The Breach News

‘CyberGuy’: The Most Shocking Data Breaches of the Year – Fox News

Title: Analysis of This Year’s Most Significant Data Breaches In a year marked by significant cybersecurity incidents, a recent article by ‘CyberGuy’ outlines the most devastating data breaches that have occurred. Organizations across various sectors have faced compromised data and security lapses, raising alarms about the ongoing threat landscape. The…

Read More‘CyberGuy’: The Most Shocking Data Breaches of the Year – Fox News

Hackers Leverage PHP Flaw to Implement Stealthy Msupedge Backdoor

A previously unknown backdoor known as Msupedge has recently been deployed in cyber attacks against an unnamed university in Taiwan. This alarming development has raised concerns in the cybersecurity community, particularly given the backdoor’s unique operational characteristics. According to a report from Symantec’s Threat Hunter Team, part of Broadcom, one…

Read MoreHackers Leverage PHP Flaw to Implement Stealthy Msupedge Backdoor

Israeli Organizations Under Cyberattack Utilizing Donut and Sliver Frameworks

Cyberattack Campaign Targets Israeli Entities Using Open-Source Tools Cybersecurity analysts have unearthed a sophisticated attack campaign directed at various entities within Israel, utilizing publicly available frameworks such as Donut and Sliver. HarfangLab, a cybersecurity research firm, detailed the operation in a report last week, describing it as highly targeted and…

Read MoreIsraeli Organizations Under Cyberattack Utilizing Donut and Sliver Frameworks

MoneyGram: No Indications of Ransomware Linked to Recent Cyberattack – DataBreaches.net

In a recent statement regarding a cybersecurity incident, MoneyGram International has clarified that there is no indication linking the attack to ransomware activity. This update comes in the wake of heightened scrutiny following reports of unauthorized access to systems and potential data compromises. The target of this breach appears to…

Read MoreMoneyGram: No Indications of Ransomware Linked to Recent Cyberattack – DataBreaches.net

Exploitation of Microsoft MSHTML Vulnerability to Distribute MerkSpy Spyware

Cybersecurity Threat: Surveillance Tool MerkSpy Exploits Microsoft MSHTML Vulnerability Recent reports from Fortinet’s FortiGuard Labs indicate the emergence of a sophisticated surveillance tool known as MerkSpy, which is being used by unidentified threat actors to compromise systems through a now-patched vulnerability in Microsoft’s MSHTML. This malicious campaign is primarily targeting…

Read MoreExploitation of Microsoft MSHTML Vulnerability to Distribute MerkSpy Spyware

Steps to Take Following a Data Breach

This week, a reader expressed concern over receiving multiple notifications regarding data breaches that may impact their accounts. Over the past few months, they have reported receiving six written notices from various companies, all of which are offering complimentary identity monitoring services through different providers. The reader seeks clarity on…

Read MoreSteps to Take Following a Data Breach

GitHub Addresses Critical Security Vulnerability in Enterprise Server That Grants Admin Privileges

GitHub has announced a series of critical security updates addressing three vulnerabilities impacting its Enterprise Server (GHES) product. Among these, one flaw is particularly severe and could potentially allow unauthorized users to obtain site administrator privileges. The vulnerability, designated as CVE-2024-6800, has been rated with a CVSS score of 9.5,…

Read MoreGitHub Addresses Critical Security Vulnerability in Enterprise Server That Grants Admin Privileges

Worldwide Police Operation Takes Down 600 Cybercrime Servers Associated with Cobalt Strike

In a significant law enforcement initiative dubbed Operation MORPHEUS, approximately 600 servers utilized by cybercriminal syndicates were dismantled, disrupting a critical component of the infrastructure linked to the Cobalt Strike tool. This crackdown, coordinated by Europol, particularly targeted unlicensed and outdated versions of the Cobalt Strike framework between June 24…

Read MoreWorldwide Police Operation Takes Down 600 Cybercrime Servers Associated with Cobalt Strike