The Breach News

China-Connected Hackers Breached East Asian Company for Three Years via F5 Devices

A cyber espionage actor with links to China has been identified as the perpetrator behind a sustained attack against an undisclosed organization in East Asia, an intrusion that has reportedly spanned approximately three years. This threat actor took advantage of legacy F5 BIG-IP appliances within the target’s infrastructure, using them…

Read MoreChina-Connected Hackers Breached East Asian Company for Three Years via F5 Devices

Mustang Panda Hackers Target Philippine Government Amid Rising South China Sea Tensions

Recent reports reveal that the Mustang Panda hacking group, linked to China, has executed a cyberattack aimed at a government entity in the Philippines. This incident occurs amidst escalating tensions between the Philippines and China concerning territorial disputes in the South China Sea, highlighting the geopolitical implications of cybersecurity in…

Read MoreMustang Panda Hackers Target Philippine Government Amid Rising South China Sea Tensions

Detecting, Preventing, and Notifying About Data Breaches

Please complete the following fields: Select CountryUnited StatesCanadaIndiaAfghanistanAlbaniaAlgeriaAmerican SamoaAndorraAngolaAnguillaAntigua & BarbudaArgentinaArmeniaArubaAustraliaAustriaAzerbaijanBahamasBahrainBangladeshBarbadosBelarusBelgiumBelizeBeninBermudaBhutanBoliviaBosnia & HerzegovinaBotswanaBrazilBritish Virgin IslandsBruneiBulgariaBurkina FasoBurundiCambodiaCameroonCape VerdeCayman IslandsCentral African RepublicChadChileChinaColombiaComorosCook IslandsCosta RicaCôte d’IvoireCroatiaCubaCyprusCzechiaDemocratic Republic of the CongoDenmarkDjiboutiDominicaDominican RepublicEcuadorEgyptEl SalvadorEquatorial GuineaEritreaEstoniaEswatiniEthiopiaFaroe IslandsFijiFinlandFranceFrench GuianaFrench PolynesiaGabonGambiaGeorgiaGermanyGhanaGibraltarGreeceGreenlandGrenadaGuadeloupeGuamGuatemalaGuineaGuinea-BissauGuyanaHaitiHondurasHong KongHungaryIcelandIndonesiaIranIraqIrelandIsraelItalyJamaicaJapanJordanKazakhstanKenyaKiribatiKosovoKuwaitKyrgyzstanLaosLatviaLebanonLesothoLiberiaLibyaLiechtensteinLithuaniaLuxembourgMacaoMadagascarMalawiMalaysiaMaldivesMaliMaltaMarshall IslandsMartiniqueMauritaniaMauritiusMayotteMexicoMicronesiaMoldovaMonacoMongoliaMontserratMoroccoMozambiqueMyanmar (Burma)NamibiaNauruNepalNetherlandsNew CaledoniaNew ZealandNicaraguaNigerNigeriaNiueNorth MacedoniaNorthern Mariana IslandsNorwayOmanPakistanPalauPanamaPapua New GuineaParaguayPeruPhilippinesPolandPortugalPuerto RicoQatarRomaniaRussiaRwandaSamoaSan MarinoSão Tomé & PríncipeSaudi ArabiaSenegalSerbiaSeychellesSierra LeoneSingaporeSlovakiaSloveniaSolomon…

Read MoreDetecting, Preventing, and Notifying About Data Breaches

Cybersecurity Updates: Data Breaches, Vulnerabilities, and Threats

This week’s Cybersecurity Newsletter provides crucial updates and insights into the ever-changing landscape of cybersecurity threats. Business owners and professionals are encouraged to stay informed about the latest developments that could impact their organizations’ security posture. The digital world continues to evolve, introducing new threats and innovative strategies from adversaries.…

Read MoreCybersecurity Updates: Data Breaches, Vulnerabilities, and Threats

ASUS Addresses Serious Authentication Bypass Vulnerability in Various Router Models

ASUS has recently deployed critical software updates aimed at rectifying a significant security vulnerability that affects its routers. This flaw poses a serious risk as it could potentially allow malicious actors to bypass authentication protocols, thereby gaining unauthorized access to devices. The vulnerability, identified as CVE-2024-3080, has been assigned a…

Read MoreASUS Addresses Serious Authentication Bypass Vulnerability in Various Router Models

New ‘HrServ.dll’ Web Shell Identified in APT Attack on Afghan Government

In a significant cybersecurity incident, an unidentified government entity in Afghanistan has fallen victim to a previously unreported web shell identified as HrServ, suggesting links to an advanced persistent threat (APT) attack. The exploit involves a dynamic-link library (DLL) file named "hrserv.dll," which boasts advanced functionalities, including custom encoding for…

Read MoreNew ‘HrServ.dll’ Web Shell Identified in APT Attack on Afghan Government

AT&T Confirms Data Breach Impacting Almost All Wireless Customers

AT&T Data Breach Exposes Wireless Customer Information Recent reports indicate that American telecom giant AT&T has suffered a significant data breach, leading to the unauthorized access of sensitive information pertaining to "nearly all" of its wireless customers. This security incident also affects customers of mobile virtual network operators (MVNOs) that…

Read MoreAT&T Confirms Data Breach Impacting Almost All Wireless Customers

Dental Patients Eligible for One-Time Payments of Up to $6,000 in Data Breach Settlement

In a significant cybersecurity incident, dental patients across the United States may be entitled to substantial compensation, with one-time payments potentially reaching up to $6,000 due to a multi-million dollar settlement resulting from a data breach involving Great Expressions. This prominent dental care network, which operates 246 centers nationwide, faced…

Read MoreDental Patients Eligible for One-Time Payments of Up to $6,000 in Data Breach Settlement

VMware Releases Patches for Cloud Foundation, vCenter Server, and vSphere ESXi

VMware has recently issued critical updates to address significant vulnerabilities affecting its Cloud Foundation, vCenter Server, and vSphere ESXi platforms. These flaws are particularly concerning as they could potentially allow attackers to escalate privileges or execute remote code. The vulnerabilities have been assigned high CVSS scores, underscoring their severity. Among…

Read MoreVMware Releases Patches for Cloud Foundation, vCenter Server, and vSphere ESXi