, potentially allowing unauthorized access to vulnerable servers for the past four years. This issue, referred to as CVE-2018-10933, enables attackers to bypass authentication methods entirely, granting them administrative control without requiring a password. This authentication bypass vulnerability was…

Read MoreLibSSH Vulnerability Enables Hackers to Seize Control of Servers Without a Password

UK to Use Face Scans on Asylum Seekers for Age Verification, Acknowledging Tech Limitations

The Home Office has stated that its implementation of face scanning technology is intended to serve as an “additional” resource for border personnel, emphasizing that it will not “supersede or undermine human judgment.” However, the department has not clarified how this technology will be applied in practical situations. According to…

Read MoreUK to Use Face Scans on Asylum Seekers for Age Verification, Acknowledging Tech Limitations

Major Data Breach Exposes Credentials for Thousands of Sensitive Networks

Cyber Attack Exploits SSL VPNs: Significant Breaches Uncovered Recent findings from Hudson Rock reveal that a sophisticated cyberattack has significantly compromised multiple organizations across several countries. The attackers employed advanced methods to intercept SSL VPN authentication hashes, utilizing a powerful 45-GPU cluster managed through Hashtopolis to crack these hashes. By…

Read MoreMajor Data Breach Exposes Credentials for Thousands of Sensitive Networks

Major Vulnerabilities Discovered in Amazon FreeRTOS IoT Operating System

A significant cybersecurity incident has emerged as a security researcher identified multiple critical vulnerabilities in FreeRTOS and its variants, which include Amazon FreeRTOS, OpenRTOS, and SafeRTOS. These vulnerabilities jeopardize a broad spectrum of Internet of Things (IoT) devices and critical infrastructures, raising alarms among industry stakeholders. FreeRTOS is a widely…

Read MoreMajor Vulnerabilities Discovered in Amazon FreeRTOS IoT Operating System

15 Harmful JetBrains Plugins Discovered Stealing DeepSeek and OpenAI API Keys

Cybercriminals Exploit Fake AI Tools in Targeted Attack on JetBrains Marketplace Cybercriminals have launched a coordinated supply chain attack targeting software developers through the JetBrains Marketplace, utilizing counterfeit artificial intelligence (AI) tools. This breach was uncovered by Aikido Security, a firm specializing in code security, which identified 15 fraudulent plugins…

Read More15 Harmful JetBrains Plugins Discovered Stealing DeepSeek and OpenAI API Keys

Serious Code Execution Vulnerability Discovered in LIVE555 Streaming Library

Critical Vulnerability Discovered in LIVE555 Streaming Media Library Security researchers have recently identified a critical code execution vulnerability in the LIVE555 streaming media library, a widely utilized framework in various media players and embedded devices for streaming audio and video content. This vulnerability raises significant concerns for businesses reliant on…

Read MoreSerious Code Execution Vulnerability Discovered in LIVE555 Streaming Library

Attention Windows and Linux Users: Update Your Secure Boot Keys Before the Deadline!

UEFI Bootkits: A Growing Cybersecurity Concern In recent years, the landscape of cybersecurity threats has evolved significantly, marked notably by the introduction of bootkits targeting Unified Extensible Firmware Interface (UEFI) systems. These sophisticated forms of malware represent a new layer of vulnerability for both individual users and corporate environments, disrupting…

Read MoreAttention Windows and Linux Users: Update Your Secure Boot Keys Before the Deadline!

Unfixed MS Word Vulnerability Might Enable Hackers to Compromise Your Computer

Recent investigations by cybersecurity specialists have uncovered a significant security vulnerability affecting Microsoft Office 2016 and earlier versions. This unpatched logical flaw enables cybercriminals to integrate malicious code into document files, effectively deceiving users into executing malware on their systems. The researchers at Cymulate identified that the vulnerability exploits the…

Read MoreUnfixed MS Word Vulnerability Might Enable Hackers to Compromise Your Computer