The Breach News

Apple Issues Essential iOS and iPadOS Updates to Address VoiceOver Password Security Flaw

Apple Releases Critical Security Updates Addressing Password Vulnerabilities and Audio Privacy Issues Apple has recently issued important updates for iOS and iPadOS targeting two significant security vulnerabilities. One of these flaws has the potential to expose users’ saved passwords via the VoiceOver assistive technology, raising alarm among cybersecurity experts. The…

Read MoreApple Issues Essential iOS and iPadOS Updates to Address VoiceOver Password Security Flaw

NoxPlayer Supply Chain Attack Possibly Linked to Gelsemium Hackers

Emergence of Gelsemium: A New Player in Supply Chain Cyberattacks A formidable new cyber espionage group, known as Gelsemium, has recently come under scrutiny following its association with a supply chain attack targeting the NoxPlayer Android emulator. This malicious campaign was initially revealed earlier this year and has raised significant…

Read MoreNoxPlayer Supply Chain Attack Possibly Linked to Gelsemium Hackers

Unveiling AI Secrets Hidden in Encrypted Shadows

Recent developments in the realm of artificial intelligence have brought to light a serious vulnerability affecting encrypted communications. Dubbed ‘Whisper Leak,’ this sophisticated side-channel attack, disclosed by Microsoft researchers, has the potential to glean sensitive information from encrypted traffic directed at large language models (LLMs). As outlined in a recent…

Read MoreUnveiling AI Secrets Hidden in Encrypted Shadows

Qualcomm Calls on OEMs to Address Critical DSP and WLAN Vulnerabilities as Exploits Are Underway

Qualcomm has issued security updates responding to nearly two dozen vulnerabilities affecting both proprietary and open-source components. Among these, a particularly severe flaw has been identified, which is reportedly under active exploitation in the field. This high-severity vulnerability, designated as CVE-2024-43047 with a CVSS score of 7.8, has been characterized…

Read MoreQualcomm Calls on OEMs to Address Critical DSP and WLAN Vulnerabilities as Exploits Are Underway

Malware Attack Targeting South Korean Entities Attributed to Andariel Group

A recent malware campaign has been uncovered, targeting South Korean organizations, specifically attributed to the North Korean hacking group Andariel. This development highlights the ongoing evolution of tactics employed by state-sponsored actors, particularly within the Lazarus Group, which has been consistently adapting its methodologies to enhance operational effectiveness. Kaspersky, a…

Read MoreMalware Attack Targeting South Korean Entities Attributed to Andariel Group

For OT Cyber Defenders, Insufficient Data Poses the Greatest Threat

The State of Operational Technology Security: A Sector Lagging Behind As cyber defenders focus on securing operational technology (OT) and industrial control systems (ICS), a significant challenge emerges: the scarcity of actionable data. Unlike their IT counterparts, OT operators often lack comprehensive logging capabilities, which hampers incident response efforts. According…

Read MoreFor OT Cyber Defenders, Insufficient Data Poses the Greatest Threat