The Breach News

Microsoft Alerts on North Korean Cyberattacks Targeting JetBrains TeamCity Vulnerability

Cybersecurity experts have reported that North Korean threat actors are leveraging a critical vulnerability in JetBrains TeamCity, specifically CVE-2023-42793, which carries a severe CVSS score of 9.8. This exploitation allows attackers to breach unprotected servers, with campaigns attributed to two distinct groups: Diamond Sleet, also known as Labyrinth Chollima, and…

Read MoreMicrosoft Alerts on North Korean Cyberattacks Targeting JetBrains TeamCity Vulnerability

Tor Browser 8.5.2 Released — Update to Address Critical Firefox Security Flaw

Important Update (June 21, 2019) ➤ The Tor Project announced on Friday the release of its latest update, Tor Browser 8.5.3, addressing a significant Firefox zero-day vulnerability identified earlier in the week. This update follows Mozilla’s recent patches for Firefox versions 67.0.3 and 60.7.1, which rectified a critical actively-exploited security…

Read MoreTor Browser 8.5.2 Released — Update to Address Critical Firefox Security Flaw

Russian Hackers Introduce ‘Tainted Leaks’ – From Phishing to Propaganda

Recent findings reveal a sophisticated disinformation campaign aimed at discrediting critics of the Russian state while compromising sensitive data. Security researchers have linked these activities to a suspected Russian government-sponsored espionage initiative, though definitive evidence of state involvement remains unproven. Notably, these operations share characteristics with the tactics employed by…

Read MoreRussian Hackers Introduce ‘Tainted Leaks’ – From Phishing to Propaganda

Seven Steps to Achieve AI Supply Chain Visibility Before a Breach Necessitates Action – VentureBeat

Seven Steps to Achieve AI Supply Chain Visibility Before a Breach Occurs In an era dominated by technological advancement, the vulnerability of supply chains to cyber threats has emerged as a critical concern for businesses. The latest discourse on this issue centers around establishing robust AI-driven visibility into supply chains…

Read MoreSeven Steps to Achieve AI Supply Chain Visibility Before a Breach Necessitates Action – VentureBeat

Cisco Zero-Day Vulnerability Targeted to Deploy Malicious Lua Backdoor on Thousands of Devices

Cisco has issued an urgent warning regarding a severe zero-day vulnerability in its IOS XE software, which is currently being exploited by an unknown actor to introduce a malicious Lua-based implant on affected devices. The vulnerability, designated as CVE-2023-20273, carries a CVSS score of 7.2 and is associated with privilege…

Read MoreCisco Zero-Day Vulnerability Targeted to Deploy Malicious Lua Backdoor on Thousands of Devices

Firefox 67.0.4 Launched — Mozilla Addresses Second 0-Day Vulnerability This Week

A critical update for the Firefox web browser is urgent, as Mozilla has issued a warning to users regarding a newly discovered zero-day vulnerability. This update comes just days after the release of a fix for another actively exploited vulnerability within Firefox 67.0.3. The most recent vulnerability, identified as CVE-2019-11708,…

Read MoreFirefox 67.0.4 Launched — Mozilla Addresses Second 0-Day Vulnerability This Week