The Breach News

Urgent Alert: Active Exploitation of Three Critical Vulnerabilities in Ivanti CSA

Ivanti Identifies Active Exploitation of New Vulnerabilities in Cloud Service Appliance Ivanti has issued an alert regarding three newly discovered security vulnerabilities in its Cloud Service Appliance (CSA), which are currently being actively exploited by attackers. These vulnerabilities add to the growing concerns over the security of this essential service,…

Read MoreUrgent Alert: Active Exploitation of Three Critical Vulnerabilities in Ivanti CSA

Legal Services Firm Requests Government Investigation into Star Health Data Breach, ET CISO

On October 15, 2024, the Software Freedom Law Centre India (SFLCI), a legal services organization based in New Delhi, formally requested the Indian Computer Emergency Response Team (CERT-In) to investigate a significant cybersecurity incident. This incident concerns a severe data breach affecting Star Health and Allied Insurance, one of the…

Read MoreLegal Services Firm Requests Government Investigation into Star Health Data Breach, ET CISO

Serious Docker Engine Vulnerability Enables Attackers to Circumvent Authorization Plugins

Docker Warns of Critical Flaw in Docker Engine Docker has issued an urgent alert regarding a significant vulnerability affecting various versions of the Docker Engine. This flaw could allow attackers to bypass authorization plugins (AuthZ) under certain conditions, posing a serious security risk for users. Labeled as CVE-2024-41110, this bypass…

Read MoreSerious Docker Engine Vulnerability Enables Attackers to Circumvent Authorization Plugins

Hackers Taking Advantage of WP-Automatic Plugin Vulnerability to Establish Admin Accounts on WordPress Sites

WP Automatic Plugin Targeted by Attackers Exploiting Critical Security Flaw Recent reports indicate that threat actors are actively trying to exploit a severe vulnerability in the ValvePress Automatic plugin for WordPress, which has the potential to enable site takeovers. The vulnerability, identified as CVE-2024-27956, has a CVSS score of 9.9,…

Read MoreHackers Taking Advantage of WP-Automatic Plugin Vulnerability to Establish Admin Accounts on WordPress Sites

Central Tickets Acknowledges Data Breach After Hacker Exposes Information of 1 Million Users

Central Tickets Suffers Major Data Breach, Exposing User Information In July 2024, Central Tickets, a London-based platform specializing in discounted theatre tickets, encountered a significant data breach that compromised a broad spectrum of personal information for its users. The breach began on July 1, but Central Tickets remained unaware of…

Read MoreCentral Tickets Acknowledges Data Breach After Hacker Exposes Information of 1 Million Users

Trending Google Headlines on Ransomware News

Sophos Survey Exposes Disturbing Trends in Ransomware Strategies A comprehensive report from Sophos, titled “Turning the Screws: The Pressure Tactics of Ransomware Gangs,” uncovers alarming trends in ransomware operations. The study indicates a disturbing shift from traditional ransomware methods—merely stealing and encrypting data for ransom—to a more aggressive approach designed…

Read MoreTrending Google Headlines on Ransomware News

Server Misconfiguration at Fuel Industry Software Provider Leaks SSNs and Personal Information

Major Data Exposure Due to Server Misconfiguration at FleetPanda A significant server misconfiguration has led to the exposure of almost one million documents belonging to FleetPanda, a noted software provider in the petroleum and fuel industry. This incident has potentially compromised a wide array of sensitive information, including invoices, driver…

Read MoreServer Misconfiguration at Fuel Industry Software Provider Leaks SSNs and Personal Information

South Yorkshire Police Confirms Loss of Three Years’ Worth of Body Camera Footage from Officers

South Yorkshire Police Faces Data Loss After Three Years of Body Cam Footage Deleted In a significant incident that raises serious concerns about data management within law enforcement, South Yorkshire Police (SYP) has publicly apologized for the deletion of over three years’ worth of officer body cam footage from its…

Read MoreSouth Yorkshire Police Confirms Loss of Three Years’ Worth of Body Camera Footage from Officers

Interested in Mastering Cybersecurity Risk Management? Join Our Georgetown University Webinar on October 23!

To Achieve Excellence in Cybersecurity Risk Management: Georgetown University Webinar Announcement Georgetown University is hosting an informative webinar on October 23, aimed at professionals seeking to enhance their knowledge and expertise in cybersecurity risk management. This event highlights the value of pursuing a master’s degree in this critical field, emphasizing…

Read MoreInterested in Mastering Cybersecurity Risk Management? Join Our Georgetown University Webinar on October 23!