The Breach News

Online Code Exploits LogoFAIL to Install Bootkitty Linux Backdoor

A recent vulnerability has been identified that targets Secure Boot protocols in certain Linux machines using UEFI firmware developed by Insyde. This exploit, known as LogoFAIL, allows attackers to bypass Secure Boot—an essential security feature designed to ensure that only trusted firmware and software are executed during the boot process.…

Read MoreOnline Code Exploits LogoFAIL to Install Bootkitty Linux Backdoor

EU Nations Failing to Meet NIS2 Deadline Given Warning

Critical Infrastructure Security, Government, Industry Specific European Commission Initiates Legal Proceedings Against 23 EU Nations Akshaya Asokan ( asokan_akshaya) • November 29, 2024 Image: Shutterstock The European Commission has launched infringement procedures against over 20 member states due to their failure to enact two pivotal cyber regulations aimed at enhancing…

Read MoreEU Nations Failing to Meet NIS2 Deadline Given Warning

Ensuring Election Integrity in the Era of Artificial Intelligence

Certainly! Here is the rewritten article based on the given content, tailored for a tech-savvy professional audience concerned about cybersecurity risks: — With the rapid advancement and increasing accessibility of artificial intelligence, there are growing concerns about its potential to disrupt the democratic process, particularly in the context of the…

Read MoreEnsuring Election Integrity in the Era of Artificial Intelligence

Issues with Advantech Industrial Wireless Access Points

Critical Vulnerabilities Discovered in Advantech Wireless Access Points Pose Serious Security Risks Recent research has uncovered 20 significant vulnerabilities in Advantech’s EKI-6333AC-2G industrial-grade wireless access points, equipment widely utilized in critical infrastructure sectors. The discovered flaws could enable attackers to execute remote code and initiate denial-of-service attacks, raising alarms about…

Read MoreIssues with Advantech Industrial Wireless Access Points

Dohman, Akerlund & Eddy Reports Data Breach Impacting Nearly 10,000 Individuals

Dohman, Akerlund & Eddy, a tax, accounting, and business consulting firm located in Aurora, Nebraska, has disclosed a significant data breach that has compromised the protected health information (PHI) of nearly 10,000 individuals. This incident highlights the growing concern over the security of sensitive data held by service firms, raising…

Read MoreDohman, Akerlund & Eddy Reports Data Breach Impacting Nearly 10,000 Individuals

Ransomware Propagating via Microsoft Teams

In a troubling development, the Black Basta ransomware group has emerged again, utilizing a sophisticated new strategy to distribute file-encrypting malware via Microsoft Teams—a platform widely utilized for workplace communication and collaboration. This evolving tactic highlights a shift for Black Basta, which has predominantly targeted sectors like technology, finance, and…

Read MoreRansomware Propagating via Microsoft Teams

Judge Rejects Changes to ‘Dealer Rule’

Blockchain & Cryptocurrency, Cryptocurrency Fraud, Cybercrime Additionally: Python Library Update Compromises Credentials; Drug Cartels Launder Profits Through Tether Rashmi Ramesh (rashmiramesh_) • November 28, 2024 Criticism from crypto firms has been directed at the U.S. Securities and Exchange Commission’s vague expanded definition of “dealer.” (Image: Shutterstock) This week, ISMG compiled…

Read MoreJudge Rejects Changes to ‘Dealer Rule’