The Breach News

Commercial Spyware ‘Landfall’ Exploited Vulnerabilities in Samsung Phones for Nearly a Year

New Vulnerability Exposes Samsung Phones to Espionage In April 2025, a significant cybersecurity vulnerability was discovered in Samsung’s image processing library, marking a major concern for users of the brand’s mobile devices. This flaw has been linked to a sophisticated zero-click exploit that allows malicious agents to penetrate devices without…

Read MoreCommercial Spyware ‘Landfall’ Exploited Vulnerabilities in Samsung Phones for Nearly a Year

Facebook Faces $18.6 Million GDPR Penalty Due to 12 Data Breaches in 2018

On Tuesday, the Irish Data Protection Commission (DPC) imposed a fine of €17 million (approximately $18.6 million) on Meta Platforms, the parent company of Facebook and WhatsApp, due to a series of security failures that breached the European Union’s General Data Protection Regulation (GDPR). The DPC determined that Meta Platforms…

Read MoreFacebook Faces $18.6 Million GDPR Penalty Due to 12 Data Breaches in 2018

Why Microsegmentation Remains an Elusive Goal for Many IT Teams

Governance & Risk Management, Network Firewalls, Network Access Control, Security Operations Audit Challenges, Legacy Policies, and Limited Scope Disrupt Microsegmentation Adoption Suparna Goswami (gsuparna) • November 6, 2025 Despite its promise for architectural clarity, microsegmentation often introduces operational complexities and challenges related to policy management, audits, and mounting technical debt.…

Read MoreWhy Microsegmentation Remains an Elusive Goal for Many IT Teams

ID Verification Laws are Sparking a New Wave of Breaches

In a landmark incident underscoring the challenges of data protection in today’s regulatory landscape, Discord has disclosed a significant data breach. This breach, revealed in early October 2025, stemmed from the compromise of one of its third-party customer service providers, resulting in unauthorized access to sensitive user information. Victims included…

Read MoreID Verification Laws are Sparking a New Wave of Breaches

New GitLab Vulnerability Poses Risk of Unauthorized CI/CD Pipeline Execution

GitLab Issues Significant Security Updates Addressing Vulnerabilities GitLab has issued critical security updates for its Community Edition (CE) and Enterprise Edition (EE), specifically targeting eight identified vulnerabilities. Notably, one severe flaw allows unauthorized execution of Continuous Integration and Continuous Delivery (CI/CD) pipelines across arbitrary branches. This vulnerability, cataloged as CVE-2024-9164,…

Read MoreNew GitLab Vulnerability Poses Risk of Unauthorized CI/CD Pipeline Execution

Ukrainian Secret Service Detains Hacker Supporting Russian Invaders

The Security Service of Ukraine (SBU) has apprehended an individual identified as a hacker, who allegedly provided critical technical support to Russian military forces by facilitating mobile communication within Ukrainian territory. This operation reportedly involved the dissemination of messages to Ukrainian officials, encouraging them to surrender and collaborate with Russian…

Read MoreUkrainian Secret Service Detains Hacker Supporting Russian Invaders

Vulnerability in Amazon WorkSpaces for Linux Enables Extraction of Valid Authentication Tokens

A severe security vulnerability has been identified in the Amazon WorkSpaces client for Linux, posing a substantial risk for organizations utilizing AWS’s virtual desktop infrastructure. This flaw, designated as CVE-2025-12779, allows malicious local users to extract valid authentication tokens, leading to unauthorized access to other users’ Workspace sessions. On November…

Read MoreVulnerability in Amazon WorkSpaces for Linux Enables Extraction of Valid Authentication Tokens