The Breach News

Data Breach Exposes Students from Iran’s MOIS Training Academy – Dark Reading | Security

Data Breach Exposes Students of Iran’s MOIS Training Academy A significant data leak has recently surfaced, revealing sensitive information belonging to students enrolled in Iran’s Ministry of Intelligence and Security (MOIS) Training Academy. This incident highlights ongoing vulnerabilities in cybersecurity practices within state institutions and raises questions about the security…

Read MoreData Breach Exposes Students from Iran’s MOIS Training Academy – Dark Reading | Security

Google’s AI Tool Big Sleep Discovers Zero-Day Vulnerability in SQLite Database Engine

Google has reported the identification of a zero-day vulnerability within the SQLite open-source database engine, utilizing its large language model (LLM)-assisted framework known as Big Sleep (formerly Project Naptime). This discovery marks a significant milestone as the first real-world vulnerability unveiled through the application of an artificial intelligence (AI) agent.…

Read MoreGoogle’s AI Tool Big Sleep Discovers Zero-Day Vulnerability in SQLite Database Engine

Experts Connect Sidewalk Malware Attacks to Grayfly, a Chinese Hacker Group

A previously undocumented backdoor, identified as SideWalk, has recently been discovered targeting an unnamed computer retail company in the United States, linked to a persistent Chinese espionage campaign known as Grayfly. This finding raises significant concerns in the cybersecurity community regarding the growing sophistication of foreign threats. In late August,…

Read MoreExperts Connect Sidewalk Malware Attacks to Grayfly, a Chinese Hacker Group

NPM Overrun by Malicious Packages Downloaded Over 86,000 Times

Exploiting Vulnerabilities in NPM: A Surge in Credential-Theft Packages Cybercriminals have recently exploited a significant vulnerability in the NPM code repository, gaining access through more than 100 malicious packages designed to steal credentials since August. Notably, these attacks largely went unnoticed until now. Security firm Koi revealed these alarming findings…

Read MoreNPM Overrun by Malicious Packages Downloaded Over 86,000 Times

Medibank Declines Ransom Payment Following Ransomware Attack Exposing 9.7 Million Customers

In a significant breach of cybersecurity, Australian health insurer Medibank has announced that the personal data of approximately 9.7 million current and former customers has been compromised due to a ransomware attack. The incident, detected on October 12, raised alarms within the company when signs consistent with a ransomware event…

Read MoreMedibank Declines Ransom Payment Following Ransomware Attack Exposing 9.7 Million Customers

Marina Bay Sands Penalized US$243,400 for Data Breach Affecting Over 665,000 Rewards Members – iGamingToday.com

Marina Bay Sands Penalized $243,400 Following Data Breach Affecting Over 665,000 Reward Members Marina Bay Sands, the iconic integrated resort situated in Singapore, has recently faced significant financial repercussions due to a data breach compromising the personal information of over 665,000 members of its rewards program. The breach, which has…

Read MoreMarina Bay Sands Penalized US$243,400 for Data Breach Affecting Over 665,000 Rewards Members – iGamingToday.com

Vulnerabilities in the Ollama AI Framework May Lead to DoS Attacks, Model Theft, and Poisoning Risks

Security Flaws Discovered in Ollama AI Framework Recent disclosures by cybersecurity researchers have revealed six vulnerabilities within the Ollama artificial intelligence (AI) framework, a tool enabling users to deploy large language models (LLMs) locally on multiple operating systems, including Windows, Linux, and macOS. These vulnerabilities present significant risks, allowing potential…

Read MoreVulnerabilities in the Ollama AI Framework May Lead to DoS Attacks, Model Theft, and Poisoning Risks

Linux Deployment of Cobalt Strike Beacon for Global Organizational Targeting

On Monday, cybersecurity researchers unveiled the existence of a newly identified re-implementation of the notorious Cobalt Strike Beacon for both Linux and Windows operating systems. This variant, dubbed “Vermilion Strike,” has been actively targeting a range of sectors, including government, telecommunications, IT, and financial institutions. This advanced yet undetected penetration…

Read MoreLinux Deployment of Cobalt Strike Beacon for Global Organizational Targeting