The Breach News

Urgent Zero-Day Vulnerability in Apache OfBiz ERP Poses Security Risk to Businesses

Zero-Day Vulnerability Discovered in Apache OfBiz ERP System A serious zero-day vulnerability has been identified in Apache OfBiz, an open-source Enterprise Resource Planning (ERP) system. This flaw poses significant risks as it could potentially allow attackers to bypass essential authentication safeguards. The vulnerability is classified as CVE-2023-51467, linked specifically to…

Read MoreUrgent Zero-Day Vulnerability in Apache OfBiz ERP Poses Security Risk to Businesses

The Hyper-Realistic AI Face Swapping Platform Fueling Romance Scams

AI Face-Swapping App Linked to Cybercrime in Southeast Asia The artificial intelligence application Haotian, designed for face-swapping capabilities, has emerged as a major player in the realm of online fraud. This Chinese-language app has reportedly generated millions of dollars by providing its technology through platforms like Telegram, facilitating integration with…

Read MoreThe Hyper-Realistic AI Face Swapping Platform Fueling Romance Scams

5 Essential Cybersecurity Steps for Every SMB

Fraud Management & Cybercrime, Governance & Risk Management, Multi-factor & Risk-based Authentication Practical Steps to Enhance Security and Resilience Sean D. Mack • December 17, 2025 Image: Shutterstock Leaders of small and mid-sized enterprises (SMEs) frequently assert, “We’re too small to be a target.” This misconception endangers their organizations, especially…

Read More5 Essential Cybersecurity Steps for Every SMB

Settlements Reached in Class Action Data Breach Cases Involving Three Healthcare Providers – The HIPAA Journal

Class Action Settlements in Healthcare Data Breaches In a recent development, three healthcare providers have reached settlements in a class action lawsuit concerning data breaches that compromised sensitive patient information. This agreement reflects a growing concern over patient data security and the responsibilities of healthcare entities in safeguarding personal health…

Read MoreSettlements Reached in Class Action Data Breach Cases Involving Three Healthcare Providers – The HIPAA Journal

New Terrapin Vulnerability Could Allow Attackers to Downgrade SSH Protocol Security

Recent research from Ruhr University Bochum has revealed a critical security vulnerability in the Secure Shell (SSH) protocol, which is widely used for secure communications over untrusted networks. The vulnerability, designated as Terrapin (CVE-2023-48795), exhibits a CVSS score of 5.9, signaling its potential significance in the cybersecurity landscape. This vulnerability…

Read MoreNew Terrapin Vulnerability Could Allow Attackers to Downgrade SSH Protocol Security