The Breach News

Salt Typhoon Strikes European Telecom Sector

Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Darktrace Reports on Compromise of Citrix NetScaler Gateway Akshaya Asokan (asokan_akshaya) • October 20, 2025 Image: Shutterstock Recent reports from the managed threat detection firm Darktrace indicate that a persistent campaign by the Chinese cyber espionage group known as Salt Typhoon continues…

Read MoreSalt Typhoon Strikes European Telecom Sector

Hackers Exploit Citrix Vulnerability and Snappybee Malware to Compromise European Telecom Network

October 21, 2025Ravie LakshmananCyber Espionage / Network Security A European telecommunications company has reportedly fallen victim to a cyber intrusion attributed to a threat actor associated with the China-linked group known as Salt Typhoon. This incident, as reported by Darktrace, took place during the first week of July 2025. Attackers…

Read MoreHackers Exploit Citrix Vulnerability and Snappybee Malware to Compromise European Telecom Network

Serious SailPoint IdentityIQ Vulnerability Allows Unauthorized File Access

Critical Vulnerability Discovered in SailPoint’s IdentityIQ Software A significant security vulnerability has been identified in SailPoint’s IdentityIQ identity and access management (IAM) software, potentially exposing sensitive data stored in application directories. The flaw, designated CVE-2024-10905, carries a maximum CVSS score of 10.0, highlighting its critical severity. This vulnerability affects various…

Read MoreSerious SailPoint IdentityIQ Vulnerability Allows Unauthorized File Access

WIRTE Hacker Group Attacks Government, Legal, and Financial Institutions in the Middle East

Stealth Malware Campaign Targets Middle Eastern Entities A sophisticated malware campaign has been uncovered, targeting government bodies, military organizations, law firms, and financial institutions predominantly in the Middle East. Initiated as early as 2019, the campaign leverages malicious Microsoft Excel and Word documents to infiltrate victim networks. Kaspersky, a Russian…

Read MoreWIRTE Hacker Group Attacks Government, Legal, and Financial Institutions in the Middle East

JumpCloud Attributes Security Breach to ‘Advanced Nation-State’ Actor

In a significant security breach, JumpCloud has confirmed that a sophisticated nation-state actor infiltrated its systems, targeting a select group of its customers. Shortly following a reset of API keys for affected clients, Bob Phan, Chief Information Security Officer (CISO) at JumpCloud, stated, “The adversary gained unauthorized access to our…

Read MoreJumpCloud Attributes Security Breach to ‘Advanced Nation-State’ Actor

Dodo and iPrimus Data Breach: Email and SIM Card Compromise | Information Age

Cybersecurity Incident: Dodo and iPrimus Email Accounts Compromised In a recent incident, Vocus Group has confirmed a significant data breach affecting its telecommunications brands, Dodo and iPrimus. The breach has led to the unauthorized access of approximately 1,600 Dodo email accounts and subsequent SIM swap fraud affecting 34 Dodo Mobile…

Read MoreDodo and iPrimus Data Breach: Email and SIM Card Compromise | Information Age

Veeam Releases Patch for Critical RCE Vulnerability in Service Provider Console

Critical Vulnerability Discovered in Veeam Service Provider Console Veeam has issued immediate security updates addressing a significant vulnerability within its Service Provider Console (VSPC). This flaw poses a serious risk, enabling potential remote code execution on vulnerable systems. The vulnerability, designated as CVE-2024-42448, has been assigned a critical CVSS score…

Read MoreVeeam Releases Patch for Critical RCE Vulnerability in Service Provider Console