The Breach News

NetApp SnapCenter Vulnerability May Allow Remote Admin Access for Users on Plug-In Systems

NetApp SnapCenter has revealed a significant security vulnerability that poses a considerable risk of privilege escalation if exploited. SnapCenter is an enterprise-grade solution employed for the management of data protection across various applications, databases, virtual machines, and file systems. It provides functionalities for backing up, restoring, and cloning data resources,…

Read MoreNetApp SnapCenter Vulnerability May Allow Remote Admin Access for Users on Plug-In Systems

Finnish Vastaamo Hacker Released While Contesting Conviction

Cybercrime, Fraud Management & Cybercrime Vastaamo Hacker Aleksanteri Kivimäki Released While Awaiting Appeal Akshaya Asokan (asokan_akshaya) • September 12, 2025 Aleksanteri Kivimäki in a Finnish courtroom on February 28, 2023 A Helsinki court has ordered the release of one of Finland’s most infamous hackers, Aleksanteri Tomminpoika Kivimäki, pending the outcome…

Read MoreFinnish Vastaamo Hacker Released While Contesting Conviction

Edelson Lechtzin LLP Launches Investigation into Data Breach Claims

Fairmont Federal Credit Union Faces Data Breach Investigation by Edelson Lechtzin LLP FAIRMONT, W.Va., September 12, 2025 — Edelson Lechtzin LLP, a prominent national class-action law firm based in suburban Philadelphia, is currently investigating reported data privacy violations stemming from a breach at Fairmont Federal Credit Union (FFCU). The credit…

Read MoreEdelson Lechtzin LLP Launches Investigation into Data Breach Claims

CISA Issues Warning on Sitecore RCE Vulnerabilities; Active Exploits Target Next.js and DrayTek Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has officially incorporated two significant six-year-old vulnerabilities affecting the Sitecore Content Management System and Experience Platform into its Known Exploited Vulnerabilities (KEV) catalog. This addition follows credible evidence indicating that these flaws are being actively targeted by malicious actors. The first vulnerability,…

Read MoreCISA Issues Warning on Sitecore RCE Vulnerabilities; Active Exploits Target Next.js and DrayTek Devices

Zerobot Botnet Surges as a Rising Threat with Enhanced Exploits and Features

The Zerobot DDoS botnet has undergone significant updates, enhancing its capacity to target a broader range of internet-connected devices and expand its network. Microsoft Threat Intelligence Center (MSTIC) is closely monitoring this evolving threat, referring to it as DEV-1061, which encompasses unidentified, emerging, or developing activity clusters. First reported by…

Read MoreZerobot Botnet Surges as a Rising Threat with Enhanced Exploits and Features

LAPSUS$ Hunters Announce Shutdown

Cybercrime, Fraud Management & Cybercrime, Social Engineering Skepticism Surrounds Announcement from Cybercriminal Group Akshaya Asokan • September 12, 2025 Image: Shutterstock A group of teenage hackers, known for targeting airlines, insurance firms, and casinos in both the United Kingdom and United States, has announced the cessation of their activities. Their…

Read MoreLAPSUS$ Hunters Announce Shutdown

⚡ THN Weekly Recap: Updates on Zero-Day Exploits, AI Security Breaches, and Cryptocurrency Theft

This week brought a significant cybersecurity incident involving a 23-year-old Serbian activist whose Android device fell prey to a sophisticated zero-day exploit. Developed by Cellebrite, this exploit chain compromised the user’s phone, likely enabling the deployment of a spyware solution known as NoviSpy. The vulnerabilities, which exploit weaknesses in the…

Read More⚡ THN Weekly Recap: Updates on Zero-Day Exploits, AI Security Breaches, and Cryptocurrency Theft