The Breach News

Russian Hackers Utilize CVE-2025-26633 through MSC EvilTwin to Deploy SilentPrism and DarkWisp

Recent investigations have uncovered that a suspected Russian hacking group known as Water Gamayun, also recognized as EncryptHub or LARVA-208, is exploiting a zero-day vulnerability in Microsoft Windows. This exploitation targets organizations by deploying two new backdoor tools, SilentPrism and DarkWisp, following the patching of a significant security flaw in…

Read MoreRussian Hackers Utilize CVE-2025-26633 through MSC EvilTwin to Deploy SilentPrism and DarkWisp

Cloudflare Confirms Data Breach: Customer Information Compromised Through Salesforce Instances

Cloudflare has publicly acknowledged a security incident involving its Salesforce environment, traced back to the breach of the Salesloft Drift integration. An advanced threat actor, known as GRUB1, exploited OAuth credentials associated with this integration to extract sensitive support case data. While crucial Cloudflare services remained unaffected, the breach did…

Read MoreCloudflare Confirms Data Breach: Customer Information Compromised Through Salesforce Instances

Meta Unveils LlamaFirewall Framework to Prevent AI Jailbreaks, Code Injections, and Security Vulnerabilities

Meta recently introduced LlamaFirewall, a new open-source framework aimed at enhancing the security of artificial intelligence systems. This initiative addresses emerging cyber threats like prompt injection, jailbreaks, and various vulnerabilities that AI technologies face today. The framework is structured around three primary guardrails: PromptGuard 2, Agent Alignment Checks, and CodeShield.…

Read MoreMeta Unveils LlamaFirewall Framework to Prevent AI Jailbreaks, Code Injections, and Security Vulnerabilities

Hydrochasma: New Cyber Threat Targets Shipping Firms and Medical Laboratories in Asia

Recent reports indicate that shipping companies and medical laboratories across Asia have become targets of a sophisticated espionage initiative attributed to a previously unidentified threat actor called Hydrochasma. This activity has been under investigation since October 2022, revealing a pattern of operations that relies solely on readily available public tools…

Read MoreHydrochasma: New Cyber Threat Targets Shipping Firms and Medical Laboratories in Asia

Data Breaches at Specialty Health Organizations Impact Nearly 900,000 Individuals

Data Security Healthcare Providers Suffer Data Breaches Impacting Nearly 900,000 Patients Marianne Kolbasuk McGee (HealthInfoSec) • September 2, 2025 Healthcare suppliers are increasingly targeted by cybercriminals. (Image: Getty Images) Recent cyberattacks have resulted in significant breaches at several specialized healthcare organizations, leading to compromised data for nearly 900,000 individuals. Providers…

Read MoreData Breaches at Specialty Health Organizations Impact Nearly 900,000 Individuals

Nearly 24,000 IPs Target PAN-OS GlobalProtect in Coordinated Login Scanning Attack

Recent reports from cybersecurity researchers indicate a significant increase in login scanning attempts directed at Palo Alto Networks PAN-OS GlobalProtect gateways. An alarming total of nearly 24,000 unique IP addresses have been identified in this activity, raising concerns about the integrity of these critical systems. This surge, which the threat…

Read MoreNearly 24,000 IPs Target PAN-OS GlobalProtect in Coordinated Login Scanning Attack

Watchdog Reports Government Cannot Determine Financial Impact of Afghan Data Breach

The UK’s Ministry of Defence (MoD) is facing scrutiny regarding its secret relocation plan set up in response to a major data leak involving Afghan individuals. The National Audit Office (NAO) has announced that the MoD is unable to accurately determine the total financial impact of this plan, which aims…

Read MoreWatchdog Reports Government Cannot Determine Financial Impact of Afghan Data Breach

SonicWall Acknowledges Ongoing Exploitation of Vulnerabilities Impacting Various Appliance Models

SonicWall Acknowledges Exploitation of Critical Vulnerabilities in SMA100 Series Devices SonicWall has confirmed that two significant vulnerabilities within its SMA100 Secure Mobile Access appliances have been actively exploited. These flaws, recently patched, pose serious risks to organizations utilizing these devices, particularly those in sensitive sectors. The first vulnerability, identified as…

Read MoreSonicWall Acknowledges Ongoing Exploitation of Vulnerabilities Impacting Various Appliance Models