The Breach News

Firefox Zero-Day Exploited: Update Your Browser Right Away!

Critical Vulnerability Discovered in Firefox Exposed to Exploitation Mozilla has announced the discovery of a significant security vulnerability affecting both Firefox and the Firefox Extended Support Release (ESR). This flaw, tracked as CVE-2024-9680, has been identified as a use-after-free bug within the Animation timeline component and carries a CVSS score…

Read MoreFirefox Zero-Day Exploited: Update Your Browser Right Away!

Rise in Cyber Espionage by Chinese Hackers Targeting Neighboring Nations

A series of cyber espionage operations, tracing back to 2014 and primarily aimed at acquiring sensitive defense information from neighboring nations, have been attributed to a Chinese military intelligence unit. A comprehensive report released this week by Massachusetts-based Recorded Future reveals connections between a group known as RedFoxtrot and the…

Read MoreRise in Cyber Espionage by Chinese Hackers Targeting Neighboring Nations

France Declares Google Analytics Noncompliant with GDPR Data Protection Law

French data protection authority, CNIL, has determined that Google Analytics breaches the European Union’s General Data Protection Regulation (GDPR). This ruling follows a similar finding in Austria just weeks prior. The CNIL’s investigation into the transatlantic transfer of Google Analytics data revealed that this practice lacks appropriate regulatory oversight, particularly…

Read MoreFrance Declares Google Analytics Noncompliant with GDPR Data Protection Law

Seven Tactics Hackers Use to Manipulate ChatGPT’s Responses

Cybersecurity firm Tenable has unveiled significant vulnerabilities in OpenAI’s ChatGPT, uncovering seven distinct risks that could allow malicious actors to compromise user data, circumvent security measures, and embed persistent threats within the model’s architecture. The analysis, referred to as HackedGPT, highlighted that several of the vulnerabilities identified in ChatGPT-4 have…

Read MoreSeven Tactics Hackers Use to Manipulate ChatGPT’s Responses

CISA Alerts About Major Fortinet Vulnerability as Palo Alto and Cisco Release Emergency Security Updates

On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced the addition of a critical security vulnerability affecting Fortinet products to its Known Exploited Vulnerabilities (KEV) catalog. This action was taken in light of evidence indicating ongoing exploitation of this flaw. Identified as CVE-2024-23113, this vulnerability has a CVSS…

Read MoreCISA Alerts About Major Fortinet Vulnerability as Palo Alto and Cisco Release Emergency Security Updates

North Korea Leveraged VPN Vulnerability to Breach South Korea’s Nuclear Research Institute

On Friday, the Korea Atomic Energy Research Institute (KAERI), a government-funded entity based in South Korea, reported a breach of its internal network. The infiltration is believed to have been executed by a threat actor linked to North Korea, with the actual breach occurring on May 14. The attackers exploited…

Read MoreNorth Korea Leveraged VPN Vulnerability to Breach South Korea’s Nuclear Research Institute