The Breach News

Cybersecurity Updates: Data Breaches, Vulnerabilities, and Threats

This week’s Cybersecurity Newsletter provides crucial updates and insights into the ever-changing landscape of cybersecurity threats. Business owners and professionals are encouraged to stay informed about the latest developments that could impact their organizations’ security posture. The digital world continues to evolve, introducing new threats and innovative strategies from adversaries.…

Read MoreCybersecurity Updates: Data Breaches, Vulnerabilities, and Threats

ASUS Addresses Serious Authentication Bypass Vulnerability in Various Router Models

ASUS has recently deployed critical software updates aimed at rectifying a significant security vulnerability that affects its routers. This flaw poses a serious risk as it could potentially allow malicious actors to bypass authentication protocols, thereby gaining unauthorized access to devices. The vulnerability, identified as CVE-2024-3080, has been assigned a…

Read MoreASUS Addresses Serious Authentication Bypass Vulnerability in Various Router Models

New ‘HrServ.dll’ Web Shell Identified in APT Attack on Afghan Government

In a significant cybersecurity incident, an unidentified government entity in Afghanistan has fallen victim to a previously unreported web shell identified as HrServ, suggesting links to an advanced persistent threat (APT) attack. The exploit involves a dynamic-link library (DLL) file named "hrserv.dll," which boasts advanced functionalities, including custom encoding for…

Read MoreNew ‘HrServ.dll’ Web Shell Identified in APT Attack on Afghan Government

AT&T Confirms Data Breach Impacting Almost All Wireless Customers

AT&T Data Breach Exposes Wireless Customer Information Recent reports indicate that American telecom giant AT&T has suffered a significant data breach, leading to the unauthorized access of sensitive information pertaining to "nearly all" of its wireless customers. This security incident also affects customers of mobile virtual network operators (MVNOs) that…

Read MoreAT&T Confirms Data Breach Impacting Almost All Wireless Customers

Dental Patients Eligible for One-Time Payments of Up to $6,000 in Data Breach Settlement

In a significant cybersecurity incident, dental patients across the United States may be entitled to substantial compensation, with one-time payments potentially reaching up to $6,000 due to a multi-million dollar settlement resulting from a data breach involving Great Expressions. This prominent dental care network, which operates 246 centers nationwide, faced…

Read MoreDental Patients Eligible for One-Time Payments of Up to $6,000 in Data Breach Settlement

VMware Releases Patches for Cloud Foundation, vCenter Server, and vSphere ESXi

VMware has recently issued critical updates to address significant vulnerabilities affecting its Cloud Foundation, vCenter Server, and vSphere ESXi platforms. These flaws are particularly concerning as they could potentially allow attackers to escalate privileges or execute remote code. The vulnerabilities have been assigned high CVSS scores, underscoring their severity. Among…

Read MoreVMware Releases Patches for Cloud Foundation, vCenter Server, and vSphere ESXi

Are You Really Secure? Nearly 49% of Enterprises Overlook SaaS Risks

SaaS Security: Revealing the Gaps in Protection and Responsibility A startling 34% of security professionals lack knowledge regarding the number of Software as a Service (SaaS) applications deployed within their organizations, a fact brought to light in the recent AppOmni 2024 State of SaaS Security Report. The report further illustrates…

Read MoreAre You Really Secure? Nearly 49% of Enterprises Overlook SaaS Risks

Singapore Banks to Eliminate OTPs for Online Logins in the Next 3 Months

Singapore’s Banking Sector Moves Away from One-Time Passwords Amid Increased Phishing Risks In a significant shift aimed at enhancing cybersecurity, the Monetary Authority of Singapore (MAS) and the Association of Banks in Singapore (ABS) announced that retail banks will discontinue the use of one-time passwords (OTPs) for online account authentication…

Read MoreSingapore Banks to Eliminate OTPs for Online Logins in the Next 3 Months

IRDAI Enforces Stringent Regulations to Tackle Insurance Fraud Following Data Breaches

In response to a series of alarming data breaches and incidents of online fraud, notably with companies like Star Health Insurance, the Insurance Regulatory and Development Authority of India (IRDAI) is advocating for rigorous measures aimed at mitigating fraudulent activities within the insurance sector. The proposal outlines a framework designed…

Read MoreIRDAI Enforces Stringent Regulations to Tackle Insurance Fraud Following Data Breaches