The Breach News

Ransomware Group FIN12 Intensifies Attacks on Healthcare Sector

A financially motivated threat group, identified as FIN12, has been linked to a series of RYUK ransomware incidents since October 2018. This organization demonstrates significant collaboration with TrickBot-affiliated actors while utilizing publicly accessible tools like Cobalt Strike Beacon payloads to penetrate victim networks. Cybersecurity firm Mandiant has attributed these security…

Read MoreRansomware Group FIN12 Intensifies Attacks on Healthcare Sector

Mailchimp Experiences Another Security Breach, Exposing Certain Customer Data

Mailchimp, a prominent email marketing and newsletter service provider based in the U.S., has announced a significant security breach resulting from a sophisticated social engineering attack. This incident has compromised the accounts of 133 customers, raising concerns about the vulnerabilities faced by organizations in the digital landscape. According to Mailchimp,…

Read MoreMailchimp Experiences Another Security Breach, Exposing Certain Customer Data

Transforming Experience into Influence: Careers in Cyber Education

Security Awareness Programs & Computer-Based Training, Training & Security Leadership Cyber Professionals Can Follow Two Distinct Career Paths in Training and Education Brandy Harris • October 22, 2025 Image: Shutterstock Upon entering the field of cybersecurity education, I found my background rooted in teaching rather than security operations. This evolving…

Read MoreTransforming Experience into Influence: Careers in Cyber Education

Landmark Data Breach Fine Serves as a Warning to Australian Businesses, More Penalties Ahead

Major Cybersecurity Breach Leads to Substantial Penalty for Australian Clinical Labs Australian Clinical Labs Limited (ACL), a prominent private pathology service provider in Australia, has been ordered to pay a total of A$5.8 million (approximately US$3.8 million) in penalties, alongside A$400,000 for legal costs, following court approval of a settlement…

Read MoreLandmark Data Breach Fine Serves as a Warning to Australian Businesses, More Penalties Ahead

Russian Hackers Leverage New NTLM Vulnerability to Distribute RAT Malware through Phishing Campaigns

A newly discovered security vulnerability in Windows NT LAN Manager (NTLM) has been exploited in a zero-day attack, with suspected ties to Russian threat actors targeting Ukraine. This vulnerability, designated as CVE-2024-43451 and rated with a CVSS score of 6.5, allows attackers to possibly expose a user’s NTLMv2 hash. Microsoft…

Read MoreRussian Hackers Leverage New NTLM Vulnerability to Distribute RAT Malware through Phishing Campaigns

Microsoft Alerts About Iran-Linked Hackers Targeting US and Israeli Defense Companies

A new hacking group reportedly aligned with Iranian national interests has been observed executing a password spraying campaign aimed at defense technology companies in the U.S., European Union, and Israel. This campaign has also extended to regional ports of entry in the Persian Gulf and maritime companies operating in the…

Read MoreMicrosoft Alerts About Iran-Linked Hackers Targeting US and Israeli Defense Companies

Everest Ransomware Claims to Have Acquired 1.5 Million Passenger Records from Dublin Airport

In a significant cybersecurity incident, the Everest ransomware group has revealed that it has targeted two new victims: Dublin Airport and Air Arabia. This development follows the group’s recent announcement regarding a breach of AT&T Careers, where they claimed to have stolen personal records of approximately 576,000 applicants and employees.…

Read MoreEverest Ransomware Claims to Have Acquired 1.5 Million Passenger Records from Dublin Airport

GoTo, Parent Company of LastPass, Faces Data Breach with Compromised Customer Backups

GoTo, Formerly LogMeIn, Reports Data Breach Affecting User Data GoTo, the parent company of LastPass and formerly known as LogMeIn, disclosed on Tuesday a significant data breach involving the theft of encrypted backups of customer information. This incident, which occurred in November 2022, involved unauthorized actors accessing data from a…

Read MoreGoTo, Parent Company of LastPass, Faces Data Breach with Compromised Customer Backups

Mitigating AI-Driven Insider Threats: Addressing Human Risk in 2025

Human Risk in 2025: Combatting AI-Driven Insider Threats As we look ahead to 2025, the cybersecurity landscape is increasingly shaped by the sophisticated capabilities of artificial intelligence. One of the most pressing concerns for organizations is the rise of AI-powered insider threats. These threats, originating from individuals within an organization…

Read MoreMitigating AI-Driven Insider Threats: Addressing Human Risk in 2025