The Breach News

Patched WinRAR Vulnerability Remains Under Active Exploitation Due to Lack of Auto-Updates

Critical Vulnerability in WinRAR Exploited by Cybercriminals Recent reports have highlighted that cybercriminal groups and independent hackers are actively taking advantage of a critical code execution vulnerability in WinRAR, a widely-used file compression tool with a user base of over 500 million. The vulnerability, designated CVE-2018-20250, was patched in the…

Read MorePatched WinRAR Vulnerability Remains Under Active Exploitation Due to Lack of Auto-Updates

Libssh Releases Update to Address Nine Security Vulnerabilities

Libssh2 Addresses Critical Security Vulnerabilities in Latest Update Libssh2, an open-source C library widely utilized for SSHv2 communication, has released a critical update aimed at addressing nine security vulnerabilities. This release underscores the persistent security risks inherent in widely used libraries and highlights the necessity for developers and organizations to…

Read MoreLibssh Releases Update to Address Nine Security Vulnerabilities

Dashlane Reveals How Attackers Successfully Downloaded Encrypted Password Vaults

In a recent cybersecurity incident involving Dashlane, attackers gained access to encrypted user vaults, raising concerns about the robustness of the platform’s security measures. While the strength of users’ master passwords plays a critical role in preventing unauthorized access, it is essential to note that not all users adhere to…

Read MoreDashlane Reveals How Attackers Successfully Downloaded Encrypted Password Vaults

PuTTY Issues Critical Software Update to Address 8 High-Severity Vulnerabilities

The developers behind the widely utilized SSH client program PuTTY have announced the release of an important software update, version 0.71, which addresses eight high-severity security vulnerabilities. This latest version comes nearly 20 months after the last release, underscoring the urgency of updating to the latest iteration to safeguard against…

Read MorePuTTY Issues Critical Software Update to Address 8 High-Severity Vulnerabilities

Meta Quietly Integrated Face Recognition Code for Its Smart Glasses into Millions of Phones

Meta’s Face Recognition Technology Embedded in Popular App Raises Privacy Concerns Meta has stealthily integrated face-recognition capabilities into an application that has been installed on millions of smartphones. Analysis by WIRED reveals that this feature, codenamed “NameTag,” is designed to identify individuals through the camera of its smart glasses. When…

Read MoreMeta Quietly Integrated Face Recognition Code for Its Smart Glasses into Millions of Phones

Medtronic’s Implantable Defibrillators at Risk of Serious Cyber Attacks

On Thursday, the U.S. Department of Homeland Security issued a critical advisory regarding significant vulnerabilities found in a range of heart defibrillators produced by Medtronic, one of the world’s leading medical device manufacturers. The advisory highlighted that these vulnerabilities could potentially enable unauthorized individuals to remotely commandeer the devices, thereby…

Read MoreMedtronic’s Implantable Defibrillators at Risk of Serious Cyber Attacks

Lazarus Group Launches npm Brandjacking Campaign to Target Developers

A recent npm campaign, attributed to North Korea’s Lazarus Group, has highlighted a new strategy in which attackers employ deceptive package names to infiltrate developers’ systems and software build environments. This tactic poses significant risks for organizations reliant on JavaScript tools, as many developers may unwittingly install these malicious packages.…

Read MoreLazarus Group Launches npm Brandjacking Campaign to Target Developers

Magento SQL Injection Vulnerability Detected – Update Your Sites Immediately

Security Alert: Critical Vulnerabilities Discovered in Magento E-Commerce Platform Business owners operating online retail websites on the Magento platform need to be alerted to significant vulnerabilities unveiled yesterday. Magento, owned by Adobe since 2018, has released updates addressing 37 newly identified security flaws impacting its widely used content management software.…

Read MoreMagento SQL Injection Vulnerability Detected – Update Your Sites Immediately

Struggling to Understand Dashlane’s Vault Theft Notification? You’re Not Alone.

Security Advisory: Dashlane’s Encrypted Vaults Compromised in Brute Force Attack On May 31, 2026, Dashlane, a widely-used password management service, issued a security advisory revealing that attackers had gained access to 20 encrypted user vaults. The incident involved a brute force attack targeting specific user accounts with the aim of…

Read MoreStruggling to Understand Dashlane’s Vault Theft Notification? You’re Not Alone.