The Breach News

Vulnerability in WordPress Plugin Exposes 4 Million Sites to Threats

Identity & Access Management, Security Operations Significant Authentication Vulnerability Affects Millions of WordPress Users Prajeet Nair (@prajeetspeaks) • November 18, 2024 Image: Shutterstock A critical security flaw has been discovered in a popular five-in-one security plugin for WordPress, putting over 4 million sites at risk of automated hacking attacks. The…

Read MoreVulnerability in WordPress Plugin Exposes 4 Million Sites to Threats

German Court Rules Facebook Users Impacted by Data Breach Can Claim Compensation, ET CISO

German Court Rules on User Data Compensation from Meta Following 2018-2019 Breach In a significant legal development, a German court ruled on Monday that Facebook users whose data was improperly accessed between 2018 and 2019 are entitled to compensation. The Federal Court of Justice (BGH) in Germany has established that…

Read MoreGerman Court Rules Facebook Users Impacted by Data Breach Can Claim Compensation, ET CISO

Entrust, Jumio, and Sumsub at the Forefront of Identity Verification in Gartner’s Magic Quadrant

Gartner Unveils First Magic Quadrant for Identity Verification as Demand Grows Amid Evolving Threats Gartner recently released its inaugural Magic Quadrant report specifically focused on identity verification (IDV), highlighting a notable shift in its use as burgeoning workforce-related use cases arise. Traditionally, identity verification served regulated sectors such as banking…

Read MoreEntrust, Jumio, and Sumsub at the Forefront of Identity Verification in Gartner’s Magic Quadrant

US Government Agencies Targeted in Bold DocuSign Phishing Scams

Surge in DocuSign Phishing Scams Targets U.S. Citizens and Government Agencies Recent cybersecurity reports reveal a significant uptick in phishing scams utilizing DocuSign, demonstrating a staggering 98% increase in malicious URLs between November 8 and November 14, compared to September and October combined. SlashNext, a cybersecurity threat research team, has…

Read MoreUS Government Agencies Targeted in Bold DocuSign Phishing Scams

ICO Fines PSNI £750,000 for Unprecedented Data Breach Affecting T

The Information Commissioner’s Office (ICO) recently levied a record £750,000 fine against the Police Service of Northern Ireland (PSNI) for what has been termed the “most significant data breach in the history of UK policing.” This unprecedented penalty followed the inadvertent disclosure of an Excel spreadsheet that contained the personal…

Read MoreICO Fines PSNI £750,000 for Unprecedented Data Breach Affecting T

Chinese Salt Typhoon Targets T-Mobile in US Telecom Breach Wave

T-Mobile Breached Again: Cybersecurity Risks Amplified by Salt Typhoon Attack In a concerning development for the telecommunications sector, T-Mobile has been targeted by a cyberespionage campaign orchestrated by the Chinese state-sponsored hacking group known as Salt Typhoon. This breach underscores significant vulnerabilities within telecom infrastructure and highlights the ongoing struggle…

Read MoreChinese Salt Typhoon Targets T-Mobile in US Telecom Breach Wave

Phishing Scheme Takes Advantage of Fake Trump Assassination Narrative to Steal Corporate Data

The cybersecurity landscape is witnessing a new wave of phishing attacks leveraging global events to target unsuspecting users. According to experts from ESET, a recent campaign is exploiting a fabricated assassination plot against former President Donald Trump to deceive individuals into revealing personal and corporate information. This tactic is particularly…

Read MorePhishing Scheme Takes Advantage of Fake Trump Assassination Narrative to Steal Corporate Data