The Breach News

Reddit Breach: User Emails, Passwords, and Private Messages Compromised

In a significant cybersecurity incident, Reddit recently confirmed a data breach occurring in June that compromised user information, including current email addresses and data from a 2007 backup that contains usernames and hashed passwords. This breach appears to be a reaction from an aggrieved party dissatisfied with Reddit’s account ban…

Read MoreReddit Breach: User Emails, Passwords, and Private Messages Compromised

Nation-State Cybercrime Exploits Linked to React2Shell

Cybercrime, Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Vercel Issues Warning: Two Additional Vulnerabilities in React Server Components Urgently Require Patching Mathew J. Schwartz (@euroinfosec) • December 15, 2025 Image: Shutterstock/React/ISMG Experts warn that the React2Shell vulnerability is being exploited en masse by state-sponsored attackers connected to China, North…

Read MoreNation-State Cybercrime Exploits Linked to React2Shell

Deadline Approaching for AT&T Customers to Claim Their Compensation – PhoneArena

Deadline Approaching for AT&T Customers to Claim Compensation AT&T customers are nearing the end of their opportunity to receive compensation related to a significant data breach that has impacted numerous individuals. This incident has raised substantial concerns regarding the security measures in place and the responsibility of companies to protect…

Read MoreDeadline Approaching for AT&T Customers to Claim Their Compensation – PhoneArena

New Proof of Concept Exploit for Apache OfBiz Vulnerability Threatens ERP Systems

Recent developments in cybersecurity reveal a critical vulnerability affecting the Apache OfBiz open-source Enterprise Resource Planning (ERP) system. Researchers at VulnCheck have successfully created proof-of-concept (PoC) code exploiting the flaw, identified as CVE-2023-51467. This vulnerability, which carries a CVSS score of 9.8, allows attackers to execute a memory-resident payload, potentially…

Read MoreNew Proof of Concept Exploit for Apache OfBiz Vulnerability Threatens ERP Systems

New Raccoon Vulnerability May Enable Attackers to Compromise SSL/TLS Encryption

New Timing Vulnerability Discovered in TLS: Raccoon Attack A recent study has revealed a significant timing vulnerability affecting the Transport Layer Security (TLS) protocol, potentially allowing attackers to compromise encryption and access sensitive communications under specific scenarios. Researchers have labeled this exploit the “Raccoon Attack,” targeting server-side operations in TLS…

Read MoreNew Raccoon Vulnerability May Enable Attackers to Compromise SSL/TLS Encryption

700Credit Data Breach Exposes Personal Information of 5.6 Million Consumers

A significant security incident has impacted 700Credit, a Fintech and data services entity based in Michigan, USA, which facilitates consumer financing options for dealerships in sectors such as auto, RV, powersports, and marine. According to the company’s breach notification, an “unauthorized access” event resulted in the copying of specific customer…

Read More700Credit Data Breach Exposes Personal Information of 5.6 Million Consumers

AI Governance: Accelerating Progress, Not Bureaucracy

Agentic AI, Artificial Intelligence & Machine Learning, Next-Generation Technologies & Secure Development Insights from ServiceNow’s Neeraj Jain on Managing Risk and Ensuring Real-Time Data Access for AI Michael Novinson (MichaelNovinson) • December 15, 2025 Neeraj Jain, Director of Product Management, Hyperscalers and Multi-Cloud, ServiceNow Organizations that incorporate governance into their…

Read MoreAI Governance: Accelerating Progress, Not Bureaucracy