The Breach News

Drift Suffers $285 Million Loss from Durable Nonce Social Engineering Attack Tied to DPRK

On April 1, 2026, the decentralized exchange Drift, built on the Solana blockchain, was significantly compromised, resulting in an estimated loss of $285 million. The breach was the result of a highly sophisticated attack that allowed unauthorized access to the platform’s administrative powers. According to Drift’s official commentary on the…

Read MoreDrift Suffers $285 Million Loss from Durable Nonce Social Engineering Attack Tied to DPRK

New Malware Substitutes Authentic Android Apps with Counterfeits on 25 Million Devices

Recent revelations from cybersecurity experts have cast a spotlight on an alarming malware campaign targeting Android users. The findings suggest that attackers have stealthily replaced legitimate applications with malicious counterparts on approximately 25 million devices globally. This revelation raises significant concerns about the integrity of widely used applications like WhatsApp,…

Read MoreNew Malware Substitutes Authentic Android Apps with Counterfeits on 25 Million Devices

Why Third-Party Risk Represents the Most Significant Vulnerability in Your Clients’ Security Posture

In today’s interconnected digital landscape, cybersecurity incidents are increasingly caused by third-party vendors rather than direct attacks on organizations themselves. Often, these breaches occur through reputable suppliers, Software as a Service (SaaS) applications, or subcontractors that internal IT teams may not even recognize, highlighting a significant vulnerability within enterprise security…

Read MoreWhy Third-Party Risk Represents the Most Significant Vulnerability in Your Clients’ Security Posture

Critical RCE Vulnerability Discovered in Zoom Video Conferencing for macOS

Recent revelations regarding privacy vulnerabilities in the widely-used Zoom video conferencing software have raised significant alarm across both personal and corporate sectors. The disclosed vulnerabilities have not only highlighted potential risks to user privacy but have also indicated serious threats to device security, especially for Mac users. The core issue…

Read MoreCritical RCE Vulnerability Discovered in Zoom Video Conferencing for macOS

Millions of AI Agents at Risk Due to Serious Vulnerability in Open Source Package

Critical Vulnerability Exposes Millions of AI Agents to Hackers A serious security flaw has been identified in Starlette, an open-source framework widely used by AI agents and tools globally, alerting industry experts to substantial cybersecurity risks. This vulnerability could enable malicious hackers to penetrate servers that host these tools and…

Read MoreMillions of AI Agents at Risk Due to Serious Vulnerability in Open Source Package

BKA Uncovers REvil Leaders Linked to 130 Ransomware Attacks in Germany

The German Federal Criminal Police Office, known as BKA (Bundeskriminalamt), has identified two prominent figures associated with the now-defunct REvil ransomware-as-a-service (RaaS) operation. This significant development comes amid ongoing efforts to combat ransomware threats globally, drawing attention to the individuals behind the cybercriminal enterprise. One of the individuals, identified as…

Read MoreBKA Uncovers REvil Leaders Linked to 130 Ransomware Attacks in Germany

This Vulnerability Could Have Enabled Hackers to Breach Any Instagram Account in Just 10 Minutes

Instagram Discloses Critical Vulnerability, Promptly Patched Instagram, the widely-used photo-sharing platform owned by Facebook, recently addressed a critical vulnerability that could have enabled unauthorized access to user accounts. This flaw posed a risk by allowing remote attackers to reset user passwords without requiring any action from the targeted individual. With…

Read MoreThis Vulnerability Could Have Enabled Hackers to Breach Any Instagram Account in Just 10 Minutes

iOS URL Scheme Vulnerability: Potential for App-in-the-Middle Attacks to Compromise Your Accounts

Security Researchers Uncover App-in-the-Middle Attack Vulnerability on iOS Recent findings from security researchers have revealed a serious vulnerability within Apple’s iOS that allows malicious applications to exploit the Custom URL Scheme feature, potentially compromising sensitive user information. This new app-in-the-middle attack enables hostile software on a user’s device to intercept…

Read MoreiOS URL Scheme Vulnerability: Potential for App-in-the-Middle Attacks to Compromise Your Accounts