The Breach News

Malware Infection on CircleCI Engineer’s Laptop Triggers Recent Security Breach

On December 16, 2022, the DevOps platform CircleCI fell victim to a sophisticated cyberattack that compromised an employee’s laptop. Unidentified threat actors utilized malware to gain access to the employee’s two-factor authentication credentials and subsequently infiltrated CircleCI’s systems. The malware was notably able to bypass the company’s antivirus defenses, underscoring…

Read MoreMalware Infection on CircleCI Engineer’s Laptop Triggers Recent Security Breach

An Essential Tool for CISOs That Can’t Be Overlooked

Agentic AI AI-Powered Threats Require AI-Driven Defense Sarah Banks • October 17, 2025    Artificial Intelligence has emerged as a significant force in the cybersecurity arena, enhancing the capabilities of defenders while simultaneously equipping attackers with unprecedented tools. Malicious actors are increasingly utilizing agentic AI to execute sophisticated, autonomous attacks…

Read MoreAn Essential Tool for CISOs That Can’t Be Overlooked

Surge in Cyber Attacks in the Philippines Driven by Deepfakes and Data Leaks — Viettel Cyber Security – The Manila Times

Surge in Cyberattacks in the Philippines Driven by Deepfakes and Data Leaks Recent reports indicate a significant rise in cyberattacks within the Philippines, primarily fueled by advanced tactics such as deepfakes and extensive data leaks. This alarming trend has raised substantial concern among business owners and cybersecurity professionals, who must…

Read MoreSurge in Cyber Attacks in the Philippines Driven by Deepfakes and Data Leaks — Viettel Cyber Security – The Manila Times

OvrC Platform Weaknesses Leave IoT Devices Vulnerable to Remote Attacks and Code Execution

Recent security audits of the OvrC cloud platform have revealed a series of vulnerabilities—specifically ten—that could enable attackers to execute code remotely on devices linked to this network. These vulnerabilities, if exploited, could allow unauthorized individuals to commandeer devices including smart power supplies, surveillance cameras, routers, and home automation systems.…

Read MoreOvrC Platform Weaknesses Leave IoT Devices Vulnerable to Remote Attacks and Code Execution

Ransomware Group FIN12 Intensifies Attacks on Healthcare Sector

A financially motivated threat group, identified as FIN12, has been linked to a series of RYUK ransomware incidents since October 2018. This organization demonstrates significant collaboration with TrickBot-affiliated actors while utilizing publicly accessible tools like Cobalt Strike Beacon payloads to penetrate victim networks. Cybersecurity firm Mandiant has attributed these security…

Read MoreRansomware Group FIN12 Intensifies Attacks on Healthcare Sector

Mailchimp Experiences Another Security Breach, Exposing Certain Customer Data

Mailchimp, a prominent email marketing and newsletter service provider based in the U.S., has announced a significant security breach resulting from a sophisticated social engineering attack. This incident has compromised the accounts of 133 customers, raising concerns about the vulnerabilities faced by organizations in the digital landscape. According to Mailchimp,…

Read MoreMailchimp Experiences Another Security Breach, Exposing Certain Customer Data

Transforming Experience into Influence: Careers in Cyber Education

Security Awareness Programs & Computer-Based Training, Training & Security Leadership Cyber Professionals Can Follow Two Distinct Career Paths in Training and Education Brandy Harris • October 22, 2025 Image: Shutterstock Upon entering the field of cybersecurity education, I found my background rooted in teaching rather than security operations. This evolving…

Read MoreTransforming Experience into Influence: Careers in Cyber Education

Landmark Data Breach Fine Serves as a Warning to Australian Businesses, More Penalties Ahead

Major Cybersecurity Breach Leads to Substantial Penalty for Australian Clinical Labs Australian Clinical Labs Limited (ACL), a prominent private pathology service provider in Australia, has been ordered to pay a total of A$5.8 million (approximately US$3.8 million) in penalties, alongside A$400,000 for legal costs, following court approval of a settlement…

Read MoreLandmark Data Breach Fine Serves as a Warning to Australian Businesses, More Penalties Ahead

Russian Hackers Leverage New NTLM Vulnerability to Distribute RAT Malware through Phishing Campaigns

A newly discovered security vulnerability in Windows NT LAN Manager (NTLM) has been exploited in a zero-day attack, with suspected ties to Russian threat actors targeting Ukraine. This vulnerability, designated as CVE-2024-43451 and rated with a CVSS score of 6.5, allows attackers to possibly expose a user’s NTLMv2 hash. Microsoft…

Read MoreRussian Hackers Leverage New NTLM Vulnerability to Distribute RAT Malware through Phishing Campaigns