The Breach News

Ukrainian Extradited Man Confesses to Involvement in Conti Ransomware Attacks

A Ukrainian man has entered a guilty plea in a U.S. court following his extradition from Ireland, admitting to involvement in the notorious Conti ransomware operation—identified as one of the most destructive cybercrime syndicates active during the pandemic years. Oleksii Oleksiyovych Lytvynenko, aged 44, confessed to conspiracy to commit wire…

Read MoreUkrainian Extradited Man Confesses to Involvement in Conti Ransomware Attacks

phpMyAdmin Issues Urgent Software Update — Update Your Sites Immediately!

phpMyAdmin Security Update Addresses Critical Vulnerabilities Developers of phpMyAdmin, one of the leading open-source tools for managing MySQL databases, have released version 4.8.4 to patch several critical vulnerabilities that could enable remote attackers to take control of affected web servers. The update, which addresses significant security flaws, underscores the need…

Read MorephpMyAdmin Issues Urgent Software Update — Update Your Sites Immediately!

The FCC Aims to Regulate Burner Phones Out of Existence

Following a report from WIRED last week indicating that Meta’s smart glasses app included code for enabling face recognition features, the company removed the code shortly thereafter without providing an explanation or indicating whether such functionality could be reintroduced. Simultaneously, another investigation by WIRED revealed that xAI’s Grok platform continues…

Read MoreThe FCC Aims to Regulate Burner Phones Out of Existence

Microsoft Releases Patch for Windows Zero-Day Vulnerability Currently Under Attack

Microsoft Releases Critical Security Updates Addressing 39 Vulnerabilities In a significant move this December, Microsoft has released security patches addressing a total of 39 vulnerabilities across its Windows operating systems and applications during its year-end Patch Tuesday. Among these, ten vulnerabilities have been designated as critical, emphasizing the potential severe…

Read MoreMicrosoft Releases Patch for Windows Zero-Day Vulnerability Currently Under Attack

Atomic Arch Campaign Compromises Over 20 Linux AUR Packages to Distribute Malware

Sonatype, a cybersecurity research firm, has identified a malicious campaign specifically targeting Linux systems through a novel exploitation method. The attackers are leveraging a vulnerability in the ownership transfer mechanism of open-source projects to deploy malware discreetly. This operation, known as “Atomic Arch,” primarily affects the Arch User Repository (AUR),…

Read MoreAtomic Arch Campaign Compromises Over 20 Linux AUR Packages to Distribute Malware

Major SQLite Vulnerability Exposes Millions of Apps to Cyber Attacks

— Cybersecurity experts have recently uncovered a serious vulnerability in SQLite, a widely adopted database software integral to billions of applications worldwide. The vulnerability, known as “Magellan,” was identified by Tencent’s Blade security team and poses significant risks, including the potential for remote attackers to execute arbitrary code, access sensitive…

Read MoreMajor SQLite Vulnerability Exposes Millions of Apps to Cyber Attacks

PeopleSoft Zero-Day Vulnerability Targets Hundreds of Organizations, Exfiltrating Gigabytes of Data

ShinyHunters Breach Exposes Sensitive Data The cybersecurity firm Mandiant has reported that several organizations faced serious security breaches, with some compromising their confidential data. This resulted in sensitive information being published on the Data Leak Site (DLS) operated by the notorious group, ShinyHunters. Notably, some organizations successfully mitigated the attacks,…

Read MorePeopleSoft Zero-Day Vulnerability Targets Hundreds of Organizations, Exfiltrating Gigabytes of Data

Hacker Reveals New Unpatched Windows Zero-Day Exploit on Twitter

A significant vulnerability has emerged concerning Microsoft’s Windows operating system, unveiled today by the security researcher known by the Twitter handle SandboxEscaper. This individual has shared a proof-of-concept (PoC) exploit that targets a newly discovered zero-day vulnerability, leaving numerous Windows users at risk. SandboxEscaper is known for previously disclosing two…

Read MoreHacker Reveals New Unpatched Windows Zero-Day Exploit on Twitter