The Breach News

Critical cPanel Vulnerability Exploited to Target Government and MSP Networks

A new threat actor has emerged, actively compromising government and military organizations in Southeast Asia, with additional focus on a select group of managed service providers (MSPs) and hosting services located in the Philippines, Laos, Canada, South Africa, and the United States. The attackers are exploiting a recently identified vulnerability…

Read MoreCritical cPanel Vulnerability Exploited to Target Government and MSP Networks

Silver Fox Launches ABCDoor Malware Through Tax-Themed Phishing Campaigns in India and Russia

A recently uncovered campaign attributed to the China-based cybercrime group known as Silver Fox—also referred to as Monarch, SwimSnake, The Great Thief of Valley, UTG-Q-1000, and Void Arachne—has targeted organizations in Russia and India with new malware identified as ABCDoor. The operation has prominently involved the use of phishing emails…

Read MoreSilver Fox Launches ABCDoor Malware Through Tax-Themed Phishing Campaigns in India and Russia

Critical New Exim Vulnerability Exposes Email Servers to Remote Attacks — Patch Available

Urgent Security Update Released for Exim Email Server Due to Critical Vulnerability A significant security flaw has been identified and swiftly addressed in the widely utilized open-source Exim email server software, which could enable remote attackers to disrupt services or execute harmful code on targeted servers. This vulnerability, classified as…

Read MoreCritical New Exim Vulnerability Exposes Email Servers to Remote Attacks — Patch Available

Government-Backed Hackers Exploit Cloudflare in Malaysian Espionage Operation

New research from Oasis Security has uncovered a campaign reportedly tied to a suspected Malaysian government operation utilizing concealed command and control infrastructure for several years. This activity indicates an enduring espionage effort characterized by sophisticated methods to disguise backend systems, thereby minimizing exposure to automated scanning tools. The operation…

Read MoreGovernment-Backed Hackers Exploit Cloudflare in Malaysian Espionage Operation

2026: The Era of AI-Powered Cyber Attacks

AI-Enhanced Cyber Attack Landscape: Insights from Recent Incidents On December 4, 2025, authorities in Osaka arrested a 17-year-old for executing a cyberattack that extracted personal information from over 7 million users of Kaikatsu Club, Japan’s largest internet cafe chain. This incident highlights a broader trend in cybersecurity: amateur attackers leveraging…

Read More2026: The Era of AI-Powered Cyber Attacks

Just a GIF Could Have Compromised Your Android Phone via WhatsApp

Critical Vulnerability Discovered in WhatsApp: An Emerging Threat A recently patched security vulnerability within WhatsApp poses notable risks for Android users. This issue, identified as CVE-2019-11932, is a double-free memory corruption bug that exists not in WhatsApp’s code but within an open-source GIF parsing library used by the app. If…

Read MoreJust a GIF Could Have Compromised Your Android Phone via WhatsApp

Bug Bounty Firms Overwhelmed by AI Noise

Surge in AI-Generated Vulnerability Reports Causes Strain on Bug Bounty Programs In recent developments within the cybersecurity landscape, a significant uptick in low-quality vulnerability reports generated by artificial intelligence has prompted software companies to reassess their bug bounty initiatives. Notably, a cohort of seasoned AI developers has created automated systems…

Read MoreBug Bounty Firms Overwhelmed by AI Noise

Phishing Attack Targets Over 80 Organizations Utilizing SimpleHelp and ScreenConnect RMM Tools

A recent active phishing campaign, identified under the codename VENOMOUS#HELPER, has been reported to be targeting various organizations since at least April 2025. This malicious endeavor involves legitimate Remote Monitoring and Management (RMM) software to facilitate sustained remote access to compromised systems. Securonix’s analysis indicates that the campaign has affected…

Read MorePhishing Attack Targets Over 80 Organizations Utilizing SimpleHelp and ScreenConnect RMM Tools