The Breach News

Apache Tomcat Vulnerability Exploited Within 30 Hours of Public Release

A recently uncovered security vulnerability in Apache Tomcat has begun to see active exploitation shortly after its disclosure. The flaw, designated as CVE-2025-24813, was made publicly available along with a proof-of-concept (PoC) within just 30 hours of its initial announcement. This vulnerability impacts several versions of Apache Tomcat, including 11.0.0-M1…

Read MoreApache Tomcat Vulnerability Exploited Within 30 Hours of Public Release

Chinese Hackers Employ Stealthy Infection Chain to Deploy LODEINFO Malware

A recently reported cybersecurity incident has revealed a stealthy infection chain employed by the Chinese state-sponsored group known as Stone Panda. This threat actor has been targeting various entities in Japan, including media outlets, governmental and public sector organizations, as well as think tanks, raising alarms about the potential risk…

Read MoreChinese Hackers Employ Stealthy Infection Chain to Deploy LODEINFO Malware

Two Eye Care Practice Strategies Impact 260,000 Patients and Staff

Data Breach Notification, Data Security, Fraud Management & Cybercrime Recent Cyberattacks Target Ophthalmology Practices in South Dakota and Florida Marianne Kolbasuk McGee (HealthInfoSec) • September 16, 2025 Major hacking breaches have affected the Retina Group of Florida and Black Hills Regional Eye Institute this year. (Image: Retina Group of Florida,…

Read MoreTwo Eye Care Practice Strategies Impact 260,000 Patients and Staff

RansomHub Named 2024’s Leading Ransomware Group, Targeting Over 600 Organizations Worldwide

Rise of RansomHub: A Resurgent Threat in Cybercrime The RansomHub ransomware-as-a-service (RaaS) group has emerged as a significant player in the cybercrime landscape, capitalizing on previously patched vulnerabilities in Microsoft Active Directory and the Netlogon protocol to facilitate unauthorized access to victim networks. Recent analyses highlight the group’s ability to…

Read MoreRansomHub Named 2024’s Leading Ransomware Group, Targeting Over 600 Organizations Worldwide

Nearly 700,000 Customers Affected by Insider Attack at U.S. Fintech Company

A US-based fintech company, FinWise, has alerted its customers about a potential data breach stemming from an insider threat. The organization, which facilitates loans on behalf of various American financial institutions, disclosed that a former employee accessed sensitive customer information after their departure from the company. According to filings made…

Read MoreNearly 700,000 Customers Affected by Insider Attack at U.S. Fintech Company

New Critical AMI BMC Vulnerability Allows Remote Server Takeover and Bricking

Serious Security Flaw Discovered in AMI’s MegaRAC BMC Software A significant security vulnerability has been identified within AMI’s MegaRAC Baseboard Management Controller (BMC) software, which allows malicious actors to bypass authentication processes and execute unauthorized actions on affected systems. This vulnerability is classified as CVE-2024-54085, and it has been assigned…

Read MoreNew Critical AMI BMC Vulnerability Allows Remote Server Takeover and Bricking

Former BreachForums Administrator Sentenced to 3 Years in Prison

Cybercrime, Fraud Management & Cybercrime Prosecutors Seek 188-Month Sentence for Conor ‘Pompompurin’ Fitzpatrick David Perera (@daveperera) • September 16, 2025 The U.S. District Court for the Eastern District of Virginia. (Image: DCStockPhotography/Shutterstock) Conor Brian Fitzpatrick, the founder of the first iteration of the BreachForums cybercrime forum, received a three-year prison…

Read MoreFormer BreachForums Administrator Sentenced to 3 Years in Prison

Top 5 VPN Services of 2025: In-Depth Reviews and Testing

Sure! Here’s a rewritten version of the provided content, tailored for a US-based, tech-savvy professional audience: Evaluating Additional VPN Providers Recent assessments have revealed significant insights into various VPN providers, underscoring contrasting capabilities in speed, privacy, and overall user experience. Private Internet Access (PIA) has established itself as a longstanding…

Read MoreTop 5 VPN Services of 2025: In-Depth Reviews and Testing