The Breach News

Alert: 3 Major Vulnerabilities Put ownCloud Users at Risk of Data Breaches

Recent advisories from the maintainers of ownCloud have revealed three critical vulnerabilities within their open-source file-sharing software that could lead to unauthorized access, data modification, and exposure of sensitive information. These vulnerabilities pose significant risks to users and require immediate attention. The first flaw, identified as CVE-2023-49103, boasts a CVSS…

Read MoreAlert: 3 Major Vulnerabilities Put ownCloud Users at Risk of Data Breaches

ALERT: Hackers Deploy Hidden Backdoor on Thousands of Microsoft SQL Servers

Malicious Campaign Targeting MS-SQL Servers Discovered by Researchers Cybersecurity experts have identified a prolonged malicious campaign that has been active since May 2018, focusing on Windows machines equipped with MS-SQL servers. The campaign, named “Vollgar” after the Vollar cryptocurrency it mines, is aimed at deploying backdoors and diverse malware, including…

Read MoreALERT: Hackers Deploy Hidden Backdoor on Thousands of Microsoft SQL Servers

Forever 21 Alerts Shoppers to Payment Card Breach at Certain Locations

In a troubling development for the retail sector, Forever 21 has announced a payment card data breach affecting its customers. The Los Angeles-based fast-fashion retailer revealed that hackers managed to access payment card information from various store locations, posing a significant cybersecurity risk. The incident was brought to light earlier…

Read MoreForever 21 Alerts Shoppers to Payment Card Breach at Certain Locations

LastPass 2022 Breach Resulted in Prolonged Cryptocurrency Theft, According to TRM Labs

Dec 25, 2025Ravie LakshmananData Breach / Financial Crime Recent findings from TRM Labs reveal that encrypted vault backups compromised in the 2022 LastPass data breach have been exploited by cybercriminals to access crypto assets, particularly due to the use of weak master passwords. This criminal activity has reportedly persisted into…

Read MoreLastPass 2022 Breach Resulted in Prolonged Cryptocurrency Theft, According to TRM Labs

Dark Nexus: Newly Discovered IoT Botnet Malware Identified in the Wild

Emergence of the Dark_Nexus IoT Botnet: A New Threat to Cybersecurity Cybersecurity experts have unveiled a sophisticated new IoT botnet known as “dark_nexus,” which is leveraging compromised smart devices to launch distributed denial-of-service (DDoS) attacks. This emerging threat can be triggered on demand through platforms offering DDoS-for-hire services, placing numerous…

Read MoreDark Nexus: Newly Discovered IoT Botnet Malware Identified in the Wild

Data Breach Update: Spotify Metadata Leaked Online

Topics: Fraud Management & Cybercrime, Fraud Risk Management, Ransomware Additional Coverage: SudamericaData Leak, RaccoonO365 Arrest, and Nefilim Case Update By Pooja Tikekar (@PoojaTikekar) • December 25, 2025 Image: Shutterstock/ISMG Every week, the Information Security Media Group provides a roundup of global cybersecurity incidents and data breaches. In this edition, a…

Read MoreData Breach Update: Spotify Metadata Leaked Online