The Breach News

How Autonomous AI Agents Enhance Insider Threats

Agentic AI, Artificial Intelligence & Machine Learning, Governance & Risk Management Shilpa Sawant Discusses the Internal Risks Posed by Autonomous AI Agents Suparna Goswami (gsuparna) • September 22, 2025 Shilpa Sawant, Vice President, Sumitomo Mitsui Banking Corporation Autonomous artificial intelligence agents are transforming the landscape of insider threats by functioning…

Read MoreHow Autonomous AI Agents Enhance Insider Threats

Stellantis, Parent Company of Jeep and Dodge, Confirms Customer Data Breach

Stellantis Confirms Data Breach Impacting North American Operations Stellantis, the multinational automobile manufacturer responsible for brands such as Jeep, Chrysler, Dodge, and FIAT, has reported a data breach that has compromised its North American customer service operations due to unauthorized access via a third-party provider. In an official statement released…

Read MoreStellantis, Parent Company of Jeep and Dodge, Confirms Customer Data Breach

FunkSec: AI-Powered Ransomware Targets 85 Victims with Double Extortion Tactics

Emergence of AI-Powered Ransomware: FunkSec Targets Global Organizations Cybersecurity researchers have identified a newly formed ransomware group, FunkSec, which has been active since late 2024 and has reportedly victimized over 85 organizations globally. This group employs sophisticated tactics, relying on artificial intelligence to enhance its ransomware operations, which significantly amplifies…

Read MoreFunkSec: AI-Powered Ransomware Targets 85 Victims with Double Extortion Tactics

Customer Names and Emails Compromised

In a troubling development for the automotive sector, Stellantis NV, the global company behind well-known brands such as Jeep, Chrysler, and Fiat, has reported a data breach that has exposed customer information via a third-party service provider. The breach impacted the company’s North American customer service operations, revealing personal data…

Read MoreCustomer Names and Emails Compromised

Hackers Exploit Vulnerability in Krpano Framework to Inject Spam Ads on Over 350 Websites

A significant security vulnerability, identified as a cross-site scripting (XSS) flaw, has been exploited in a widely-used virtual tour framework, allowing cybercriminals to inject harmful scripts into hundreds of websites. This malicious activity aims to manipulate search results and promote spam advertising on a large scale. According to a report…

Read MoreHackers Exploit Vulnerability in Krpano Framework to Inject Spam Ads on Over 350 Websites

Experts Caution About Continued Widespread Exploitation of Zimbra RCE Vulnerability

On Thursday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) reported the addition of two critical vulnerabilities to its Known Exploited Vulnerabilities Catalog, both linked to severe weaknesses within Zimbra Collaboration software. These flaws have shown substantial evidence of active exploitation, posing significant risks to affected email servers. The vulnerabilities…

Read MoreExperts Caution About Continued Widespread Exploitation of Zimbra RCE Vulnerability

ENISA Reports Ransomware Attack Linked to Collins Aerospace Hack

Fraud Management & Cybercrime, Ransomware Service Disruptions Persist at Major European Airports Following Recent Cyberattack Akshaya Asokan (asokan_akshaya) • September 22, 2025 Flight cancellations at Brussels International Airport on May 4, 2010. (Image: Shutterstock) In a significant cyber incident categorized as a ransomware attack, several major European airports, including London…

Read MoreENISA Reports Ransomware Attack Linked to Collins Aerospace Hack

How the Powerful Atomic Credential Stealer is Making Its Way onto Macs

Credential Stealer Targets LastPass Users via Malicious Ads Recent reports have surfaced regarding a cybersecurity threat involving malicious advertisements that impersonate various online services, with a particular focus on users of the LastPass password manager. Security firms have alerted the public about this campaign, which aims to infect Mac computers…

Read MoreHow the Powerful Atomic Credential Stealer is Making Its Way onto Macs

Google OAuth Flaw Exposes Millions Through Unsecured Startup Domains

Recent investigations have unveiled a serious vulnerability within Google’s “Sign in with Google” authentication system, which can be exploited through a peculiar loophole in domain ownership. This flaw potentially allows unauthorized users to access sensitive data associated with former employees of defunct companies. Dylan Ayrey, co-founder and CEO of Truffle…

Read MoreGoogle OAuth Flaw Exposes Millions Through Unsecured Startup Domains