The Breach News

Feds Link ‘Scattered Spider’ Pair to $115 Million in Ransom Payments – Krebs on Security

In a significant legal development, U.S. prosecutors recently filed criminal charges against Thalha Jubair, a 19-year-old from the U.K., in connection with his alleged involvement as a central figure in Scattered Spider, a notorious cybercrime organization implicated in extortion schemes totaling over $115 million. These accusations, which emerged as Jubair…

Read MoreFeds Link ‘Scattered Spider’ Pair to $115 Million in Ransom Payments – Krebs on Security

Supermicro Server Motherboards Vulnerable to Permanent Malware Infections

Critical Vulnerabilities Found in Supermicro Motherboards Expose Servers to Exploits Recent security findings have revealed significant vulnerabilities in servers powered by motherboards sold by Supermicro. These high-severity flaws enable attackers to remotely install malicious firmware that operates prior to the system’s operating system, resulting in infections that are challenging to…

Read MoreSupermicro Server Motherboards Vulnerable to Permanent Malware Infections

Aikido Security Acquires Allseek and Haicker: A Major Move in Security Systems News

Aikido Security Expands Reach with Acquisition of Allseek and Haicker Aikido Security has recently announced its acquisition of Allseek and Haicker, two firms known for their advancements in cybersecurity solutions. This move is significant as it positions Aikido to strengthen its offerings in an increasingly competitive landscape. The integration of…

Read MoreAikido Security Acquires Allseek and Haicker: A Major Move in Security Systems News

Cisco Confirms Salt Typhoon’s Exploitation of CVE-2018-0171 to Attack U.S. Telecom Networks

Cisco has disclosed that a Chinese threat actor, identified as Salt Typhoon, successfully infiltrated major U.S. telecommunications companies by exploiting a known vulnerability labeled CVE-2018-0171 and utilizing stolen login credentials. This targeted operation reflects the sophisticated methods employed by adversaries focusing on critical infrastructure. According to Cisco Talos, the group…

Read MoreCisco Confirms Salt Typhoon’s Exploitation of CVE-2018-0171 to Attack U.S. Telecom Networks

Meta Intensifies Efforts Against Cyber Espionage Operations Misusing Facebook in South Asia

Meta Platforms, the parent company of Facebook, has reported the dismantling of two sophisticated cyber-espionage campaigns targeting individuals across South Asia, utilizing its platforms as channels for malware dissemination. The operations, conducted by groups identified as Bitter APT and Transparent Tribe, showcase evolving tactics aimed at exploiting social media for…

Read MoreMeta Intensifies Efforts Against Cyber Espionage Operations Misusing Facebook in South Asia

Secret Service Neutralizes NY Telecom Threat During UN Meeting

Critical Infrastructure Security, Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime U.S. Secret Service Disrupts Network of Telecom Devices Targeting Government Officials Chris Riotta (@chrisriotta) • September 23, 2025 Equipment seized by the U.S. Secret Service prior to the United Nations General Assembly. (Image: U.S. Secret Service) The U.S. Secret…

Read MoreSecret Service Neutralizes NY Telecom Threat During UN Meeting

‘SIM Farms’ Are a Spam Epidemic: Federal Authorities Warn of a Major Threat to US Infrastructure from One in New York.

The recent discovery of a SIM farm operation in New York has highlighted a long-standing issue within the cybercrime landscape. SIM farms, which consist of large collections of SIM cards that can be remotely managed, have been exploited by criminals for various illicit activities, including spam distribution, swatting incidents, and…

Read More‘SIM Farms’ Are a Spam Epidemic: Federal Authorities Warn of a Major Threat to US Infrastructure from One in New York.

Chinese APT Leverages BeyondTrust API Key to Infiltrate U.S. Treasury Systems and Access Sensitive Documents

The U.S. Treasury Department has reported a significant cybersecurity breach that has purportedly provided suspected Chinese threat actors with remote access to some computers and unclassified documents. This incident was publicly disclosed following a communication from BeyondTrust, a third-party software provider of the Treasury, on December 8, 2024, regarding unauthorized…

Read MoreChinese APT Leverages BeyondTrust API Key to Infiltrate U.S. Treasury Systems and Access Sensitive Documents

Ransomware Turmoil Escalates Following Marks & Spencer Breach, Yet HyperBUNKER’s Innovative Diode Vault Challenges Traditional Data Protection Norms

Ransomware Attack on Marks & Spencer Exposes Flaws in Backup Strategies HyperBUNKER Advocates for Offline Storage Amid Criticism Over Costs Data Diodes Establish Secure One-Way Channels to Protect Data Integrity Marks & Spencer (M&S), a prominent UK retailer, recently faced a ransomware attack that significantly disrupted its internal operations, effectively…

Read MoreRansomware Turmoil Escalates Following Marks & Spencer Breach, Yet HyperBUNKER’s Innovative Diode Vault Challenges Traditional Data Protection Norms