The Breach News

SIM Cards in 29 Countries at Risk of Remote Simjacker Attacks

Recently, cybersecurity researchers have spotlighted a significant vulnerability known as SimJacker, affecting a variety of SIM cards. This flaw can be exploited remotely, allowing attackers to gain unauthorized access to mobile devices through a meticulously crafted binary SMS. The implications are severe, as the vulnerability poses a risk to countless…

Read MoreSIM Cards in 29 Countries at Risk of Remote Simjacker Attacks

Adobe Issues Emergency Security Updates for 82 Vulnerabilities Across Multiple Products

Adobe Releases Critical Patch Updates for Multiple Products On the third Tuesday of the month, Adobe has rolled out significant out-of-band security updates to address a substantial number of vulnerabilities across its product suite. This proactive measure comes in response to 82 identified security flaws, as noted in an early…

Read MoreAdobe Issues Emergency Security Updates for 82 Vulnerabilities Across Multiple Products

DAEMON Tools Supply Chain Attack Infects Official Installers with Malware

Targeted Supply Chain Attack on DAEMON Tools Software Discovered A recent investigation by Kaspersky has revealed a sophisticated supply chain attack targeting DAEMON Tools software. The attack involves tampering with the software’s installers, which are distributed through the official DAEMON Tools website and are signed with valid digital certificates from…

Read MoreDAEMON Tools Supply Chain Attack Infects Official Installers with Malware

Facebook Offers Rewards to Hackers for Reporting Security Vulnerabilities in Third-Party Apps

In response to prior security incidents and data misuse involving its platform, Facebook has taken significant steps to enhance the security of third-party applications and websites through an expanded bug bounty program. This initiative aims to address vulnerabilities in external apps that interface with Facebook, reinforcing the company’s commitment to…

Read MoreFacebook Offers Rewards to Hackers for Reporting Security Vulnerabilities in Third-Party Apps

MuddyWater Exploits Microsoft Teams for Credential Theft in Deceptive Ransomware Attack

In a recent incident, the Iranian state-sponsored hacking group known as MuddyWater has been implicated in a ransomware attack described as a “false flag” operation. This incident was tracked by Rapid7 in early 2026, where attackers exploited social engineering techniques utilizing Microsoft Teams to initiate their malicious activities. Initially perceived…

Read MoreMuddyWater Exploits Microsoft Teams for Credential Theft in Deceptive Ransomware Attack

New PHP Vulnerability Could Allow Attackers to Compromise Nginx-Hosted Sites

A newly identified vulnerability poses significant risks for PHP-based websites operating on NGINX servers with PHP-FPM enabled. This security flaw, identified as CVE-2019-11043, could enable unauthorized remote access to affected systems. Researchers have already released proof-of-concept (PoC) exploits demonstrating this vulnerability, highlighting its potential for exploitation across various configurations that…

Read MoreNew PHP Vulnerability Could Allow Attackers to Compromise Nginx-Hosted Sites