The Breach News

AI SOC Agents Reduce Alert Response Time, Study Reveals

Artificial Intelligence & Machine Learning, Next-Generation Technologies & Secure Development, Security Operations Troy Leach of the Cloud Security Alliance Discusses AI’s Impact on SOC Analysts’ Efficiency Anna Delaney (annamadeline) • November 5, 2025 Troy Leach, Chief Strategy Officer, Cloud Security Alliance Security operations centers (SOCs) face an increasing demand for…

Read MoreAI SOC Agents Reduce Alert Response Time, Study Reveals

CISA Issues Alert on Ongoing Exploitation of Vulnerability in SolarWinds Help Desk Software

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced on Tuesday the addition of a serious vulnerability affecting SolarWinds Web Help Desk (WHD) software to its Known Exploited Vulnerabilities (KEV) catalog. This decision comes amid indications of active exploitation of the flaw. Identified as CVE-2024-28987, this vulnerability has been assigned…

Read MoreCISA Issues Alert on Ongoing Exploitation of Vulnerability in SolarWinds Help Desk Software

Experts Identify Malware Threats Targeting Corporate Networks in Latin America

New Espionage Campaign Unveiled: Targets Corporate Networks in Venezuela On Thursday, cybersecurity researchers revealed an ongoing espionage campaign primarily aimed at corporate networks in Spanish-speaking countries, with Venezuela being the focal point. This newly identified threat, named “Bandidos” by security firm ESET, employs an enhanced variant of the notorious Bandook…

Read MoreExperts Identify Malware Threats Targeting Corporate Networks in Latin America

T-Mobile Confirms Lapsus$ Hackers Breached Internal Tools and Accessed Source Code

T-Mobile has confirmed it fell victim to a security breach in March, attributed to the notorious LAPSUS$ hacking group, known for its sophisticated cyber exploits. This assertion comes following revelations by investigative journalist Brian Krebs, who disclosed internal communications from LAPSUS$ that corroborate multiple incursions into T-Mobile’s systems throughout March,…

Read MoreT-Mobile Confirms Lapsus$ Hackers Breached Internal Tools and Accessed Source Code

Lawsuits and Investigations Surge Following Conduent Cyberattack

Data Breach Notification, Data Privacy, Data Security 2025 Sees Major Data Breach Affecting 10.5 Million Individuals, Multiple Insurers, State Authorities Marianne Kolbasuk McGee (HealthInfoSec) • November 4, 2025 Conduent, a publicly traded entity spun off from Xerox in 2017, is facing a surge of class-action lawsuits following a data breach…

Read MoreLawsuits and Investigations Surge Following Conduent Cyberattack

GitHub Addresses Critical Vulnerability in Enterprise Server That Permits Unauthorized Access

GitHub Security Updates Address Critical Vulnerabilities in Enterprise Server GitHub has announced crucial security updates for its Enterprise Server (GHES), responding to multiple vulnerabilities, including a severe flaw that could lead to unauthorized access. The updates aim to enhance user protection, particularly against a vulnerability identified as CVE-2024-9487, which has…

Read MoreGitHub Addresses Critical Vulnerability in Enterprise Server That Permits Unauthorized Access

Kaseya Issues Patches for Vulnerabilities Targeted in Major Ransomware Attack

In a significant cybersecurity response, Kaseya, a software vendor based in Florida, released urgent updates on Sunday to rectify critical vulnerabilities in its Virtual System Administrator (VSA) solution. This action follows a massive ransomware incident that exploited VSA to target up to 1,500 businesses globally, a situation categorized as a…

Read MoreKaseya Issues Patches for Vulnerabilities Targeted in Major Ransomware Attack