The Breach News

DOGE Transfers Social Security Data to the Cloud

Cybercrime, Fraud Management & Cybercrime Recent Developments: CIRO Phishing Breach, Ingram Micro Ransomware, and CVE Increase Pooja Tikekar (@PoojaTikekar) • January 22, 2026 Image: Shutterstock/ISMG ISMG compiles weekly summaries of cybersecurity breaches globally. Recent incidents include sensitive data shared by the U.S. Social Security Administration on an unauthorized Cloudflare server,…

Read MoreDOGE Transfers Social Security Data to the Cloud

January 23: Kazakhstan Takes Steps to Criminalize Large-Scale Data Breaches

Kazakhstan Advances Data Breach Law Reforms, Elevating Risks for Australian Firms Kazakhstan is set to implement significant reforms to its data breach laws, which will introduce criminal charges for mass personal data leaks while increasing the maximum fines to approximately $42,500. This legislative move signals an escalating commitment to stricter…

Read MoreJanuary 23: Kazakhstan Takes Steps to Criminalize Large-Scale Data Breaches

New P2PInfect Worm Affects Redis Servers on Linux and Windows Platforms

Cybersecurity experts have identified a new peer-to-peer (P2P) worm named P2PInfect, which specifically targets vulnerable Redis installations for subsequent exploitation. Unlike many previous threats, P2PInfect can compromise Redis servers operating on both Linux and Windows platforms, making it a particularly formidable threat, as noted by researchers from Palo Alto Networks’…

Read MoreNew P2PInfect Worm Affects Redis Servers on Linux and Windows Platforms

Stolen D-Link Certificate Exploited to Digitally Sign Surveillance Malware

Digitally signed malware has gained traction recently, utilizing legitimate digital certificates to mask malicious activities. Recent investigations have uncovered a malware campaign employing stolen valid digital certificates from Taiwanese technology firms, including D-Link, to authenticate their harmful applications and thereby appear trustworthy to unwitting users. Digital certificates, issued by recognized…

Read MoreStolen D-Link Certificate Exploited to Digitally Sign Surveillance Malware

Drowning in AI Noise, cURL Halts Bug Bounties to Safeguard “Mental Well-being”

cURL Project Ends Vulnerability Reward Program Amid AI Report Surge The developers behind cURL, a widely-used networking tool, are discontinuing their vulnerability reward program due to a significant influx of low-quality submissions, many of which have been identified as AI-generated. Daniel Stenberg, the founder and lead developer of the open-source…

Read MoreDrowning in AI Noise, cURL Halts Bug Bounties to Safeguard “Mental Well-being”

Coupang Investors Call for US Intervention, Potentially Straining Trade Relations with Seoul

Coupang CEO Apologizes for Data Breach, Again Fails to Attend Parliamentary Hearing Bom Kim, the founder and CEO of Coupang, Inc., publicly apologized on Sunday regarding a significant data breach that has impacted nearly the entirety of the company’s customer base. This incident has prompted a comprehensive tax investigation by…

Read MoreCoupang Investors Call for US Intervention, Potentially Straining Trade Relations with Seoul