The Breach News

AT&T to Distribute $177 Million Settlement: Find Out If You Qualify for a $7,500 Payment

AT&T Settles Class Action Lawsuits Following Major Cyber Breaches In a significant development for data security, telecommunications leader AT&T has reached settlements for two class action lawsuits triggered by dual data breaches that unfolded in 2024. These incidents were notable not only for their scale but also for the sensitive…

Read MoreAT&T to Distribute $177 Million Settlement: Find Out If You Qualify for a $7,500 Payment

Google Strengthens GenAI Security with Enhanced Multi-Layered Defenses Against Prompt Injection Threats

June 23, 2025
Artificial Intelligence / AI Security

Google has announced new safety measures aimed at fortifying its generative artificial intelligence (AI) systems against emerging threats such as indirect prompt injections. These attacks, unlike direct prompt injections that involve the submission of harmful commands, embed malicious instructions within external data sources like emails, documents, or calendar invites, potentially leading AI systems to leak sensitive information or execute harmful actions. In response, Google’s GenAI security team has developed a comprehensive “layered” defense strategy that raises the difficulty, cost, and complexity associated with executing successful attacks. This multifaceted approach includes model hardening and the introduction of specialized safeguards.

Google Enhances Security Measures to Protect GenAI from Prompt Injection Threats On June 23, 2025, Google announced strategic enhancements to the security of its generative artificial intelligence (AI) systems, aimed at countering sophisticated attack vectors such as indirect prompt injection. This development comes amid rising concerns about vulnerabilities in AI…

Read More

Google Strengthens GenAI Security with Enhanced Multi-Layered Defenses Against Prompt Injection Threats

June 23, 2025
Artificial Intelligence / AI Security

Google has announced new safety measures aimed at fortifying its generative artificial intelligence (AI) systems against emerging threats such as indirect prompt injections. These attacks, unlike direct prompt injections that involve the submission of harmful commands, embed malicious instructions within external data sources like emails, documents, or calendar invites, potentially leading AI systems to leak sensitive information or execute harmful actions. In response, Google’s GenAI security team has developed a comprehensive “layered” defense strategy that raises the difficulty, cost, and complexity associated with executing successful attacks. This multifaceted approach includes model hardening and the introduction of specialized safeguards.

Ransomware Claims Emerge Amid Ongoing Colt Outages

Fraud Management & Cybercrime, Ransomware Colt Technology Services Faces Major Disruption Following Ransomware Attack Prajeet Nair (@prajeetspeaks) • August 17, 2025 Image: aileenchik/Shutterstock Colt Technology Services, a multinational telecommunications company based in the UK, has reported widespread disruptions to its customer portal and support services, citing a “cyber incident” as…

Read MoreRansomware Claims Emerge Amid Ongoing Colt Outages

GitLab Duo Vulnerability Allowed Attackers to Manipulate AI Responses via Hidden Prompts

May 23, 2025
Artificial Intelligence / Cybersecurity Threats

Cybersecurity researchers have identified a critical indirect prompt injection vulnerability in GitLab’s AI assistant, Duo. This flaw could potentially allow malicious actors to access source code and inject untrusted HTML into the AI’s responses, redirecting users to harmful websites. GitLab Duo, an AI-driven coding assistant launched in June 2023 and built on Anthropic’s Claude models, has been shown to be vulnerable. According to findings from Legit Security, this weakness enables attackers to steal code from private projects, alter code suggestions for other users, and even exfiltrate sensitive undisclosed zero-day vulnerabilities. Prompt injection is a known class of vulnerabilities within AI systems, allowing threat actors to exploit large language models (LLMs) to manipulate user interactions.

GitLab Duo Vulnerability Exposes Users to Potential Code Hijacking and Malware Risks May 23, 2025 | Cybersecurity Insights Cybersecurity experts have recently identified a significant security vulnerability in GitLab’s AI coding assistant, Duo. This flaw involves indirect prompt injection, which could potentially enable malicious actors to access confidential source code…

Read More

GitLab Duo Vulnerability Allowed Attackers to Manipulate AI Responses via Hidden Prompts

May 23, 2025
Artificial Intelligence / Cybersecurity Threats

Cybersecurity researchers have identified a critical indirect prompt injection vulnerability in GitLab’s AI assistant, Duo. This flaw could potentially allow malicious actors to access source code and inject untrusted HTML into the AI’s responses, redirecting users to harmful websites. GitLab Duo, an AI-driven coding assistant launched in June 2023 and built on Anthropic’s Claude models, has been shown to be vulnerable. According to findings from Legit Security, this weakness enables attackers to steal code from private projects, alter code suggestions for other users, and even exfiltrate sensitive undisclosed zero-day vulnerabilities. Prompt injection is a known class of vulnerabilities within AI systems, allowing threat actors to exploit large language models (LLMs) to manipulate user interactions.

XDigo Malware Exploits Windows LNK Vulnerability in Eastern European Government Attacks

On June 23, 2025, cybersecurity researchers unveiled XDigo, a Go-based malware utilized in attacks against Eastern European government entities in March 2025. The cyber espionage campaign, known as XDSpy, has been targeting government agencies in Eastern Europe and the Balkans since 2011, with its origins traced back to early documentation by the Belarusian CERT in 2020. Recent years have seen numerous campaigns aimed at organizations in Russia and Moldova, deploying malware families such as UTask, XDDown, and DSDownloader to retrieve sensitive data from compromised systems. HarfangLab reported that the threat actor exploited a remote code execution vulnerability in Microsoft Windows, triggered by specially crafted LNK files, as part of a multi-stage attack approach.

XDigo Malware Exploits Windows LNK Vulnerability in Eastern European Government Attacks Cybersecurity analysts have identified a Go-based malware, designated XDigo, that has recently been employed in targeted cyberattacks against governmental entities in Eastern Europe. According to French cybersecurity firm HarfangLab, these attacks were particularly concentrated in March 2025 and utilized…

Read More

XDigo Malware Exploits Windows LNK Vulnerability in Eastern European Government Attacks

On June 23, 2025, cybersecurity researchers unveiled XDigo, a Go-based malware utilized in attacks against Eastern European government entities in March 2025. The cyber espionage campaign, known as XDSpy, has been targeting government agencies in Eastern Europe and the Balkans since 2011, with its origins traced back to early documentation by the Belarusian CERT in 2020. Recent years have seen numerous campaigns aimed at organizations in Russia and Moldova, deploying malware families such as UTask, XDDown, and DSDownloader to retrieve sensitive data from compromised systems. HarfangLab reported that the threat actor exploited a remote code execution vulnerability in Microsoft Windows, triggered by specially crafted LNK files, as part of a multi-stage attack approach.

From Awareness to Implementation: Cultivating Enduring Cybersecurity Practices

For insights on enhancing your organization’s cybersecurity measures, consider exploring Security Awareness Programs & Computer-Based Training and Training & Security Leadership. Authored by Brandy Harris • August 15, 2025 Every October, companies reexamine their cybersecurity protocols, reiterating that “Security is everyone’s responsibility.” Despite these efforts, the prevalence of security incidents…

Read MoreFrom Awareness to Implementation: Cultivating Enduring Cybersecurity Practices

CISA Alerts on Potential Widespread SaaS Attacks Targeting App Secrets and Cloud Misconfigurations

May 23, 2025
Cloud Security / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced that Commvault is actively monitoring cyber threats aimed at applications hosted in their Microsoft Azure environment. According to the agency, “Threat actors may have accessed client secrets for Commvault’s (Metallic) Microsoft 365 (M365) backup SaaS solution in Azure.” This breach potentially granted unauthorized access to Commvault’s customers’ M365 environments, where application secrets are stored. CISA further indicated that this activity might be part of a larger campaign targeting various SaaS providers’ cloud infrastructures that utilize default configurations and elevated permissions. This advisory follows Commvault’s recent revelation that Microsoft alerted the company in February 2025 about unauthorized activity from a nation-state threat actor within its Azure environment. The incident prompted…

CISA Issues Warning on Potential Widespread SaaS Attacks Targeting Application Secrets and Cloud Misconfigurations On May 23, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an important advisory concerning emerging cyber threats affecting applications running in cloud environments, specifically highlighting the ongoing monitoring efforts by Commvault. This alert…

Read More

CISA Alerts on Potential Widespread SaaS Attacks Targeting App Secrets and Cloud Misconfigurations

May 23, 2025
Cloud Security / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced that Commvault is actively monitoring cyber threats aimed at applications hosted in their Microsoft Azure environment. According to the agency, “Threat actors may have accessed client secrets for Commvault’s (Metallic) Microsoft 365 (M365) backup SaaS solution in Azure.” This breach potentially granted unauthorized access to Commvault’s customers’ M365 environments, where application secrets are stored. CISA further indicated that this activity might be part of a larger campaign targeting various SaaS providers’ cloud infrastructures that utilize default configurations and elevated permissions. This advisory follows Commvault’s recent revelation that Microsoft alerted the company in February 2025 about unauthorized activity from a nation-state threat actor within its Azure environment. The incident prompted…

Customers may receive up to $7,500 from AT&T data breach settlement.

AT&T customers may be entitled to financial compensation following a significant settlement of $177 million stemming from two data breaches that compromised sensitive information. These breaches occurred in March and July of the previous year, exposing critical personal data, including Social Security numbers and phone numbers, of millions of both…

Read MoreCustomers may receive up to $7,500 from AT&T data breach settlement.