The Breach News

Intel Broker Alleges Cisco Data Breach, Peddling Stolen Information from Leading Companies

Major Data Breach Allegedly Targets Cisco Systems: Intel Broker Claims Responsibility Intel Broker, a notorious figure in the realm of cybercrime, has asserted that he successfully breached Cisco Systems, Inc., resulting in the theft of a significant trove of sensitive data, including source codes, confidential documents, and various credentials. The…

Read MoreIntel Broker Alleges Cisco Data Breach, Peddling Stolen Information from Leading Companies

Researchers Uncover ConfusedFunction Vulnerability in Google Cloud Platform

Critical Vulnerability Discovered in Google Cloud Platform’s Cloud Functions Service Cybersecurity experts have identified a significant privilege escalation vulnerability impacting the Cloud Functions service offered by Google Cloud Platform (GCP). Dubbed "ConfusedFunction" by Tenable, this vulnerability may allow malicious actors to access other services and sensitive information without authorization. The…

Read MoreResearchers Uncover ConfusedFunction Vulnerability in Google Cloud Platform

New U.K. Legislation Prohibits Default Passwords on Smart Devices Beginning April 2024

The U.K. National Cyber Security Centre (NCSC) is urging smart device manufacturers to align with new regulatory measures set to take effect on April 29, 2024. These regulations prohibit the use of default passwords, marking a significant shift toward enhancing cybersecurity for Internet of Things (IoT) devices. The legislation, known…

Read MoreNew U.K. Legislation Prohibits Default Passwords on Smart Devices Beginning April 2024

AI Chatbots Can Decode Invisible Text That Humans Can’t: Here’s How.

In a significant development within the realm of Unicode and character encoding, an overlooked block initially intended for country representation has come to light due to recent findings by cybersecurity researcher Riley Goodside. The plan to repurpose this block for designating country codes—using tags like “us” for the United States…

Read MoreAI Chatbots Can Decode Invisible Text That Humans Can’t: Here’s How.

Councils, Solicitors, NHS, and Police Criticized for Disclosing Personal Information of Domestic Abuse Victims

A coalition of councils, solicitors, an NHS trust, and law enforcement agencies in the UK has faced significant backlash for disclosing sensitive personal information of domestic abuse victims. The UK Information Commissioner’s Office (ICO) has issued stern warnings, indicating that these data breaches severely endanger the lives of victims, with…

Read MoreCouncils, Solicitors, NHS, and Police Criticized for Disclosing Personal Information of Domestic Abuse Victims

Cybercriminals Employ Unicode to Conceal Mongolian Skimmer in Online Retail Sites

New Cyber Threat: Mongolian Skimmer Campaign Revealed Cybersecurity experts have recently uncovered a sophisticated digital skimmer campaign utilizing Unicode obfuscation techniques to deploy a skimmer known as “Mongolian Skimmer.” Researchers from Jscrambler noted that the obfuscated nature of the script raises eyebrows due to the extensive use of accented characters,…

Read MoreCybercriminals Employ Unicode to Conceal Mongolian Skimmer in Online Retail Sites

Government Data Compromised Twice by ‘Rogue Employees’ Within Six Months — Capital Brief

In the first half of this year, Australian government agencies encountered two significant data breaches attributed to “rogue employees or insider threats.” This alarming trend coincides with a broader surge in data breaches across Australia, which have reached a three-and-a-half-year peak. These incidents raise critical concerns about the integrity and…

Read MoreGovernment Data Compromised Twice by ‘Rogue Employees’ Within Six Months — Capital Brief

Vulnerabilities in Telerik Report Server Could Enable Remote Code Execution

Critical Security Flaw in Telerik Report Server Requires Immediate Updates Progress Software has issued a strong recommendation for users to promptly update their Telerik Report Server instances due to a newly discovered critical security vulnerability that poses a significant risk of remote code execution. This flaw, designated as CVE-2024-6327, has…

Read MoreVulnerabilities in Telerik Report Server Could Enable Remote Code Execution