The Breach News

Vulnerabilities in Emergency Alert System Could Allow Attackers to Send Fake Messages

The U.S. Department of Homeland Security (DHS) has issued an urgent alert regarding significant security flaws found in Emergency Alert System (EAS) encoder and decoder devices. Such vulnerabilities, if not addressed, may allow malicious entities to generate fake emergency alerts across various broadcasting mediums, including television, radio, and cable networks.…

Read MoreVulnerabilities in Emergency Alert System Could Allow Attackers to Send Fake Messages

Feds Link ‘Scattered Spider’ Pair to $115 Million in Ransom Payments – Krebs on Security

In a significant legal development, U.S. prosecutors recently filed criminal charges against Thalha Jubair, a 19-year-old from the U.K., in connection with his alleged involvement as a central figure in Scattered Spider, a notorious cybercrime organization implicated in extortion schemes totaling over $115 million. These accusations, which emerged as Jubair…

Read MoreFeds Link ‘Scattered Spider’ Pair to $115 Million in Ransom Payments – Krebs on Security

Supermicro Server Motherboards Vulnerable to Permanent Malware Infections

Critical Vulnerabilities Found in Supermicro Motherboards Expose Servers to Exploits Recent security findings have revealed significant vulnerabilities in servers powered by motherboards sold by Supermicro. These high-severity flaws enable attackers to remotely install malicious firmware that operates prior to the system’s operating system, resulting in infections that are challenging to…

Read MoreSupermicro Server Motherboards Vulnerable to Permanent Malware Infections

Aikido Security Acquires Allseek and Haicker: A Major Move in Security Systems News

Aikido Security Expands Reach with Acquisition of Allseek and Haicker Aikido Security has recently announced its acquisition of Allseek and Haicker, two firms known for their advancements in cybersecurity solutions. This move is significant as it positions Aikido to strengthen its offerings in an increasingly competitive landscape. The integration of…

Read MoreAikido Security Acquires Allseek and Haicker: A Major Move in Security Systems News

Cisco Confirms Salt Typhoon’s Exploitation of CVE-2018-0171 to Attack U.S. Telecom Networks

Cisco has disclosed that a Chinese threat actor, identified as Salt Typhoon, successfully infiltrated major U.S. telecommunications companies by exploiting a known vulnerability labeled CVE-2018-0171 and utilizing stolen login credentials. This targeted operation reflects the sophisticated methods employed by adversaries focusing on critical infrastructure. According to Cisco Talos, the group…

Read MoreCisco Confirms Salt Typhoon’s Exploitation of CVE-2018-0171 to Attack U.S. Telecom Networks

Meta Intensifies Efforts Against Cyber Espionage Operations Misusing Facebook in South Asia

Meta Platforms, the parent company of Facebook, has reported the dismantling of two sophisticated cyber-espionage campaigns targeting individuals across South Asia, utilizing its platforms as channels for malware dissemination. The operations, conducted by groups identified as Bitter APT and Transparent Tribe, showcase evolving tactics aimed at exploiting social media for…

Read MoreMeta Intensifies Efforts Against Cyber Espionage Operations Misusing Facebook in South Asia

Secret Service Neutralizes NY Telecom Threat During UN Meeting

Critical Infrastructure Security, Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime U.S. Secret Service Disrupts Network of Telecom Devices Targeting Government Officials Chris Riotta (@chrisriotta) • September 23, 2025 Equipment seized by the U.S. Secret Service prior to the United Nations General Assembly. (Image: U.S. Secret Service) The U.S. Secret…

Read MoreSecret Service Neutralizes NY Telecom Threat During UN Meeting

‘SIM Farms’ Are a Spam Epidemic: Federal Authorities Warn of a Major Threat to US Infrastructure from One in New York.

The recent discovery of a SIM farm operation in New York has highlighted a long-standing issue within the cybercrime landscape. SIM farms, which consist of large collections of SIM cards that can be remotely managed, have been exploited by criminals for various illicit activities, including spam distribution, swatting incidents, and…

Read More‘SIM Farms’ Are a Spam Epidemic: Federal Authorities Warn of a Major Threat to US Infrastructure from One in New York.

Chinese APT Leverages BeyondTrust API Key to Infiltrate U.S. Treasury Systems and Access Sensitive Documents

The U.S. Treasury Department has reported a significant cybersecurity breach that has purportedly provided suspected Chinese threat actors with remote access to some computers and unclassified documents. This incident was publicly disclosed following a communication from BeyondTrust, a third-party software provider of the Treasury, on December 8, 2024, regarding unauthorized…

Read MoreChinese APT Leverages BeyondTrust API Key to Infiltrate U.S. Treasury Systems and Access Sensitive Documents