The Breach News

Robbery and Extortion

Emerging Threats Highlighted in 2024 Attack Intelligence Report The "2024 Attack Intelligence Report" by Rapid7 delivers critical insights into the evolving landscape of cybersecurity threats. This comprehensive report outlines alarming trends regarding vulnerabilities exploited in the past year, particularly emphasizing the dominance of zero-day vulnerabilities. Of the more than thirty…

Read MoreRobbery and Extortion

PSNI Penalized £750,000 for ‘Severe’ Data Breach – DataBreaches.Net

The Police Service of Northern Ireland (PSNI) has been penalized with a substantial fine of £750,000 due to a significant data breach affecting personal information belonging to its staff and officers. This ruling, issued by the Information Commissioner’s Office (ICO), underscores the severity of the breach, which has raised concerns…

Read MorePSNI Penalized £750,000 for ‘Severe’ Data Breach – DataBreaches.Net

Microsoft Resolves ASCII Smuggling Vulnerability That Allowed Data Theft from Microsoft 365 Copilot

Microsoft 365 Copilot Vulnerability Exposed: ASCII Smuggling Risk to User Data Recently, a significant vulnerability within Microsoft 365 Copilot was identified and subsequently patched, shedding light on an emerging security concern known as ASCII smuggling. This technique, which leverages specific Unicode characters resembling ASCII but remaining nearly invisible in user…

Read MoreMicrosoft Resolves ASCII Smuggling Vulnerability That Allowed Data Theft from Microsoft 365 Copilot

PHP Security Flaw Exploited for Malware Distribution and DDoS Attacks

Recent cybersecurity developments highlight alarming activities surrounding a critical vulnerability in PHP, identified as CVE-2024-4577, which possesses a high severity rating of 9.8 on the CVSS scale. This flaw enables cybercriminals to remotely execute harmful commands on Windows systems, particularly when these systems operate with Chinese and Japanese language settings.…

Read MorePHP Security Flaw Exploited for Malware Distribution and DDoS Attacks

NETSCOUT Reports Rise in DDoS Attacks Targeting Healthcare Sector

On October 2, NETSCOUT, a global leader in network monitoring solutions, revealed critical findings in its latest DDoS Threat Intelligence Report. The organization reported that Distributed Denial of Service (DDoS) attacks are evolving, increasingly employing innovative technologies and tactics to disrupt networks. This alarming update comes as entities in multiple…

Read MoreNETSCOUT Reports Rise in DDoS Attacks Targeting Healthcare Sector

Severe WPML Plugin Vulnerability Puts WordPress Sites at Risk of Remote Code Execution

An alarming security vulnerability has been identified within the WPML (WordPress Multilingual) plugin, which has the potential to allow authenticated users to perform remote code execution under specific conditions. This security flaw, designated as CVE-2024-6386, carries a critical CVSS score of 9.9 and affects all versions prior to 4.6.13, released…

Read MoreSevere WPML Plugin Vulnerability Puts WordPress Sites at Risk of Remote Code Execution

DarkGate Malware Targets Samba File Shares in Brief Surge Attack

Cybersecurity Experts Uncover DarkGate Malware Campaign Targeting Samba File Shares In a recent investigation, cybersecurity analysts have unveiled a brief yet impactful campaign associated with DarkGate malware, which exploited Samba file sharing services as a vector for infection. Researchers from Palo Alto Networks’ Unit 42 indicated that the campaign occurred…

Read MoreDarkGate Malware Targets Samba File Shares in Brief Surge Attack

Extending Operation Cronos: Insights into LockBit Ransomware and FIN7 Deepfake Malware

Europol, in a coordinated effort with global law enforcement agencies, has expanded its Operation Cronos to apprehend four individuals alleged to have connections with the notorious LockBit ransomware group. A recent press release highlighted the successful arrests as well as the seizure of servers and financial assets linked to this…

Read MoreExtending Operation Cronos: Insights into LockBit Ransomware and FIN7 Deepfake Malware

MSSP Market Update: Court Evaluates Liability for Data Breaches

Security Concerns Heightened Amid Data Breach at Columbus Regional Healthcare System Recent developments surrounding the data breach at Columbus Regional Healthcare System (CRHS) underscore the escalating concerns over cybersecurity vulnerabilities in the healthcare sector. A federal class-action lawsuit has emerged from this incident, alleging that CRHS failed to adequately protect…

Read MoreMSSP Market Update: Court Evaluates Liability for Data Breaches