The Breach News

New Zero-Day Vulnerability in Google Chrome Discovered and Actively Exploited

A critical security vulnerability has been identified in Google Chrome that poses a significant risk to users. Discovered by Clement Lecigne, a security researcher from Google’s Threat Analysis Group, this flaw could enable remote attackers to execute arbitrary code, potentially giving them complete control over affected systems. Designated as CVE-2019-5786,…

Read MoreNew Zero-Day Vulnerability in Google Chrome Discovered and Actively Exploited

Microsoft Issues Patches for 64 Vulnerabilities, Including Two Currently Under Attack

Microsoft has rolled out a series of crucial updates as part of its monthly “Patch Tuesday” initiative, aiming to address a total of 64 CVE-listed vulnerabilities in its Windows operating systems and various applications. Among these vulnerabilities, 17 have been classified as critical, 45 as important, while one is considered…

Read MoreMicrosoft Issues Patches for 64 Vulnerabilities, Including Two Currently Under Attack

Patched WinRAR Vulnerability Remains Under Active Exploitation Due to Lack of Auto-Updates

Critical Vulnerability in WinRAR Exploited by Cybercriminals Recent reports have highlighted that cybercriminal groups and independent hackers are actively taking advantage of a critical code execution vulnerability in WinRAR, a widely-used file compression tool with a user base of over 500 million. The vulnerability, designated CVE-2018-20250, was patched in the…

Read MorePatched WinRAR Vulnerability Remains Under Active Exploitation Due to Lack of Auto-Updates

Libssh Releases Update to Address Nine Security Vulnerabilities

Libssh2 Addresses Critical Security Vulnerabilities in Latest Update Libssh2, an open-source C library widely utilized for SSHv2 communication, has released a critical update aimed at addressing nine security vulnerabilities. This release underscores the persistent security risks inherent in widely used libraries and highlights the necessity for developers and organizations to…

Read MoreLibssh Releases Update to Address Nine Security Vulnerabilities

Dashlane Reveals How Attackers Successfully Downloaded Encrypted Password Vaults

In a recent cybersecurity incident involving Dashlane, attackers gained access to encrypted user vaults, raising concerns about the robustness of the platform’s security measures. While the strength of users’ master passwords plays a critical role in preventing unauthorized access, it is essential to note that not all users adhere to…

Read MoreDashlane Reveals How Attackers Successfully Downloaded Encrypted Password Vaults

PuTTY Issues Critical Software Update to Address 8 High-Severity Vulnerabilities

The developers behind the widely utilized SSH client program PuTTY have announced the release of an important software update, version 0.71, which addresses eight high-severity security vulnerabilities. This latest version comes nearly 20 months after the last release, underscoring the urgency of updating to the latest iteration to safeguard against…

Read MorePuTTY Issues Critical Software Update to Address 8 High-Severity Vulnerabilities

Meta Quietly Integrated Face Recognition Code for Its Smart Glasses into Millions of Phones

Meta’s Face Recognition Technology Embedded in Popular App Raises Privacy Concerns Meta has stealthily integrated face-recognition capabilities into an application that has been installed on millions of smartphones. Analysis by WIRED reveals that this feature, codenamed “NameTag,” is designed to identify individuals through the camera of its smart glasses. When…

Read MoreMeta Quietly Integrated Face Recognition Code for Its Smart Glasses into Millions of Phones

Medtronic’s Implantable Defibrillators at Risk of Serious Cyber Attacks

On Thursday, the U.S. Department of Homeland Security issued a critical advisory regarding significant vulnerabilities found in a range of heart defibrillators produced by Medtronic, one of the world’s leading medical device manufacturers. The advisory highlighted that these vulnerabilities could potentially enable unauthorized individuals to remotely commandeer the devices, thereby…

Read MoreMedtronic’s Implantable Defibrillators at Risk of Serious Cyber Attacks

Lazarus Group Launches npm Brandjacking Campaign to Target Developers

A recent npm campaign, attributed to North Korea’s Lazarus Group, has highlighted a new strategy in which attackers employ deceptive package names to infiltrate developers’ systems and software build environments. This tactic poses significant risks for organizations reliant on JavaScript tools, as many developers may unwittingly install these malicious packages.…

Read MoreLazarus Group Launches npm Brandjacking Campaign to Target Developers