The Breach News

Over 300K Prometheus Instances Exposed: Online Leak of Credentials and API Keys

Recent cybersecurity reports indicate a significant vulnerability affecting numerous servers running the Prometheus monitoring and alerting toolkit. Security researchers have identified that thousands of these servers are susceptible to data leakage, denial-of-service (DoS), and remote code execution (RCE) attacks. Experts from Aqua Security, Yakir Kadkoda and Assaf Morag, disclosed that…

Read MoreOver 300K Prometheus Instances Exposed: Online Leak of Credentials and API Keys

Chinese APT Hackers Exploit Log4Shell to Attack Academic Institution

A sophisticated cyber intrusion attributed to a China-based threat group, identified as Aquatic Panda, has been detected leveraging severe vulnerabilities in the Apache Log4j logging system. This attack vector enabled the adversaries to execute various post-exploitation activities, including reconnaissance operations and credential harvesting from their targets. The cybersecurity firm CrowdStrike…

Read MoreChinese APT Hackers Exploit Log4Shell to Attack Academic Institution

One Republican Now Oversees a Significant Portion of US Election Infrastructure

Dominion Voting Systems Acquired by Knowink CEO: Implications for Election Integrity Last week, the acquisition of Dominion Voting Systems by Scott Leiendecker, founder and CEO of Knowink—an electronic poll book manufacturer based in Missouri—has raised questions among election integrity advocates concerning potential impacts on U.S. voter confidence and the electoral…

Read MoreOne Republican Now Oversees a Significant Portion of US Election Infrastructure

HelloKitty Ransomware Group Targets Vulnerabilities in Apache ActiveMQ

Recent warnings from cybersecurity experts indicate that a significant security vulnerability in Apache ActiveMQ, an open-source message broker service, is being actively exploited, potentially allowing remote code execution. This vulnerability, identified as CVE-2023-46604, has drawn attention due to its critical nature. The cybersecurity firm Rapid7 reported that attackers have made…

Read MoreHelloKitty Ransomware Group Targets Vulnerabilities in Apache ActiveMQ

Physician Practices to Pay $50 Million to Resolve Cyberattack Lawsuits

Data Privacy , Data Security , Healthcare 2022 Ransomware Attack, Data Theft Affected 3.4 Million Patients Marianne Kolbasuk McGee (HealthInfoSec) • October 17, 2025     Regal Medical Group is among nine physician practices affiliated with Heritage Provider Network paying nearly $50 million to settle litigation involving a 2022 hacking…

Read MorePhysician Practices to Pay $50 Million to Resolve Cyberattack Lawsuits

When Transparency Backfires: Reassessing the Ethics of Acknowledging Failure – Techerati

When Transparency Hurts: The Emerging Ethics of Acknowledging Failure In an era where data integrity and cybersecurity are paramount, recent discussions have arisen around the ethics of transparency in admitting organizational failures. As businesses navigate the complex landscape of cybersecurity threats, recognizing and disclosing data breaches or vulnerabilities can be…

Read MoreWhen Transparency Backfires: Reassessing the Ethics of Acknowledging Failure – Techerati

Severe OpenWrt Vulnerability Leaves Devices Vulnerable to Malicious Firmware Injection

A significant security vulnerability has been identified in the Attended Sysupgrade (ASU) feature of OpenWrt. If exploited, this flaw could enable the distribution of compromised firmware packages, posing a threat to users of this popular open-source Linux-based OS. The vulnerability, assigned the identifier CVE-2024-54143, has a critical CVSS score of…

Read MoreSevere OpenWrt Vulnerability Leaves Devices Vulnerable to Malicious Firmware Injection

Microsoft Cautions on Ongoing Attacks Targeting Apache Log4j Vulnerabilities

Cybersecurity experts are raising alarms over ongoing attempts by both nation-state actors and commodity attackers to exploit vulnerabilities in the Log4j open-source logging framework, a situation that poses significant risks to organizations worldwide. Microsoft has reported a surge in exploitation attempts aimed at deploying malware on susceptible systems, highlighting the…

Read MoreMicrosoft Cautions on Ongoing Attacks Targeting Apache Log4j Vulnerabilities

Nation-State Hackers Distribute Malware via “Bulletproof” Blockchains

Cybersecurity Alert: North Korean Cyber Operatives Exploit Smart Contracts for Malware Deployment Recent investigations by Google have uncovered a sophisticated malware delivery system leveraging smart contracts on the Ethereum and BNB Smart Chain blockchains. The cost-effectiveness of creating or modifying these contracts—often below $2 per transaction—marks a stark contrast to…

Read MoreNation-State Hackers Distribute Malware via “Bulletproof” Blockchains