The Breach News

PseudoManuscrypt Malware Spreads Like CryptBot, Targeting Korean Users

A sophisticated botnet known as PseudoManuscrypt has been actively targeting Windows systems in South Korea since May 2021, employing tactics similar to those used by the malware CryptBot. This trend has raised significant concerns within the cybersecurity community. A report from the South Korean cybersecurity firm AhnLab Security Emergency Response…

Read MorePseudoManuscrypt Malware Spreads Like CryptBot, Targeting Korean Users

Fortra Acknowledges ‘Unauthorized Access’ Incident Affecting GoAnywhere MFT

Encryption & Key Management, Fraud Management & Cybercrime, Governance & Risk Management Medusa Ransomware Group Linked to Exploitation of Recently Patched Zero-Day Vulnerability Mathew J. Schwartz (euroinfosec) • October 10, 2025 Image: Shutterstock/ISMG Recent cyberattacks have targeted Fortra’s GoAnywhere managed file transfer software, primarily affecting on-premises setups where the management…

Read MoreFortra Acknowledges ‘Unauthorized Access’ Incident Affecting GoAnywhere MFT

Apple Unveils $2 Million Bug Bounty for Critical Exploit Discoveries

Apple has significantly escalated its bug bounty program, now offering a maximum payout of $2 million for software exploits that could facilitate spyware attacks. This announcement was made by Ivan Krstić, Apple’s vice president of security engineering and architecture, during the Hexacon offensive security conference held in Paris. The new…

Read MoreApple Unveils $2 Million Bug Bounty for Critical Exploit Discoveries

Security Flaw in Rogue WordPress Plugin Puts E-Commerce Sites at Risk for Credit Card Theft

Cybersecurity researchers have uncovered a malicious WordPress plugin capable of creating unauthorized administrator accounts and injecting harmful JavaScript code designed to siphon credit card information. This activity is linked to a broader Magecart campaign specifically targeting e-commerce platforms, as reported by Sucuri. According to security analyst Ben Martin, the rogue…

Read MoreSecurity Flaw in Rogue WordPress Plugin Puts E-Commerce Sites at Risk for Credit Card Theft

59% of Organizations Experience MFT Breaches Due to Inadequate Security Measures

Key Takeaways: 59% of organizations have reported Managed File Transfer (MFT) security incidents, largely due to governance and encryption shortfalls. The GoAnywhere zero-day exploit laid bare serious vulnerabilities exploited by attackers to deploy ransomware. Implementing robust governance and integrated security measures can significantly lessen breach risks and enhance visibility. Recent…

Read More59% of Organizations Experience MFT Breaches Due to Inadequate Security Measures

Critical Security Flaws Resolved in SonicWall, Palo Alto Expedition, and Aviatrix Controllers

Palo Alto Networks Releases Critical Software Patches for Expedition Tool Palo Alto Networks has announced the rollout of crucial software patches aimed at mitigating multiple security vulnerabilities in its Expedition migration tool. Among these flaws, a significant one has been identified that permits authenticated attackers to gain access to sensitive…

Read MoreCritical Security Flaws Resolved in SonicWall, Palo Alto Expedition, and Aviatrix Controllers

Iranian State Broadcaster IRIB Targeted by Devastating Wiper Malware

Cyberattack on Iranian National Media Uncovered: Wiper Malware Deployed In late January 2022, a sophisticated cyberattack against the Islamic Republic of Iran Broadcasting (IRIB), a key player in the country’s national media landscape, was confirmed to involve the deployment of wiper malware alongside tailored malicious implants. This incident underscores the…

Read MoreIranian State Broadcaster IRIB Targeted by Devastating Wiper Malware

Australia Imposes First-Ever Fine Under Privacy Act for Laboratory Breach

Data Breach Notification, Data Privacy, Data Security Australian Clinical Labs Fined $5.8 Million for 2022 Data Theft Incident Marianne Kolbasuk McGee (HealthInfoSec) • October 9, 2025 An Australian court has mandated a $5.8 million penalty against Australian Clinical Labs for deficiencies in data management during a data theft incident in…

Read MoreAustralia Imposes First-Ever Fine Under Privacy Act for Laboratory Breach

SonicWall Reports That Hackers Accessed All Firewall Backups

In September 2025, SonicWall disclosed a data breach affecting its cloud backup service, initially indicating that fewer than 5% of its clients were impacted. However, this assessment has evolved as SonicWall, in collaboration with incident response firm Mandiant, has confirmed that attackers accessed backup configuration files for all customers utilizing…

Read MoreSonicWall Reports That Hackers Accessed All Firewall Backups