The Breach News

Envoy Air (American Airlines) Confirms Oracle EBS Zero-Day Breach Linked to Cl0p Group

On October 17, 2025, Envoy Air, a Texas-based regional airline and the largest carrier under American Airlines, confirmed that it was recently compromised due to a series of cyberattacks exploiting a zero-day vulnerability in a major corporate software application. The hacks were executed by CL0P, a notorious ransomware group known…

Read MoreEnvoy Air (American Airlines) Confirms Oracle EBS Zero-Day Breach Linked to Cl0p Group

JumpCloud Revokes API Keys in Response to Ongoing Cybersecurity Incident

JumpCloud Responds to Cybersecurity Incident Affecting Clients JumpCloud, a cloud-based identity and access management provider, has taken swift action in response to a significant cybersecurity incident that has impacted a number of its clients. The breach has prompted the company to reset the application programming interface (API) keys for all…

Read MoreJumpCloud Revokes API Keys in Response to Ongoing Cybersecurity Incident

Salt Typhoon Strikes European Telecom Sector

Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Darktrace Reports on Compromise of Citrix NetScaler Gateway Akshaya Asokan (asokan_akshaya) • October 20, 2025 Image: Shutterstock Recent reports from the managed threat detection firm Darktrace indicate that a persistent campaign by the Chinese cyber espionage group known as Salt Typhoon continues…

Read MoreSalt Typhoon Strikes European Telecom Sector

Hackers Exploit Citrix Vulnerability and Snappybee Malware to Compromise European Telecom Network

October 21, 2025Ravie LakshmananCyber Espionage / Network Security A European telecommunications company has reportedly fallen victim to a cyber intrusion attributed to a threat actor associated with the China-linked group known as Salt Typhoon. This incident, as reported by Darktrace, took place during the first week of July 2025. Attackers…

Read MoreHackers Exploit Citrix Vulnerability and Snappybee Malware to Compromise European Telecom Network

Serious SailPoint IdentityIQ Vulnerability Allows Unauthorized File Access

Critical Vulnerability Discovered in SailPoint’s IdentityIQ Software A significant security vulnerability has been identified in SailPoint’s IdentityIQ identity and access management (IAM) software, potentially exposing sensitive data stored in application directories. The flaw, designated CVE-2024-10905, carries a maximum CVSS score of 10.0, highlighting its critical severity. This vulnerability affects various…

Read MoreSerious SailPoint IdentityIQ Vulnerability Allows Unauthorized File Access

WIRTE Hacker Group Attacks Government, Legal, and Financial Institutions in the Middle East

Stealth Malware Campaign Targets Middle Eastern Entities A sophisticated malware campaign has been uncovered, targeting government bodies, military organizations, law firms, and financial institutions predominantly in the Middle East. Initiated as early as 2019, the campaign leverages malicious Microsoft Excel and Word documents to infiltrate victim networks. Kaspersky, a Russian…

Read MoreWIRTE Hacker Group Attacks Government, Legal, and Financial Institutions in the Middle East

JumpCloud Attributes Security Breach to ‘Advanced Nation-State’ Actor

In a significant security breach, JumpCloud has confirmed that a sophisticated nation-state actor infiltrated its systems, targeting a select group of its customers. Shortly following a reset of API keys for affected clients, Bob Phan, Chief Information Security Officer (CISO) at JumpCloud, stated, “The adversary gained unauthorized access to our…

Read MoreJumpCloud Attributes Security Breach to ‘Advanced Nation-State’ Actor