The Breach News

WordPress Plugin Warning: Severe SQLi Vulnerability Poses Risk to Over 200,000 Websites

A significant security vulnerability has been identified in the widely used WordPress plugin, Ultimate Member, which boasts over 200,000 active installations. The flaw, labeled CVE-2024-1071, has a critical CVSS score of 9.8, indicating its severity and potential for exploitation. Security researcher Christiaan Swiers is credited with discovering and reporting this…

Read MoreWordPress Plugin Warning: Severe SQLi Vulnerability Poses Risk to Over 200,000 Websites

Experts Reveal Malware Attacks Targeting Colombian Government and Businesses

In a recent development, cybersecurity researchers uncovered an ongoing surveillance initiative targeting Colombian government institutions and private enterprises within the energy and metallurgical sectors. This attack campaign, referred to as “Operation Spalax,” was detailed in a report released Tuesday by ESET, a Slovak cybersecurity firm. The operation first began in…

Read MoreExperts Reveal Malware Attacks Targeting Colombian Government and Businesses

US Telecoms Dismiss Regulation as a Solution to Chinese Hacking Threats

Critical Infrastructure Security, Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Industry Advocates for Voluntary Measures Amid Security Concerns Chris Riotta (@chrisriotta) • December 2, 2025 Image: Shutterstock During a recent Senate hearing, experts highlighted that U.S. telecommunications networks remain susceptible to foreign threats, primarily from nation-states like China. Concerns…

Read MoreUS Telecoms Dismiss Regulation as a Solution to Chinese Hacking Threats

New Vulnerability in Hugging Face Poses Risk of Supply Chain Attacks on AI Models

Recent findings by cybersecurity researchers have unveiled vulnerabilities in the Hugging Face Safetensors conversion service, potentially allowing adversaries to hijack user-submitted machine learning models, effectively leveraging them for supply chain attacks. The implications of this discovery raise significant concerns for businesses relying on the Hugging Face platform for their machine…

Read MoreNew Vulnerability in Hugging Face Poses Risk of Supply Chain Attacks on AI Models

Researchers Reveal Previously Unknown Chinese Malware Involved in Recent Attacks

Recent revelations by cybersecurity experts have uncovered a series of sophisticated cyberattacks orchestrated by a Chinese threat actor, targeting various organizations in Russia and Hong Kong. This campaign has been noted for the deployment of an undocumented backdoor, showcasing the evolving nature of threats in today’s digital landscape. Researchers from…

Read MoreResearchers Reveal Previously Unknown Chinese Malware Involved in Recent Attacks

Russia Aims to Use This Mega Missile to Deter the West, But It Continues to Fail

A Russian intercontinental ballistic missile (ICBM) was launched from an underground silo in southern Russia on Friday as part of a planned test intended to demonstrate the delivery of a dummy warhead to a target nearly 4,000 miles away. However, the missile reportedly failed spectacularly, crashing just short of 4,000…

Read MoreRussia Aims to Use This Mega Missile to Deter the West, But It Continues to Fail