The Breach News

Microsoft Issues Patches for Critical ‘Wormable Vulnerability’ and 78 Additional Security Concerns

Microsoft Releases Security Updates Addressing 79 Vulnerabilities Microsoft has announced its monthly security updates, releasing patches for a total of 79 CVE-listed vulnerabilities across its software platforms. This month’s updates come with particular urgency as they address a critical wormable vulnerability that can enable malware to spread autonomously from one…

Read MoreMicrosoft Issues Patches for Critical ‘Wormable Vulnerability’ and 78 Additional Security Concerns

New Class of CPU Vulnerabilities Impacts Nearly All Intel Processors Since 2011

Recent research has unveiled an alarming class of speculative execution vulnerabilities that affect Intel processors, impacting all modern devices, including those produced by Apple. These vulnerabilities build upon the widely publicized Spectre and Meltdown flaws, which were discovered last year and led to widespread concern regarding the security risks faced…

Read MoreNew Class of CPU Vulnerabilities Impacts Nearly All Intel Processors Since 2011

PoC Exploit for Unpatched Windows 10 Zero-Day Vulnerability Released Online

An anonymous hacker known by the pseudonym “SandboxEscaper” has disclosed proof-of-concept exploit code for a newly identified zero-day vulnerability impacting the Windows 10 operating system. This marks the hacker’s fifth public disclosure of a zero-day exploit related to Windows within a year. The details of this vulnerability were made available…

Read MorePoC Exploit for Unpatched Windows 10 Zero-Day Vulnerability Released Online

Almost 1 Million Computers Remain Exposed to “Wormable” BlueKeep RDP Vulnerability

Nearly one million Windows systems remain unpatched and vulnerable to a critical remote code execution vulnerability in the Windows Remote Desktop Protocol (RDP), known as BlueKeep and tracked as CVE-2019-0708. This situation persists two weeks after Microsoft released a security patch aimed at addressing the vulnerability. Should this flaw be…

Read MoreAlmost 1 Million Computers Remain Exposed to “Wormable” BlueKeep RDP Vulnerability

Your Linux System is Vulnerable: Just Opening a File in Vim or Neovim Could Lead to Hacking

Linux users are currently facing a significant security risk. A newly uncovered vulnerability in the widely-used command-line text editors Vim and Neovim poses a serious threat, particularly for those who have not recently updated their systems. Discovered by security researcher Armin Razmjou, this high-severity bug (CVE-2019-12735) could allow unauthorized command…

Read MoreYour Linux System is Vulnerable: Just Opening a File in Vim or Neovim Could Lead to Hacking

FBI and Europol Take Down LeakBase Forum for Trading Stolen Credentials

A significant law enforcement initiative has led to the shutdown of **LeakBase**, one of the largest cybercriminal forums globally, where illicit transactions involving stolen data and cybercrime tools were rampant. As reported by the U.S. Department of Justice (DoJ), the LeakBase forum boasted a membership exceeding 142,000, with over 215,000…

Read MoreFBI and Europol Take Down LeakBase Forum for Trading Stolen Credentials

Adobe Releases Urgent Patches for ColdFusion, Flash Player, and Campaign

This week marks the latest Patch Tuesday, which brings significant updates from Adobe aimed at addressing numerous security vulnerabilities across its key software products. In June 2019, Adobe unveiled updates to fix 11 identified vulnerabilities spread across Adobe ColdFusion, Flash Player, and Adobe Campaign. Among these vulnerabilities, three critical flaws…

Read MoreAdobe Releases Urgent Patches for ColdFusion, Flash Player, and Campaign

Trivy Exploit Distributes Infostealer through Docker, Initiates Worm and Kubernetes Wiper

Recent cybersecurity investigations have identified malicious artifacts that infiltrated Docker Hub, stemming from the Trivy supply chain attack. This incident illustrates the expanding impact such breaches can have on developer environments, raising significant concerns for businesses leveraging open-source tools. The last known untainted version of Trivy, a widely used open-source…

Read MoreTrivy Exploit Distributes Infostealer through Docker, Initiates Worm and Kubernetes Wiper