The Breach News

Over 115,000 Drupal Sites Remain Susceptible to Drupalgeddon2 Exploit

Critical Security Flaw Leaves Thousands of Drupal Websites Vulnerable A significant security vulnerability impacting websites built on the Drupal content management system (CMS) has come to light, with over 115,000 sites remaining unpatched months after security fixes were released. This highly critical vulnerability, known as Drupalgeddon2 (CVE-2018-7600), was initially identified…

Read MoreOver 115,000 Drupal Sites Remain Susceptible to Drupalgeddon2 Exploit

Why is Microsoft Redirecting example.com Traffic to a Company in Japan?

Microsoft Network Anomaly Redirects Traffic Intended for Testing Domain In an unusual incident reported by Microsoft, an unexplained network anomaly inadvertently redirected traffic meant for the testing domain example.com to a Japanese electronics cable manufacturer, Sumitomo Electric. The example.com domain, outlined under RFC2606, is designated solely for illustrative and testing…

Read MoreWhy is Microsoft Redirecting example.com Traffic to a Company in Japan?

Part II: These 7 Major Cyber Attacks Show That No One is Safe from Hacking

In an increasingly interconnected world, recent cyber incidents underscore the vulnerabilities that organizations face today. A notable highlight includes a series of impactful cyber attacks that exemplify the pressing need for robust cybersecurity measures across various sectors. One alarming case involved the hacking of vehicles, particularly the Jeep Cherokee. Security…

Read MorePart II: These 7 Major Cyber Attacks Show That No One is Safe from Hacking

Real-Time Phishing Kits Now Targeting Okta, Microsoft, and Google

Cybersecurity experts are currently grappling with a surge of voice-phishing attacks aimed at single sign-on (SSO) tools. These coordinated efforts have led to instances of data theft and extortion, as various cybercrime groups, including one claiming ties to ShinyHunters, harness sophisticated voice calls and phishing kits to deceive victims into…

Read MoreReal-Time Phishing Kits Now Targeting Okta, Microsoft, and Google

North Korean Hacker Group Andariel Launches New EarlyRat Malware Attack

A new report has unveiled a previously undocumented malware variant, named EarlyRat, which has been utilized by the North Korean-aligned threat actor known as Andariel in targeted phishing campaigns. This addition enhances Andariel’s already diverse toolkit, marking a notable shift in their operational capabilities. Kaspersky’s latest findings reveal that Andariel…

Read MoreNorth Korean Hacker Group Andariel Launches New EarlyRat Malware Attack

Wiper Malware Aimed at Poland’s Power Grid Linked to Moscow

Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Indicators Reveal Prolonged Engagement by ‘Sandworm’ Military Intelligence Hackers Mathew J. Schwartz (euroinfosec) • January 26, 2026 Polish Prime Minister Donald Tusk speaks at a press conference on January 15, detailing Russian cyberattacks on Poland’s power grid in late 2025. (Image: Polish…

Read MoreWiper Malware Aimed at Poland’s Power Grid Linked to Moscow