The Breach News

European Capitals Resist Proposed Changes to GDPR

Artificial Intelligence & Machine Learning, General Data Protection Regulation (GDPR), Next-Generation Technologies & Secure Development EU Council Rejects Redefined ‘Personal Data’ Classification David Meyer • February 24, 2026 Image: Christophe Licoppe/Shutterstock The Council of the European Union has formally rejected a proposal from the European Commission aimed at redefining ‘personal…

Read MoreEuropean Capitals Resist Proposed Changes to GDPR

Public Prosecutor’s Office Initiates Investigation into Odido Cyberattack

The Dutch Public Prosecutor’s Office has initiated a criminal investigation into a significant cyberattack on the telecom provider Odido, resulting in the theft of millions of customer records. While the investigation is confirmed, no additional details have been disclosed at this time. Odido has also opted for no public commentary…

Read MorePublic Prosecutor’s Office Initiates Investigation into Odido Cyberattack

Critical RCE Vulnerability Discovered in Spotify’s Backstage Developer Platform and Software Catalog

Spotify’s Backstage has been identified as vulnerable to a significant security flaw that could allow remote code execution through the exploitation of a recently disclosed bug in a third-party module. This vulnerability has been assigned a CVSS score of 9.8, indicating a critical risk level. At the core of the…

Read MoreCritical RCE Vulnerability Discovered in Spotify’s Backstage Developer Platform and Software Catalog

New Fileless Ransomware with Code Injection Capabilities Discovered in the Wild

Emerging Threat: Fileless Ransomware “Sorebrect” Targets Enterprises Cybercriminals are evolving, leveraging increasingly sophisticated tactics to execute attacks. A recent report highlights the emergence of a fileless ransomware strain known as “Sorebrect.” Unlike traditional ransomware, which often relies on files to infect systems, Sorebrect injects malicious code directly into legitimate processes,…

Read MoreNew Fileless Ransomware with Code Injection Capabilities Discovered in the Wild

Dutch Authorities Confirm Exposure of Employee Contact Data Due to Ivanti Zero-Day Exploit

The Dutch Data Protection Authority (AP) and the Council for the Judiciary have confirmed that their systems were compromised in a cyber attack exploiting vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM). This information was disclosed in a notice to the Dutch parliament, revealing that both agencies experienced unauthorized access to…

Read MoreDutch Authorities Confirm Exposure of Employee Contact Data Due to Ivanti Zero-Day Exploit

Ad Tech Firm Optimizely Hit by Cyberattack – SecurityWeek

Optimizely Targeted in Cyberattack: A Comprehensive Overview In a notable cybersecurity incident, Optimizely, a prominent ad tech company, has recently fallen victim to a cyberattack that has raised significant concerns within the industry. This breach highlights vulnerabilities within digital marketing infrastructures and serves as a stark reminder of the ongoing…

Read MoreAd Tech Firm Optimizely Hit by Cyberattack – SecurityWeek

Iranian Hackers Breach U.S. Federal Agency Network via Log4Shell Exploit

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reported a security breach involving a federal agency, attributed to threat actors affiliated with the Iranian government. The attackers exploited the Log4Shell vulnerability found in an unpatched VMware Horizon server, demonstrating a sophisticated exploitation technique. The breach, which occurred between mid-June…

Read MoreIranian Hackers Breach U.S. Federal Agency Network via Log4Shell Exploit