The Breach News

Malware Exploiting Google MultiLogin to Sustain Access After Password Resets

A recent security report reveals that information-stealing malware is exploiting a previously undocumented Google OAuth endpoint known as MultiLogin. This vulnerability allows cybercriminals to hijack user sessions, granting them continuous access to Google services even after victims have conducted password resets. This revelation has raised significant concerns regarding user privacy…

Read MoreMalware Exploiting Google MultiLogin to Sustain Access After Password Resets

A Google Drive Vulnerability Could Enable Attackers to Coerce You into Installing Malware

A recently uncovered vulnerability in Google Drive presents a significant risk, potentially allowing cybercriminals to distribute malware disguised as legitimate files. This largely unaddressed security oversight enables attackers to leverage Google Drive’s file version management feature, resulting in higher success rates for spear-phishing schemes. The flaw, which Google is reportedly…

Read MoreA Google Drive Vulnerability Could Enable Attackers to Coerce You into Installing Malware

14 Harmful NuGet Packages Discovered Exfiltrating Crypto Wallets and Ad Information

The rapid expansion of digital currencies has seen a corresponding rise in tactics employed by cybercriminals to siphon off assets. Recently, a significant cybersecurity threat emerged on NuGet, a widely utilized platform for software developers seeking building blocks for their applications. This threat was identified by ReversingLabs, a reputable software…

Read More14 Harmful NuGet Packages Discovered Exfiltrating Crypto Wallets and Ad Information

DomainFactory Breached—Hosting Provider Urges All Users to Update Passwords

Data Breach at DomainFactory: A Reminder of Cybersecurity Vigilance A significant data breach affecting DomainFactory, one of Germany’s leading web hosting providers and owned by GoDaddy, has recently come to light. The breach, which first occurred in January, only became public knowledge last week when an unidentified attacker disclosed details…

Read MoreDomainFactory Breached—Hosting Provider Urges All Users to Update Passwords

Chinese Hackers Compromise European Networks for Espionage Activities

Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Ink Dragon Compromises European IIS Networks to Distribute ShadowPad Malware Akshaya Asokan (asokan_akshaya) • December 17, 2025 Image: tostphoto/Shutterstock A Chinese hacking group, identified as Ink Dragon, has compromised European government networks, utilizing them as relay nodes to execute commands and facilitate…

Read MoreChinese Hackers Compromise European Networks for Espionage Activities

Urgent: Ivanti Issues Patch for Serious Vulnerability in Endpoint Manager Solution

Ivanti has disclosed critical security vulnerabilities within its Endpoint Manager (EPM) solution that pose severe risks to affected systems. This vulnerability, identified as CVE-2023-39336, has received a high-risk CVSS score of 9.6 out of 10, indicating its potential for abuse. The flaw affects both the EPM 2021 and EPM 2022…

Read MoreUrgent: Ivanti Issues Patch for Serious Vulnerability in Endpoint Manager Solution

Russian National Arrested for Allegedly Offering $1 Million to U.S. Employee to Deploy Malware

In a striking incident highlighting ongoing cybersecurity threats, the FBI has apprehended a Russian national accused of attempting to infiltrate a U.S. company’s computer network through dubious means. The individual, identified as Egor Igorevich Kriuchkov, 27, was arrested in Los Angeles after reportedly offering $1 million to an employee of…

Read MoreRussian National Arrested for Allegedly Offering $1 Million to U.S. Employee to Deploy Malware

Browser Extensions with 8 Million Users Gather In-Depth AI Conversations

A recent investigation has revealed disturbing data collection practices involving various browser extensions that compromise user privacy by harvesting conversations from popular AI platforms such as ChatGPT, Claude, and Gemini. Koi, a security firm, has published a detailed report outlining the extent of this data gathering, which includes not only…

Read MoreBrowser Extensions with 8 Million Users Gather In-Depth AI Conversations