The Breach News

North Korea is Targeting Software Developers with Malware Attacks

The Lazarus Group, an infamous hacking unit allegedly sponsored by the North Korean regime, has intensified its malware campaigns, now specifically targeting software developers and freelancers. The group employs deceptive tactics to gain access to victims’ corporate networks. For freelancers, the risk is heightened; according to reports, Lazarus hackers utilize…

Read MoreNorth Korea is Targeting Software Developers with Malware Attacks

Russia Implements Espionage Tactics Against Kazakhstan

Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime, Geo Focus: Asia Hackers Exploit Malicious Macros in Diplomatic Documents to Target Asian Nations Prajeet Nair (@prajeetspeaks) • January 15, 2025 The Nur-Sultan Astana Government Building of the Republic of Kazakhstan (Image: Shutterstock) Recent developments indicate that hackers, potentially affiliated with the…

Read MoreRussia Implements Espionage Tactics Against Kazakhstan

PowerSchool Breach Victim Reports Total Student Data Theft by Hackers

Cybersecurity Alert: Data Breach at PowerSchool Affects Students and Educators Recently, several school districts have reported a significant data breach involving PowerSchool, an educational technology provider that serves over 50 million students. In this cyberattack, hackers may potentially have gained access to the personal information of students and teachers, raising…

Read MorePowerSchool Breach Victim Reports Total Student Data Theft by Hackers

Black Basta-Style Cyberattack Bombards Inboxes with 1,165 Emails in Just 90 Minutes

Cyberattack Mimics Black Basta Tactics, Compromises Client Email Security In a recent cybersecurity incident, a wave of malicious emails, closely resembling the strategies employed by the infamous Black Basta ransomware group, targeted a client of SlashNext. Spanning a rapid 90-minute period, over 1,165 nefarious emails inundated the inboxes of 22…

Read MoreBlack Basta-Style Cyberattack Bombards Inboxes with 1,165 Emails in Just 90 Minutes

CISA Identifies Salt Typhoon Hackers in Federal Networks for the First Time

Critical Infrastructure Security, Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime US Cyber Defense Agency Was Not Initially Aware of Hackers Involved in Salt Typhoon Chris Riotta (@chrisriotta) • January 15, 2025 Director of the Cybersecurity and Infrastructure Security Agency, Jen Easterly, remarked that the Chinese “Salt Typhoon” breach of…

Read MoreCISA Identifies Salt Typhoon Hackers in Federal Networks for the First Time

New York Revises Data Breach Notification Law to Strengthen Notification Standards and Broaden Definition of ‘Private Information’ | Ogletree, Deakins, Nash, Smoak & Stewart, P.C.

On December 24, 2024, Governor Kathy Hochul of New York enacted significant amendments to both the state’s private-sector and government agency data breach notification laws. These revisions to the General Business Law § 899-aa and New York State Technology Law § 208 introduce strict new timelines and a broadened scope…

Read MoreNew York Revises Data Breach Notification Law to Strengthen Notification Standards and Broaden Definition of ‘Private Information’ | Ogletree, Deakins, Nash, Smoak & Stewart, P.C.

FunkSec Ransomware Developed with Artificial Intelligence

Ransomware incidences have recently surged, drawing attention to an emerging player in the cybercrime landscape. A group identifying itself as FunkSec has captured headlines by asserting responsibility for over 80 cyberattacks throughout December 2024, a claim underscored by a report from Check Point Software Technologies. FunkSec differentiates itself from other…

Read MoreFunkSec Ransomware Developed with Artificial Intelligence

AI and Applied Security Take Center Stage in Nullcon Paper Submissions

Endpoint Security, Hardware / Chip-level Security, Internet of Things Security CFP Board Members Discuss AI, Hardware Access and Emerging Trends for Nullcon 2025 Rahul Neel Mani (@rneelmani) • January 15, 2025 Neelu Tripathi, principal AppSec consultant and security researcher at Thoughtworks; and Anant Shrivastava, founder of Cyfinoid Research As cybersecurity…

Read MoreAI and Applied Security Take Center Stage in Nullcon Paper Submissions