The Breach News

French Electricity Provider Penalized for Storing User Passwords Using Vulnerable MD5 Algorithm

In a recent regulatory action, the French data protection authority, Commission nationale de l’informatique et des libertés (CNIL), has imposed a €600,000 fine on Électricité de France (EDF) for non-compliance with the European Union’s General Data Protection Regulation (GDPR). This penalty highlights ongoing challenges companies face in protecting sensitive consumer…

Read MoreFrench Electricity Provider Penalized for Storing User Passwords Using Vulnerable MD5 Algorithm

Everest Exposes AT&T Data Breach, Seeks $1M for Dublin Airport Passenger Information

The Everest ransomware group, notorious for its cybercriminal activities, has reportedly leaked a database purportedly belonging to AT&T Carrier, the official recruitment platform for the telecommunications giant. This platform is primarily used by applicants and employees for job applications, resume submissions, and managing career information. In a further unsettling development,…

Read MoreEverest Exposes AT&T Data Breach, Seeks $1M for Dublin Airport Passenger Information

California’s New Laws: A Snapshot of Pay Ranges, Layoffs, and Data Breaches – The Business Journal

California Implements New Laws Addressing Pay Transparency, Layoffs, and Data Security In a significant legislative move, California has enacted new laws aimed at enhancing workplace protections and transparency regarding pay, layoffs, and data security breaches. This legislative package comes at a time when data vulnerabilities and employee rights are in…

Read MoreCalifornia’s New Laws: A Snapshot of Pay Ranges, Layoffs, and Data Breaches – The Business Journal

CISA Warns of Ongoing Exploitation of Serious Vulnerability in Palo Alto Networks

On Thursday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog with a recently patched critical vulnerability affecting Palo Alto Networks’ Expedition tool. CISA’s action follows evidence suggesting that the flaw is actively being exploited, posing significant risks to organizations relying on this software.…

Read MoreCISA Warns of Ongoing Exploitation of Serious Vulnerability in Palo Alto Networks

New Tomiris Backdoor Discovered Tied to Hackers Involved in SolarWinds Cyberattack

New Malware Uncovered Linked to Nobelium’s Supply Chain Attacks On Wednesday, cybersecurity researchers unveiled a previously unreported backdoor likely developed by Nobelium, the advanced persistent threat group responsible for last year’s SolarWinds supply chain attack. This latest malware, codenamed “Tomiris” by Kaspersky, further expands an arsenal of hacking tools employed…

Read MoreNew Tomiris Backdoor Discovered Tied to Hackers Involved in SolarWinds Cyberattack

CBP Conducts Unprecedented Number of Phone Searches at US Border in the Past Year

The surge in electronic device searches at U.S. borders has continued to rise sharply, predominantly fueled by a significant increase in activity over the past six months. According to new statistics from the Customs and Border Protection (CBP), there were 16,173 searches conducted between July and September, following a record-setting…

Read MoreCBP Conducts Unprecedented Number of Phone Searches at US Border in the Past Year

LastPass Faces New Security Breach, Compromising Customer Information

LastPass Investigates Security Incident Impacting Customer Data LastPass, a widely utilized password management service, has disclosed an ongoing investigation into a security breach that has revealed unauthorized access to certain customer information. This incident follows a previous compromise in August 2022, raising new concerns regarding the security measures in place.…

Read MoreLastPass Faces New Security Breach, Compromising Customer Information

Palo Alto Integrates Agentic AI to Enhance Security Automation

Security Operations CEO Nikesh Arora: Next-Generation Security Play Integrates Automation and Identity in Cloud Environments Michael Novinson (MichaelNovinson) • October 28, 2025 Nikesh Arora, Chairman and CEO, Palo Alto Networks (Image: Palo Alto Networks) Palo Alto Networks is set to integrate intelligent agents throughout its security platform to enhance the…

Read MorePalo Alto Integrates Agentic AI to Enhance Security Automation

183 Million Credentials Leaked in Malware Breach, Featuring Gmail Accounts

Recent developments in the cybersecurity landscape have raised alarms as a massive dataset, comprising credentials from 183 million accounts, has surfaced online. Notably, a substantial portion of this data is associated with Gmail users. This exposure arises from logs generated by infostealer malware accumulated over several years, rather than a…

Read More183 Million Credentials Leaked in Malware Breach, Featuring Gmail Accounts