The Breach News

Experts Connect Sidewalk Malware Attacks to Grayfly, a Chinese Hacker Group

A previously undocumented backdoor, identified as SideWalk, has recently been discovered targeting an unnamed computer retail company in the United States, linked to a persistent Chinese espionage campaign known as Grayfly. This finding raises significant concerns in the cybersecurity community regarding the growing sophistication of foreign threats. In late August,…

Read MoreExperts Connect Sidewalk Malware Attacks to Grayfly, a Chinese Hacker Group

NPM Overrun by Malicious Packages Downloaded Over 86,000 Times

Exploiting Vulnerabilities in NPM: A Surge in Credential-Theft Packages Cybercriminals have recently exploited a significant vulnerability in the NPM code repository, gaining access through more than 100 malicious packages designed to steal credentials since August. Notably, these attacks largely went unnoticed until now. Security firm Koi revealed these alarming findings…

Read MoreNPM Overrun by Malicious Packages Downloaded Over 86,000 Times

Medibank Declines Ransom Payment Following Ransomware Attack Exposing 9.7 Million Customers

In a significant breach of cybersecurity, Australian health insurer Medibank has announced that the personal data of approximately 9.7 million current and former customers has been compromised due to a ransomware attack. The incident, detected on October 12, raised alarms within the company when signs consistent with a ransomware event…

Read MoreMedibank Declines Ransom Payment Following Ransomware Attack Exposing 9.7 Million Customers

Marina Bay Sands Penalized US$243,400 for Data Breach Affecting Over 665,000 Rewards Members – iGamingToday.com

Marina Bay Sands Penalized $243,400 Following Data Breach Affecting Over 665,000 Reward Members Marina Bay Sands, the iconic integrated resort situated in Singapore, has recently faced significant financial repercussions due to a data breach compromising the personal information of over 665,000 members of its rewards program. The breach, which has…

Read MoreMarina Bay Sands Penalized US$243,400 for Data Breach Affecting Over 665,000 Rewards Members – iGamingToday.com

Vulnerabilities in the Ollama AI Framework May Lead to DoS Attacks, Model Theft, and Poisoning Risks

Security Flaws Discovered in Ollama AI Framework Recent disclosures by cybersecurity researchers have revealed six vulnerabilities within the Ollama artificial intelligence (AI) framework, a tool enabling users to deploy large language models (LLMs) locally on multiple operating systems, including Windows, Linux, and macOS. These vulnerabilities present significant risks, allowing potential…

Read MoreVulnerabilities in the Ollama AI Framework May Lead to DoS Attacks, Model Theft, and Poisoning Risks

Linux Deployment of Cobalt Strike Beacon for Global Organizational Targeting

On Monday, cybersecurity researchers unveiled the existence of a newly identified re-implementation of the notorious Cobalt Strike Beacon for both Linux and Windows operating systems. This variant, dubbed “Vermilion Strike,” has been actively targeting a range of sectors, including government, telecommunications, IT, and financial institutions. This advanced yet undetected penetration…

Read MoreLinux Deployment of Cobalt Strike Beacon for Global Organizational Targeting

The Microsoft Azure Outage Highlights the Stark Truth About Cloud Failures

Microsoft Azure Suffers Major Outage Amid Configuration Issues Microsoft’s Azure cloud platform, along with its widely utilized 365 services and gaming platforms such as Xbox and Minecraft, experienced significant outages around noon Eastern time on Wednesday. The company attributed these disruptions to “an inadvertent configuration change.” This incident represents the…

Read MoreThe Microsoft Azure Outage Highlights the Stark Truth About Cloud Failures

Indian Government Releases Draft of Digital Personal Data Protection Bill 2022

The Indian government has unveiled a draft of the much-anticipated Digital Personal Data Protection Bill, marking the fourth attempt to establish comprehensive data protection legislation since its initial proposal in July 2018. This draft aims to enhance personal data security while emphasizing user consent through clear and straightforward language regarding…

Read MoreIndian Government Releases Draft of Digital Personal Data Protection Bill 2022