The Breach News

Exploitable Backdoors in npm Packages Allow Attackers to Compromise Entire Systems

Malicious npm Packages Discovered, Posing Serious Threat to Developers Security researchers have uncovered two npm packages that exceed their purported functionality, posing a significant threat to developers. Disguised as tools for system monitoring and data synchronization, these packages harbor destructive backdoors capable of remotely erasing all files within an application.…

Read MoreExploitable Backdoors in npm Packages Allow Attackers to Compromise Entire Systems

Mirai Botnet Variant Takes Advantage of DVR Vulnerability to Form Swarm

Endpoint Security, Internet of Things Security Variant of Mirai Botnet Exploits DVR Command Injection Vulnerability, Impacting 50,000 Devices Anviksha More (AnvikshaMore) • June 9, 2025 Image: Ivan Kislitsin/Shutterstock A newly identified variant of the Mirai botnet is making headlines as it exploits a command injection vulnerability in internet-connected digital video…

Read MoreMirai Botnet Variant Takes Advantage of DVR Vulnerability to Form Swarm

A Researcher Discovered a Method to Expose Any Phone Number Associated with a Google Account

A cybersecurity researcher recently identified a vulnerability that enabled the extraction of phone numbers associated with any Google account. This information is generally private and sensitive, as confirmed by both the researcher and independent testing by 404 Media. The vulnerability has since been addressed by Google. However, at the time…

Read MoreA Researcher Discovered a Method to Expose Any Phone Number Associated with a Google Account

Data Breach: Limited Canva Creator Information Exposed Through AI Chatbot Database

A Chroma database managed by the Russian AI chatbot startup My Jedai has been found exposed online, resulting in a significant data leak that includes survey responses from over 500 Canva Creators. This compromised dataset features personal email addresses, feedback on Canva’s Creator Program, and insights into the experiences of…

Read MoreData Breach: Limited Canva Creator Information Exposed Through AI Chatbot Database

Jackson Health System Reveals Additional 5-Year Insider Data Breach – The HIPAA Journal

Jackson Health System Reports Significant Insider Data Breach In a troubling development within the healthcare sector, Jackson Health System has revealed a new insider data breach that extends over a five-year period. This breach has raised concerns about the safeguarding of sensitive patient information, a critical aspect of healthcare organizations…

Read MoreJackson Health System Reveals Additional 5-Year Insider Data Breach – The HIPAA Journal

China’s Data Crisis: 4 Billion User Records Exposed in Massive Breach

In a significant cybersecurity incident, researchers have identified what could be the largest single-source breach of Chinese personal data, with more than 4 billion user records exposed through an unsecured database. This incident raises alarms about potential invasions of privacy, surveillance, and the risk of data misuse, as the leaked…

Read MoreChina’s Data Crisis: 4 Billion User Records Exposed in Massive Breach