The Breach News

FritzFrog Strikes Again: Log4Shell and PwnKit Used to Deliver Malware Within Your Network

The notorious peer-to-peer (P2P) botnet known as FritzFrog has resurfaced with a new variant exploiting the critically recognized Log4Shell vulnerability. This sophisticated malware aims to propagate internally within networks that have already suffered compromises. According to a report by Akamai, a prominent web infrastructure and security company, the exploitation mechanism…

Read MoreFritzFrog Strikes Again: Log4Shell and PwnKit Used to Deliver Malware Within Your Network

Extracting Data from Air-Gapped Computers Using Wi-Fi Signals (No Wi-Fi Equipment Required)

A recent breakthrough in cybersecurity research reveals a significant vulnerability within air-gapped systems, which are designed to be isolated from unsecured networks. Researchers have successfully demonstrated a method for exfiltrating sensitive data using a novel attack called AIR-FI. This technique operates by leveraging electromagnetic emissions from the computer’s DDR SDRAM…

Read MoreExtracting Data from Air-Gapped Computers Using Wi-Fi Signals (No Wi-Fi Equipment Required)

Senators Reintroduce Legislation to Enhance Cybersecurity in Healthcare

New Bipartisan Bill Aims to Fortify Healthcare Cybersecurity with Enhanced Regulations and Support Marianne Kolbasuk McGee (HealthInfoSec) • December 8, 2025 A bipartisan coalition of U.S. senators has reintroduced a significant cybersecurity bill aimed at enhancing protections in the healthcare sector. (Image: U.S. Congress) A bipartisan group of four U.S.…

Read MoreSenators Reintroduce Legislation to Enhance Cybersecurity in Healthcare

Coupang Hit with U.S. Lawsuit for Punitive Damages Following Data Breach – 조선일보

Coupang Faces U.S. Lawsuit for Punitive Damages Following Data Breach In a significant development within the cybersecurity landscape, Coupang, a prominent South Korean e-commerce platform, is now facing a lawsuit in the United States related to a recent data breach. This legal action seeks punitive damages, reflecting mounting concerns over…

Read MoreCoupang Hit with U.S. Lawsuit for Punitive Damages Following Data Breach – 조선일보

Mastodon Security Flaw Lets Hackers Take Control of Any Decentralized Account

A significant security vulnerability has been identified within the decentralized social network Mastodon, enabling attackers to impersonate any user and seize control of their accounts. The issue stems from inadequate origin validation, as stated in a recent advisory from Mastodon’s maintainers. This vulnerability, cataloged as CVE-2024-23832, carries a severity score…

Read MoreMastodon Security Flaw Lets Hackers Take Control of Any Decentralized Account

Almost 18,000 SolarWinds Clients Installed Compromised Software

SolarWinds, a Texas-based supplier of enterprise monitoring software, has acknowledged a major cybersecurity incident linked to a compromised version of its Orion products. Up to 18,000 customers, including numerous Fortune 500 companies and U.S. military branches, may have implemented this affected software, raising significant alarm across various sectors. This revelation…

Read MoreAlmost 18,000 SolarWinds Clients Installed Compromised Software

France Fines Google $57 Million for Insufficient Transparency and Consent

In a significant enforcement action under the European Union’s General Data Protection Regulation (GDPR), France’s data protection authority, CNIL, has imposed a €50 million (approximately $57 million) fine on Google. This marks the first major penalty levied under the GDPR since its implementation in May 2018. The CNIL cited “lack…

Read MoreFrance Fines Google $57 Million for Insufficient Transparency and Consent

NCSC Alerts: AI Prompt Injection Risks Major Data Breaches in the UK

Growing Concerns Over AI Vulnerabilities in the UK: NCSC Warns of Prompt Injection Risks The National Cyber Security Centre (NCSC) has issued a significant warning regarding a misunderstanding that could expose UK organizations to serious data breaches. As generative AI technologies continue to proliferate, many developers and cybersecurity professionals are…

Read MoreNCSC Alerts: AI Prompt Injection Risks Major Data Breaches in the UK

Widespread Exploitation of Recent SSRF Vulnerability in Ivanti VPN Products

Mass Exploitation of SSRF Vulnerability in Ivanti Products A significant server-side request forgery (SSRF) vulnerability affecting Ivanti Connect Secure and Policy Secure products has been widely exploited. Recent reports indicate that attacks are emanating from over 170 distinct IP addresses, indicating a coordinated effort to establish unauthorized access, including reverse…

Read MoreWidespread Exploitation of Recent SSRF Vulnerability in Ivanti VPN Products