The Breach News

Customer Names and Emails Compromised

In a troubling development for the automotive sector, Stellantis NV, the global company behind well-known brands such as Jeep, Chrysler, and Fiat, has reported a data breach that has exposed customer information via a third-party service provider. The breach impacted the company’s North American customer service operations, revealing personal data…

Read MoreCustomer Names and Emails Compromised

Hackers Exploit Vulnerability in Krpano Framework to Inject Spam Ads on Over 350 Websites

A significant security vulnerability, identified as a cross-site scripting (XSS) flaw, has been exploited in a widely-used virtual tour framework, allowing cybercriminals to inject harmful scripts into hundreds of websites. This malicious activity aims to manipulate search results and promote spam advertising on a large scale. According to a report…

Read MoreHackers Exploit Vulnerability in Krpano Framework to Inject Spam Ads on Over 350 Websites

Experts Caution About Continued Widespread Exploitation of Zimbra RCE Vulnerability

On Thursday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported the addition of two critical vulnerabilities to its Known Exploited Vulnerabilities Catalog, both linked to severe weaknesses within Zimbra Collaboration software. These flaws have shown substantial evidence of active exploitation, posing significant risks to affected email servers. The vulnerabilities…

Read MoreExperts Caution About Continued Widespread Exploitation of Zimbra RCE Vulnerability

ENISA Reports Ransomware Attack Linked to Collins Aerospace Hack

Fraud Management & Cybercrime, Ransomware Service Disruptions Persist at Major European Airports Following Recent Cyberattack Akshaya Asokan (asokan_akshaya) • September 22, 2025 Flight cancellations at Brussels International Airport on May 4, 2010. (Image: Shutterstock) In a significant cyber incident categorized as a ransomware attack, several major European airports, including London…

Read MoreENISA Reports Ransomware Attack Linked to Collins Aerospace Hack

How the Powerful Atomic Credential Stealer is Making Its Way onto Macs

Credential Stealer Targets LastPass Users via Malicious Ads Recent reports have surfaced regarding a cybersecurity threat involving malicious advertisements that impersonate various online services, with a particular focus on users of the LastPass password manager. Security firms have alerted the public about this campaign, which aims to infect Mac computers…

Read MoreHow the Powerful Atomic Credential Stealer is Making Its Way onto Macs

Google OAuth Flaw Exposes Millions Through Unsecured Startup Domains

Recent investigations have unveiled a serious vulnerability within Google’s “Sign in with Google” authentication system, which can be exploited through a peculiar loophole in domain ownership. This flaw potentially allows unauthorized users to access sensitive data associated with former employees of defunct companies. Dylan Ayrey, co-founder and CEO of Truffle…

Read MoreGoogle OAuth Flaw Exposes Millions Through Unsecured Startup Domains

Stellantis, Manufacturer of Citroën, FIAT, Jeep, and More, Confirms Data Breach

Stellantis, the multinational automotive corporation behind brands such as Citroën, FIAT, Jeep, Chrysler, and Peugeot, has disclosed a data breach impacting its North American customers. This incident highlights significant vulnerabilities in third-party service provider networks associated with customer service operations. On Sunday, Stellantis reported the detection of unauthorized access to…

Read MoreStellantis, Manufacturer of Citroën, FIAT, Jeep, and More, Confirms Data Breach

Hackers Leverage Vulnerability in Paragon Partition Manager Driver for Ransomware Attacks

Recent investigations have unveiled that cybercriminals have exploited a critical vulnerability in the BioNTdrv.sys driver of Paragon Partition Manager, leveraging it in ransomware attacks to escalate privileges and execute unauthorized code. This significant zero-day vulnerability, classified as CVE-2025-0289, is part of a broader set of five vulnerabilities identified by Microsoft…

Read MoreHackers Leverage Vulnerability in Paragon Partition Manager Driver for Ransomware Attacks

Chinese Hackers Compromise MiMi Chat App to Target Windows, Linux, and macOS Users

Recent investigations by cybersecurity firms SEKOIA and Trend Micro have uncovered a new campaign led by the Chinese threat actor known as Lucky Mouse. This operation involves deploying a compromised version of the MiMi chat application, which serves as a vector for backdoor attacks on systems across multiple platforms. The…

Read MoreChinese Hackers Compromise MiMi Chat App to Target Windows, Linux, and macOS Users