The Breach News

A Limited Set of Training Documents Can Enable a Backdoor in LLMs

Artificial Intelligence & Machine Learning, Next-Generation Technologies & Secure Development Study Reveals Minor Data Poisoning Can Compromise Large Language Models Rashmi Ramesh (rashmiramesh_) • October 14, 2025 Image: ArtemisDiana/Shutterstock Recent findings indicate that as few as a few hundred malicious training documents can lead a large language model (LLM) to…

Read MoreA Limited Set of Training Documents Can Enable a Backdoor in LLMs

Qantas and Collins Aerospace Incidents Highlight Necessity for Enhanced Assurance

Recent cyber incidents have underscored the vulnerabilities permeating the aviation sector. The latest episode, the significant data breach of Qantas, has put millions of personal records at risk, echoing previous security failures such as the breach involving Collins Aerospace. These incidents unveil a systemic fragility within a network of interlinked…

Read MoreQantas and Collins Aerospace Incidents Highlight Necessity for Enhanced Assurance

Apache Tomcat Vulnerability CVE-2024-56337 Poses RCE Risk to Servers

The Apache Software Foundation (ASF) has announced a critical security update for its Tomcat server software, addressing a significant vulnerability that could lead to remote code execution (RCE) under specific conditions. This update highlights vulnerabilities identified as CVE-2024-56337 and CVE-2024-50379, the latter of which has a CVSS score of 9.8,…

Read MoreApache Tomcat Vulnerability CVE-2024-56337 Poses RCE Risk to Servers

Hacking Team DoNot Targets Government and Military Entities in South Asia

A persistent threat actor, suspected to have ties to an Indian cybersecurity firm, has been actively attacking military organizations in South Asia since at least September 2020. The targeted nations include Bangladesh, Nepal, and Sri Lanka, with various iterations of their specialized malware framework used in each assault. According to…

Read MoreHacking Team DoNot Targets Government and Military Entities in South Asia

Hackers Develop New Method to Capture 2-Factor Authentication Codes from Android Devices

Recent reports reveal a concerning new attack method, identified as “Pixnapping,” that exposes vulnerabilities in Android devices, enabling attackers to surreptitiously acquire crucial information such as two-factor authentication codes, location data, and other sensitive details within a mere 30 seconds. The Pixnapping attack originates from a malicious app that must…

Read MoreHackers Develop New Method to Capture 2-Factor Authentication Codes from Android Devices

DJVU Ransomware’s New Variant ‘Xaro’ Masquerades as Cracked Software

A new variant of the well-known DJVU ransomware is being distributed through cracked software, raising fresh concerns within the cybersecurity community. This particular variant appends the .xaro extension to files, prompting affected users to pay a ransom for decryption capabilities. According to Cybereason security researcher Ralph Villanueva, the behavior is…

Read MoreDJVU Ransomware’s New Variant ‘Xaro’ Masquerades as Cracked Software

Vietnam Airlines and Qantas Airways Face Data Breaches, Compromising Customer Information and Raising Serious Cybersecurity Concerns in the Aviation Industry: Key Insights You Should Know

Home » AIRLINE NEWS » Recent Data Breaches at Vietnam Airlines and Qantas Raise Alarm on Aviation Cybersecurity Published on October 14, 2025 The airline industry is witnessing an alarming rise in data breaches, with recent incidents involving **Vietnam Airlines** and **Qantas Airways** revealing severe vulnerabilities within the sector. Both…

Read MoreVietnam Airlines and Qantas Airways Face Data Breaches, Compromising Customer Information and Raising Serious Cybersecurity Concerns in the Aviation Industry: Key Insights You Should Know

CISA Includes Acclaim USAHERDS Vulnerability in KEV Catalog Due to Ongoing Exploitation

On December 23, 2024, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced the addition of a critical vulnerability affecting Acclaim Systems USAHERDS to its Known Exploited Vulnerabilities (KEV) catalog. This addition follows verifiable evidence that the flaw has been actively exploited. The vulnerability, identified as CVE-2021-44207, has a CVSS…

Read MoreCISA Includes Acclaim USAHERDS Vulnerability in KEV Catalog Due to Ongoing Exploitation