The Breach News

As Digital Payments Surge, Here’s How Small Retailers Can Tackle Cybersecurity Threats

Cybersecurity Vulnerabilities: SMEs as Prime Targets Many small and medium-sized enterprises (SMEs) operate under the erroneous belief that their size shields them from the attentions of cybercriminals. This misconception could not be further from the truth. In fact, SMEs are increasingly becoming prime targets for a range of cyber threats,…

Read MoreAs Digital Payments Surge, Here’s How Small Retailers Can Tackle Cybersecurity Threats

Google Cloud Researchers Identify Vulnerabilities in Rsync File Synchronization Tool

Recent disclosures have unveiled up to six security vulnerabilities within the widely-used Rsync file synchronization tool, critical for Unix-based systems. These vulnerabilities present significant risks, including the potential for attackers to execute arbitrary code on client machines. The CERT Coordination Center (CERT/CC) alerted users that exploiting these flaws could allow…

Read MoreGoogle Cloud Researchers Identify Vulnerabilities in Rsync File Synchronization Tool

Introducing ‘SockDetour’: A Fileless, Socketless Backdoor Targeting U.S. Defense Contractors

Title: New Malware ‘SockDetour’ Exposed as a Menace to U.S. Defense Contractors Recent research unveiled a sophisticated and previously unreported malware known as SockDetour, which has been targeting defense contractors in the United States. This stealthy backdoor is engineered to act as a secondary implant on compromised Windows systems, raising…

Read MoreIntroducing ‘SockDetour’: A Fileless, Socketless Backdoor Targeting U.S. Defense Contractors

Arrests Highlight Concerns Over Teen Recruitment for Cyberespionage

Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Telegram Utilized in Recruitment of Teenage Cyber Reconnaissance Chris Riotta (@chrisriotta) • October 8, 2025 Europol headquarters in The Hague, Netherlands, captured in a photo dated December 7, 2019. (Image: Aperture Exposure Images/Shutterstock) In late September, law enforcement in the Netherlands arrested…

Read MoreArrests Highlight Concerns Over Teen Recruitment for Cyberespionage

Salesforce Declines to Meet $1 Billion Extortion Demand Following Data Breach of 1 Billion Records

Salesforce is facing a serious cybersecurity threat as a criminal syndicate, identifying itself as Scattered LAPSUS$ Hunters, has made allegations of stealing around one billion records from multiple Salesforce customers. The group initiated this extortion campaign back in May, utilizing voice calls to reach organizations that utilize Salesforce for data…

Read MoreSalesforce Declines to Meet $1 Billion Extortion Demand Following Data Breach of 1 Billion Records

Ukrainian Cryptojacking Kingpin Arrested at 29 for Exploiting Cloud Services

Ukrainian National Arrested for Sophisticated Cryptojacking Scheme A 29-year-old individual from Ukraine has been apprehended for orchestrating a comprehensive cryptojacking operation, which has reportedly yielded over $2 million (€1.8 million) in illicit earnings. Identified as the key architect behind the scheme, the suspect was arrested in Mykolaiv on January 9…

Read MoreUkrainian Cryptojacking Kingpin Arrested at 29 for Exploiting Cloud Services

Researcher Identifies Significant Vulnerabilities in Various Iterations of Ivanti Endpoint Manager

Ivanti Security Updates Patch Critical Vulnerabilities in Endpoint Manager Ivanti has announced the release of critical security updates to mitigate several vulnerabilities affecting its Avalanche, Application Control Engine, and Endpoint Manager (EPM) products. Among these are four significant flaws, each rated 9.8 out of 10.0 on the Common Vulnerability Scoring…

Read MoreResearcher Identifies Significant Vulnerabilities in Various Iterations of Ivanti Endpoint Manager

Russia-Ukraine Conflict: Phishing, Malware, and Hacker Factions Aligning with Their Causes

Ukraine’s Computer Emergency Response Team (CERT-UA) has issued a warning regarding cyber attacks orchestrated by Belarusian state-sponsored hackers, aimed at military personnel and associated individuals amid the ongoing conflict in Ukraine. This phishing campaign is significant as it targets accounts affiliated with the Ukrainian military, specifically personal accounts hosted on…

Read MoreRussia-Ukraine Conflict: Phishing, Malware, and Hacker Factions Aligning with Their Causes