The Breach News

Hackers Taking Advantage of MS Excel Vulnerability to Distribute Agent Tesla Malware

Recent cybersecurity threats have revealed that attackers are exploiting an aging vulnerability in Microsoft Office as a tactic within phishing campaigns. This method is being employed to disseminate a malware variant known as Agent Tesla. The infection vector often involves decoy Excel files, which are typically embedded in messages that…

Read MoreHackers Taking Advantage of MS Excel Vulnerability to Distribute Agent Tesla Malware

Vulnerabilities in Industrial VPNs May Expose Critical Infrastructure to Attacks

Cybersecurity experts have identified serious vulnerabilities within widely used industrial VPN systems, which are crucial for accessing operational technology (OT) networks remotely. These vulnerabilities may enable malicious actors to manipulate data, execute harmful code, or interfere with industrial control systems (ICS), raising significant security concerns across various sectors. A newly…

Read MoreVulnerabilities in Industrial VPNs May Expose Critical Infrastructure to Attacks

MedStar Health Informs Patients of Data Breach Incident

Data Breach Notification, Data Security, Healthcare Ransomware Group Rhysida Claims to Have Leaked 3.7TB of Data From Maryland Hospital System Marianne Kolbasuk McGee (HealthInfoSec) • December 18, 2025 MedStar Health is alerting patients about a hacking incident involving compromised data. Ransomware group Rhysida claims to have obtained the entity’s stolen…

Read MoreMedStar Health Informs Patients of Data Breach Incident

Ex-Evoke Wellness Employee Misappropriates Patient Data – The HIPAA Journal

Data Breach Report: Former Employee Misuses Patient Information at Evoke Wellness In a significant breach of patient confidentiality, a former employee of Evoke Wellness has been found to have unlawfully obtained and misused sensitive patient data. This incident raises critical concerns regarding data security practices within healthcare organizations and the…

Read MoreEx-Evoke Wellness Employee Misappropriates Patient Data – The HIPAA Journal

UAC-0099: Leveraging WinRAR Vulnerabilities to Attack Ukrainian Companies with LONEPAGE Malware

The threat actor identified as UAC-0099 has intensified its campaign targeting Ukraine, utilizing a critical vulnerability in the WinRAR software to distribute the malware variant known as LONEPAGE. This method highlights a significant shift in tactics, emphasizing the exploitation of existing software vulnerabilities to facilitate attacks. According to cybersecurity firm…

Read MoreUAC-0099: Leveraging WinRAR Vulnerabilities to Attack Ukrainian Companies with LONEPAGE Malware

EU Sanctions Hackers from China, Russia, and North Korea Wanted by the FBI

The European Union has enacted its inaugural sanctions aimed at individuals and entities implicated in cyber-attacks that target European citizens and member states. This unprecedented directive has identified six individuals and three entities linked to various cyber intrusions, including notable incidents such as the WannaCry ransomware attack and NotPetya malware…

Read MoreEU Sanctions Hackers from China, Russia, and North Korea Wanted by the FBI

Thousands of Mobile Apps Put Unsecured Firebase Databases at Risk

Recent investigations by mobile security experts have unveiled extensive vulnerabilities within Firebase databases used by numerous iOS and Android applications. These deficiencies have exposed over 100 million data records, including unencrypted passwords, user identifiers, geographical data, and in certain instances, sensitive financial information related to banking and cryptocurrency transactions. As…

Read MoreThousands of Mobile Apps Put Unsecured Firebase Databases at Risk

Coupang Breach Triggers Leadership Restructuring

Cybercrime, Fraud Management & Cybercrime, Incident & Breach Response Also: Texas AG Sues Smart TV Manufacturers, Fortinet SSO Flaws Pooja Tikekar (@PoojaTikekar) • December 18, 2025 Image: Shutterstock/ISMG This week, Information Security Media Group presents a roundup of significant cybersecurity breaches globally. Major developments include a leadership transition at Coupang,…

Read MoreCoupang Breach Triggers Leadership Restructuring