The Breach News

China-Linked UAT-7810 Enhances ORB Network with New LONGLEASH Malware

Recently, cybersecurity researchers identified a sophisticated threat actor from China, designated as UAT-7810, which is intensifying its operations to enhance its Operational Relay Box (ORB) network by infiltrating network devices that are accessible over the internet. This revelation comes from an analysis conducted by Cisco Talos, a reputable threat intelligence…

Read MoreChina-Linked UAT-7810 Enhances ORB Network with New LONGLEASH Malware

States Demand Visibility from ICE Agents, but the Trump Administration Is Interfering

Federal Lawsuit Against States Over ICE Accountability Laws Raises Cybersecurity Concerns The Trump administration has initiated legal action against at least five states and the city of Philadelphia, challenging laws that supporters assert would enhance accountability for law enforcement, particularly Immigration and Customs Enforcement (ICE) officers. These laws present various…

Read MoreStates Demand Visibility from ICE Agents, but the Trump Administration Is Interfering

Critical Linux Sudo Vulnerability Enables Users to Attain Root Access

A significant vulnerability has been identified in the Linux operating system, potentially allowing a low-privilege attacker to gain complete root access to affected systems. This flaw, known as CVE-2017-1000367, was uncovered by researchers at Qualys Security within Sudo’s “get_process_ttyname()” function, which could enable users with Sudo privileges to execute commands…

Read MoreCritical Linux Sudo Vulnerability Enables Users to Attain Root Access

New Ghost Phishing Wave Shattering Conventional Email Security

EvilTokens Campaign Unveils New Email Security Vulnerabilities A recent series of attacks by the EvilTokens campaign has spotlighted a significant blind spot in email security protocols, primarily affecting businesses across the United States and Europe. This tactic, sometimes referred to as “ghost phishing,” cleverly obscures malicious webpages until they are…

Read MoreNew Ghost Phishing Wave Shattering Conventional Email Security

A Covert Hacking Tool Targeting AI Infrastructure Is Hiding in Plain Sight

As artificial intelligence (AI) tools become increasingly integrated into software development, recent findings from CrowdStrike highlight a concerning trend where attackers are specifically targeting the AI toolchain. Their research reveals methods employed by cybercriminals to compromise access credentials, gain unauthorized entry into systems, exfiltrate sensitive data, and even destroy crucial…

Read MoreA Covert Hacking Tool Targeting AI Infrastructure Is Hiding in Plain Sight

Ten-Year-Old Root Privilege Escalation Vulnerability Found in Unix/Linux/BSD Systems

Update on Stack Clash Vulnerability: Immediate Action Required Security experts have uncovered a vulnerability known as “Stack Clash,” affecting multiple Unix-based operating systems, including Linux, OpenBSD, NetBSD, FreeBSD, and Solaris. This issue, designated as CVE-2017-1000364, poses a significant risk as attackers could potentially exploit it to escalate their privileges to…

Read MoreTen-Year-Old Root Privilege Escalation Vulnerability Found in Unix/Linux/BSD Systems

New HalluSquatting Attack Threatens AI Coding Assistants with Botnet Malware Installation

A concerning trend has emerged with AI coding assistants, which frequently generate fictitious project names when asked for popular tools. Recent research termed “HalluSquatting” exploits this tendency, involving malicious actors who identify and register these fabricated names before the AI can utilize them, effectively creating traps for unsuspecting users. This…

Read MoreNew HalluSquatting Attack Threatens AI Coding Assistants with Botnet Malware Installation

Major Skype Vulnerability Allows Hackers to Execute Malicious Code Remotely

A significant security vulnerability has been identified in Skype, the widely used web messaging and voice calling service owned by Microsoft. This flaw may enable malicious actors to execute code remotely, potentially compromising systems running outdated versions of the application. Skype has become integral for online communication, offering voice, video,…

Read MoreMajor Skype Vulnerability Allows Hackers to Execute Malicious Code Remotely