The Breach News

Panchan: A Golang-based Peer-to-Peer Botnet Aiming at Linux Servers

Recently, cybersecurity researchers have identified a new Golang-based peer-to-peer (P2P) botnet, named Panchan, that has been actively targeting Linux servers within the education sector since its debut in March 2022. This malware exploits built-in concurrency features to enhance its propagation and deploy malicious modules, specifically by harvesting SSH keys to…

Read MorePanchan: A Golang-based Peer-to-Peer Botnet Aiming at Linux Servers

Mitigating AI Risks in CIAM: Safeguarding Compliance, Security, and Trust

Exploring AI Risks in CIAM: Navigating Compliance, Security, and Trust Challenges In the rapidly evolving landscape of cybersecurity, the integration of artificial intelligence (AI) within Customer Identity and Access Management (CIAM) systems poses significant risks that demand the attention of business owners. As organizations increasingly adopt AI to streamline identity…

Read MoreMitigating AI Risks in CIAM: Safeguarding Compliance, Security, and Trust

NodeStealer Malware Compromises Facebook Ad Accounts to Exfiltrate Credit Card Information

Cybersecurity experts have raised alarms regarding a revamped version of the Python-based malware known as NodeStealer, which now has enhanced capabilities to extract sensitive information from victims’ Facebook Ads Manager accounts, including stored credit card data from web browsers. According to Netskope Threat Labs researcher Jan Michael Alcantara, the attacker’s…

Read MoreNodeStealer Malware Compromises Facebook Ad Accounts to Exfiltrate Credit Card Information

Grateful for My VPN: The Recent Data Leaks from Balenciaga, Gucci, and Alexander McQueen

A significant cybersecurity incident affecting renowned fashion brands, including Balenciaga, Gucci, and Alexander McQueen, has come to light. The breach, attributed to a cybercriminal group known as ‘Shiny Hunters’, reportedly involved the exposure of approximately 7.4 million unique email addresses following an April attack. This incident underscores the importance of…

Read MoreGrateful for My VPN: The Recent Data Leaks from Balenciaga, Gucci, and Alexander McQueen

Cloud Security for Lending Platforms: Misconfigurations Exposing PII

Surge in Cloud Adoption Alongside Data Exposure Concerns Recent developments indicate a significant uptick in both cloud adoption and the associated risk of data exposures. A comprehensive report on cloud security reveals that a staggering 95% of organizations have encountered cloud-related security breaches within an 18-month span. Alarmingly, 92% of…

Read MoreCloud Security for Lending Platforms: Misconfigurations Exposing PII

Ivanti Addresses Critical Vulnerabilities in Connect Secure and Policy Secure – Urgent Update Recommended

Ivanti Issues Urgent Security Updates Amid Exploitation Risks Ivanti has recently announced critical security updates aimed at addressing multiple vulnerabilities identified in its products—specifically Connect Secure (ICS), Policy Secure (IPS), and Cloud Services Application (CSA). These flaws pose significant risks, potentially enabling attackers to execute arbitrary code on affected systems.…

Read MoreIvanti Addresses Critical Vulnerabilities in Connect Secure and Policy Secure – Urgent Update Recommended

Chinese Hackers Target South Asian Entity by Exploiting Zero-Day Flaw in Sophos Firewall

A sophisticated advanced persistent threat (APT) from China has leveraged a critical vulnerability in Sophos’ firewall software to execute a targeted attack against an undisclosed organization in South Asia. This incident highlights the ongoing risk posed by APT actors who are adept at exploiting weaknesses within cybersecurity defenses. According to…

Read MoreChinese Hackers Target South Asian Entity by Exploiting Zero-Day Flaw in Sophos Firewall