The Breach News

Cisco Alerts Users to Potential Exploitation of Long-Standing ASA WebVPN Flaw

On Monday, Cisco issued an updated advisory highlighting an ongoing threat linked to a long-standing vulnerability in its Adaptive Security Appliance (ASA). The flaw, identified as CVE-2014-2120, has a CVSS score of 4.3 and relates to insufficient input validation within the WebVPN login interface. This vulnerability permits unauthenticated remote attackers…

Read MoreCisco Alerts Users to Potential Exploitation of Long-Standing ASA WebVPN Flaw

New Chinotto Spyware Aims at North Korean Defectors and Human Rights Advocates

Recent Cyber Surveillance Attacks Target North Korean Defectors and Journalists In a disturbing development, advanced persistent threats (APTs) linked to nation-state actors have launched a series of highly-targeted surveillance attacks against North Korean defectors, journalists covering North Korea, and associated organizations based in South Korea. Reports from Russian cybersecurity firm…

Read MoreNew Chinotto Spyware Aims at North Korean Defectors and Human Rights Advocates

Envoy Air (American Airlines) Confirms Oracle EBS Zero-Day Breach Linked to Cl0p Group

On October 17, 2025, Envoy Air, a Texas-based regional airline and the largest carrier under American Airlines, confirmed that it was recently compromised due to a series of cyberattacks exploiting a zero-day vulnerability in a major corporate software application. The hacks were executed by CL0P, a notorious ransomware group known…

Read MoreEnvoy Air (American Airlines) Confirms Oracle EBS Zero-Day Breach Linked to Cl0p Group

JumpCloud Revokes API Keys in Response to Ongoing Cybersecurity Incident

JumpCloud Responds to Cybersecurity Incident Affecting Clients JumpCloud, a cloud-based identity and access management provider, has taken swift action in response to a significant cybersecurity incident that has impacted a number of its clients. The breach has prompted the company to reset the application programming interface (API) keys for all…

Read MoreJumpCloud Revokes API Keys in Response to Ongoing Cybersecurity Incident

Salt Typhoon Strikes European Telecom Sector

Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Darktrace Reports on Compromise of Citrix NetScaler Gateway Akshaya Asokan (asokan_akshaya) • October 20, 2025 Image: Shutterstock Recent reports from the managed threat detection firm Darktrace indicate that a persistent campaign by the Chinese cyber espionage group known as Salt Typhoon continues…

Read MoreSalt Typhoon Strikes European Telecom Sector

Hackers Exploit Citrix Vulnerability and Snappybee Malware to Compromise European Telecom Network

October 21, 2025Ravie LakshmananCyber Espionage / Network Security A European telecommunications company has reportedly fallen victim to a cyber intrusion attributed to a threat actor associated with the China-linked group known as Salt Typhoon. This incident, as reported by Darktrace, took place during the first week of July 2025. Attackers…

Read MoreHackers Exploit Citrix Vulnerability and Snappybee Malware to Compromise European Telecom Network

Serious SailPoint IdentityIQ Vulnerability Allows Unauthorized File Access

Critical Vulnerability Discovered in SailPoint’s IdentityIQ Software A significant security vulnerability has been identified in SailPoint’s IdentityIQ identity and access management (IAM) software, potentially exposing sensitive data stored in application directories. The flaw, designated CVE-2024-10905, carries a maximum CVSS score of 10.0, highlighting its critical severity. This vulnerability affects various…

Read MoreSerious SailPoint IdentityIQ Vulnerability Allows Unauthorized File Access

WIRTE Hacker Group Attacks Government, Legal, and Financial Institutions in the Middle East

Stealth Malware Campaign Targets Middle Eastern Entities A sophisticated malware campaign has been uncovered, targeting government bodies, military organizations, law firms, and financial institutions predominantly in the Middle East. Initiated as early as 2019, the campaign leverages malicious Microsoft Excel and Word documents to infiltrate victim networks. Kaspersky, a Russian…

Read MoreWIRTE Hacker Group Attacks Government, Legal, and Financial Institutions in the Middle East