The Breach News

OpenSSL Issues Patch for Two Critical Vulnerabilities

OpenSSL has announced critical updates addressing two high-severity vulnerabilities within its cryptographic library. These flaws, identified as CVE-2022-3602 and CVE-2022-3786, pose risks of denial-of-service (DoS) attacks and potential remote code execution (RCE). The vulnerabilities stem from buffer overrun issues that can be exploited during the verification of X.509 certificates, typically…

Read MoreOpenSSL Issues Patch for Two Critical Vulnerabilities

Caution: Avoid Clicking That Google Docs Link from Your Email!

Recent reports indicate that many individuals—including prominent journalists and cybersecurity professionals—are being targeted by a sophisticated OAuth phishing campaign masquerading as a legitimate Google Docs sharing notification. Upon receiving a seemingly innocuous email claiming that a contact has shared a document, users are advised not to click the link under…

Read MoreCaution: Avoid Clicking That Google Docs Link from Your Email!

Google Secures HTTPS with Quantum Technology, Compressing 2.5kB of Data into 64 Bytes – Ars Technica

Google Enhances TLS Certificate Security in Response to Quantum Threats In a significant advancement for internet security, Google announced plans to fortify its Transport Layer Security (TLS) certificates by integrating quantum-resistant algorithms. This move comes in the wake of growing concerns over the potential implications of quantum computing, particularly as…

Read MoreGoogle Secures HTTPS with Quantum Technology, Compressing 2.5kB of Data into 64 Bytes – Ars Technica

Hack of Trust Wallet Chrome Extension Leads to $8.5M Theft via Shai-Hulud Supply Chain Attack

Trust Wallet Suffers Major Cyber Breach: $8.5 Million in Assets Stolen On Tuesday, Trust Wallet disclosed a significant security compromise stemming from the re-emergence of the Shai-Hulud supply chain attack, which occurred in November 2025. This incident has been linked to a breach of Trust Wallet’s Google Chrome extension, resulting…

Read MoreHack of Trust Wallet Chrome Extension Leads to $8.5M Theft via Shai-Hulud Supply Chain Attack

New Menlo Security CEO Focuses on Agentic AI Runtime Protection

Artificial Intelligence & Machine Learning, Data Security, Next-Generation Technologies & Secure Development Former Mandiant Executive Bill Robbins Aims to Advance Browser-Based AI Security Michael Novinson (MichaelNovinson) • February 27, 2026 Bill Robbins, CEO, Menlo Security (Image: Menlo Security) Menlo Security has appointed Bill Robbins, a seasoned leader from Mandiant, as…

Read MoreNew Menlo Security CEO Focuses on Agentic AI Runtime Protection

Multiple Vulnerabilities Discovered in Checkmk IT Infrastructure Monitoring Software

Recent research has uncovered multiple critical vulnerabilities within Checkmk, an IT infrastructure monitoring software, which may allow an unauthenticated remote attacker to seize full control of affected systems. These vulnerabilities could potentially be mishandled collectively, posing significant risks to users, especially those utilizing Checkmk version 2.1.0p10 or older. Stefan Schiller,…

Read MoreMultiple Vulnerabilities Discovered in Checkmk IT Infrastructure Monitoring Software

Ilya Lichtenstein, Convicted in Bitfinex Hack, Released Early Under U.S. First Step Act

Ilya Lichtenstein, previously convicted of money laundering linked to the 2016 hack of the cryptocurrency exchange Bitfinex, has announced his early release from prison. In a recent post on X, Lichtenstein, 38, attributed his release to the First Step Act, a criminal justice reform law enacted during the Trump administration,…

Read MoreIlya Lichtenstein, Convicted in Bitfinex Hack, Released Early Under U.S. First Step Act