The Breach News

Adobe Issues Urgent Updates for Acrobat Reader, Photoshop, Bridge, and ColdFusion

In a significant move outside of the regular Patch Tuesday schedule, Adobe has released an extensive set of out-of-band software updates aimed at addressing a total of 41 newly discovered security vulnerabilities across six different products. This proactive approach follows Adobe’s recent communication regarding an impending security update for its…

Read MoreAdobe Issues Urgent Updates for Acrobat Reader, Photoshop, Bridge, and ColdFusion

Severe RCE Vulnerability Impacts Millions of OpenWrt-based Networking Devices

In a significant cybersecurity revelation, a researcher has unveiled critical technical details regarding a remote code execution vulnerability impacting OpenWrt, a commonly utilized Linux-based operating system for network devices such as routers and gateways. This vulnerability, cataloged as CVE-2020-7982, is tied to the OPKG package manager’s flaw in its integrity…

Read MoreSevere RCE Vulnerability Impacts Millions of OpenWrt-based Networking Devices

Chaos Unfolds as Cyberattack Disrupts Canvas Learning Platform During Finals

Cyberattack Disrupts US Educational Institutions Amid Final Exams A significant cyberattack impacted schools and universities across the United States on Thursday, coinciding with student final exams. The online learning platform, Canvas, which is widely used in educational settings, experienced substantial disruptions as students prepared for crucial assessments. Instructure, the parent…

Read MoreChaos Unfolds as Cyberattack Disrupts Canvas Learning Platform During Finals

CISA Alerts: Patched Pulse Secure VPNs May Still Leave Organizations Vulnerable to Hackers

The United States Cybersecurity and Infrastructure Security Agency (CISA) has recently issued an advisory urging organizations to update all Active Directory credentials to enhance security against cyberattacks exploiting a known remote code execution (RCE) vulnerability within Pulse Secure VPN servers, regardless of whether they have applied patches. This warning follows…

Read MoreCISA Alerts: Patched Pulse Secure VPNs May Still Leave Organizations Vulnerable to Hackers

Severe SaltStack RCE Vulnerability (CVSS Score 10) Impacts Thousands of Data Centers

Two critical security vulnerabilities have recently been uncovered in the open-source **SaltStack Salt configuration framework**, posing significant risks to servers operating in both data center and cloud settings. These vulnerabilities could potentially enable threat actors to execute arbitrary code remotely. The vulnerabilities, disclosed by F-Secure researchers this past Thursday, were…

Read MoreSevere SaltStack RCE Vulnerability (CVSS Score 10) Impacts Thousands of Data Centers

Introducing Rassvet: Russia’s Response to Starlink

In late March, Russian company Bureau 1440 successfully launched the first 16 satellites of its broadband internet constellation known as Rassvet, which observers have compared to SpaceX’s Starlink. This initiative aims to establish a global internet network, potentially masking larger strategic objectives, including military and communication control. The launch occurred…

Read MoreIntroducing Rassvet: Russia’s Response to Starlink

Billions of Devices at Risk: New Bluetooth Vulnerability Uncovered

Researchers at École Polytechnique Fédérale de Lausanne (EPFL) have uncovered a significant security vulnerability in Bluetooth technology that can enable attackers to spoof devices that were previously paired. This flaw potentially puts over a billion modern devices at risk of unauthorized access. The vulnerability, referred to as the Bluetooth Impersonation…

Read MoreBillions of Devices at Risk: New Bluetooth Vulnerability Uncovered