The Breach News

Sharp Panda Leverages New Soul Framework Version to Engage Southeast Asian Governments

Southeast Asian Governments Targeted in Ongoing Cyber Espionage by Sharp Panda A sophisticated cyber espionage campaign has emerged, focusing on high-profile government entities across Southeast Asia, with the Chinese threat actor known as Sharp Panda at the forefront. This activity has reportedly intensified since late last year, evolving away from…

Read MoreSharp Panda Leverages New Soul Framework Version to Engage Southeast Asian Governments

CISO Webinar: The Rise of AI in the UK and Its Impact on Attack Surfaces

Mandy Andress: Visionary Leader in Cybersecurity CISO, Elastic Mandy Andress serves as the Chief Information Security Officer (CISO) at Elastic, bringing with her a wealth of experience in information risk management and cybersecurity. Her career journey includes pivotal roles where she spearheaded information security initiatives at MassMutual and played a…

Read MoreCISO Webinar: The Rise of AI in the UK and Its Impact on Attack Surfaces

CISA Includes CrushFTP Vulnerability in KEV Catalog After Confirmed Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reported a significant security vulnerability affecting CrushFTP, now cataloged as a Known Exploited Vulnerability following active exploitation incidents. The flaw, identified as an authentication bypass, allows unauthenticated attackers to gain control of vulnerable instances, raising serious concerns among cybersecurity professionals. This…

Read MoreCISA Includes CrushFTP Vulnerability in KEV Catalog After Confirmed Active Exploitation

TransUnion Data Breach Exposes 4.5 Million Records via Third-Party Application

TransUnion Cyberattack Exposes Personal Data of 4.4 Million Consumers TransUnion, one of the United States’ primary credit reporting agencies, has reported a cyberattack that has compromised the sensitive personal information of over 4.4 million U.S. consumers. This breach, confirmed on July 30, originated due to vulnerabilities in a third-party application…

Read MoreTransUnion Data Breach Exposes 4.5 Million Records via Third-Party Application

SysAid Addresses 4 Critical Vulnerabilities Allowing Pre-Authenticated RCE in On-Premises Version

SysAid IT Support Software Vulnerabilities Expose Businesses to Remote Code Execution Risks Cybersecurity experts have revealed critical security vulnerabilities in the on-premise version of SysAid IT support software, presenting significant risks for organizations using this platform. These vulnerabilities, identified as CVE-2025-2775, CVE-2025-2776, and CVE-2025-2777, enable attackers to execute remote commands…

Read MoreSysAid Addresses 4 Critical Vulnerabilities Allowing Pre-Authenticated RCE in On-Premises Version

Live Webinar | Safeguarding Identity in the Manufacturing Revolution: Machines, Mergers, and Missteps.

Chris Fields: Leading Cybersecurity Insights at Simeio Senior Vice President, Simeio Chris Fields serves as Senior Vice President at Simeio, bringing over 30 years of expertise in IT and Identity and Access Management (IAM). His career is marked by leadership roles in strategy, delivery, and innovative solutions in the cybersecurity…

Read MoreLive Webinar | Safeguarding Identity in the Manufacturing Revolution: Machines, Mergers, and Missteps.

UAC-0226 Distributes GIFTEDCROOK Stealer through Malicious Excel Files Aimed at Ukraine

The Computer Emergency Response Team of Ukraine (CERT-UA) has reported a series of cyber attacks targeting Ukrainian institutions through information-stealing malware. These coordinated assaults specifically aim at military units, law enforcement agencies, and local government bodies, particularly those positioned near Ukraine’s eastern border. The attack methodology involves the distribution of…

Read MoreUAC-0226 Distributes GIFTEDCROOK Stealer through Malicious Excel Files Aimed at Ukraine