The Breach News

Adobe Releases Urgent Patches for ColdFusion, Flash Player, and Campaign

This week marks the latest Patch Tuesday, which brings significant updates from Adobe aimed at addressing numerous security vulnerabilities across its key software products. In June 2019, Adobe unveiled updates to fix 11 identified vulnerabilities spread across Adobe ColdFusion, Flash Player, and Adobe Campaign. Among these vulnerabilities, three critical flaws…

Read MoreAdobe Releases Urgent Patches for ColdFusion, Flash Player, and Campaign

Trivy Exploit Distributes Infostealer through Docker, Initiates Worm and Kubernetes Wiper

Recent cybersecurity investigations have identified malicious artifacts that infiltrated Docker Hub, stemming from the Trivy supply chain attack. This incident illustrates the expanding impact such breaches can have on developer environments, raising significant concerns for businesses leveraging open-source tools. The last known untainted version of Trivy, a widely used open-source…

Read MoreTrivy Exploit Distributes Infostealer through Docker, Initiates Worm and Kubernetes Wiper

RAMBleed Attack: Exploiting Bit Flips to Retrieve Sensitive Data from Computer Memory

New Cyber Threat: RAMBleed Side-Channel Attack Exposes Vulnerabilities in DRAM A team of cybersecurity experts has recently unveiled a significant side-channel attack targeting dynamic random-access memory (DRAM), revealing serious implications for system security. Dubbed RAMBleed and associated with CVE-2019-0174, this attack enables malicious software residing on a modern computer to…

Read MoreRAMBleed Attack: Exploiting Bit Flips to Retrieve Sensitive Data from Computer Memory

We Discovered Eight Attack Vectors in AWS Bedrock: Potential Threats and Exploits Explored

Amazon Web Services (AWS) has launched Bedrock, a platform designed for developing AI-powered applications, granting developers access to foundation models and the essential tools for directly integrating those models with enterprise data and systems. While this connectivity amplifies its capabilities, it simultaneously exposes Bedrock to various security threats. When an…

Read MoreWe Discovered Eight Attack Vectors in AWS Bedrock: Potential Threats and Exploits Explored

Firefox Issues Urgent Patch Update to Address Ongoing Zero-Day Vulnerabilities

Critical Firefox Update Released to Address New Zero-Day Vulnerability On June 21, 2019, Mozilla announced an essential update for its Firefox web browser, specifically version 67.0.4, aimed at patching a second zero-day vulnerability. This release comes closely on the heels of Firefox 67.0.3 and Firefox Extended Support Release (ESR) 60.7.1,…

Read MoreFirefox Issues Urgent Patch Update to Address Ongoing Zero-Day Vulnerabilities

Dismantling of a Botnet Comprised of Over 17 Million Devices

Authorities in the Netherlands have successfully dismantled a significant botnet that encompassed over 17 million compromised devices, orchestrated through 200 servers. This concerted operation involved collaboration between the police and the National Cyber Security Center (NCSC), aiming to address the growing threat of large-scale cybercrime networks. The operation was made…

Read MoreDismantling of a Botnet Comprised of Over 17 Million Devices

U.S. Imposes 6.75-Year Sentence on Russian Hacker for Involvement in $9 Million Ransomware Attack

A 26-year-old Russian national, Aleksei Olegovich Volkov, has been sentenced to 6.75 years in prison in the United States for his involvement with prominent cybercrime groups, including the notorious Yanluowang ransomware collective. This sentencing comes in light of his pivotal role in orchestrating multiple cyberattacks targeting U.S. businesses and organizations.…

Read MoreU.S. Imposes 6.75-Year Sentence on Russian Hacker for Involvement in $9 Million Ransomware Attack

Urgent: Recent Oracle WebLogic Vulnerability Exploited — Update Immediately

Oracle Deploys Critical WebLogic Server Update Amid Exploitation Threats Oracle has issued an urgent software update to address a newly identified critical vulnerability in its WebLogic Server, which is a Java-based multi-tier enterprise application server utilized by businesses to efficiently roll out products and services across both cloud and traditional…

Read MoreUrgent: Recent Oracle WebLogic Vulnerability Exploited — Update Immediately