The Breach News

Malicious Python Package Conceals Sliver C2 Framework Within Counterfeit Requests Library Logo

Malicious Python Package Discovered Concealing Golang Command-and-Control Framework Cybersecurity researchers have unveiled a nefarious Python package masquerading as an extension of the widely-used requests library. This malicious package, named requests-darwin-lite, has been found to hide a Golang variant of the Sliver command-and-control (C2) framework within an image file of the…

Read MoreMalicious Python Package Conceals Sliver C2 Framework Within Counterfeit Requests Library Logo

The 2024 Browser Security Report Reveals the Hidden Dangers of Every Web Session

As the browser becomes the dominant workspace in enterprises, it is increasingly exploited by cybercriminals as a key attack vector. Various threats ranging from account takeovers and phishing attacks to malicious browser extensions highlight the browser’s role in compromising sensitive data and breaching organizational systems. Security professionals tasked with developing…

Read MoreThe 2024 Browser Security Report Reveals the Hidden Dangers of Every Web Session

Fidelity Investments Data Breach Exposes Personal Information of Over 77,000 Customers

Fidelity Investments has reported a significant data breach affecting the personal information of over 77,000 customers. The breach involved unauthorized access to sensitive data, including Social Security numbers and driver’s licenses, although no Fidelity accounts were compromised. The incident is concerning, given that Fidelity is one of the world’s largest…

Read MoreFidelity Investments Data Breach Exposes Personal Information of Over 77,000 Customers

New Zero-Day Vulnerability in Apache OFBiz ERP Enables Remote Code Execution

The cybersecurity landscape is facing significant concern as a recently disclosed zero-day vulnerability in the Apache OFBiz open-source enterprise resource planning (ERP) system poses severe risks to its users. This vulnerability, categorized as CVE-2024-38856, has been assigned a critical CVSS score of 9.8 out of a possible 10. It predominantly…

Read MoreNew Zero-Day Vulnerability in Apache OFBiz ERP Enables Remote Code Execution

Three U.S. Banks Expose Personal and Account Information of Hundreds of Customers Due to Data Breaches

Three U.S. Banks Alert Customers to Data Breaches of Sensitive Information Recent advisories from three major U.S. banks have revealed that sensitive personally identifiable information (PII) of customers has been compromised. Citizens Bank, Truist Bank, and First National Bank have all reported incidents that underscore the ongoing threat posed by…

Read MoreThree U.S. Banks Expose Personal and Account Information of Hundreds of Customers Due to Data Breaches

Google Addresses Newly Discovered Android Kernel Vulnerability Actively Being Exploited

Google has recently mitigated a significant security vulnerability within the Android kernel, a flaw that is reportedly being actively exploited. The vulnerability, designated as CVE-2024-36971, has serious implications, allowing for remote code execution within the kernel. In its August 2024 Android security bulletin, Google indicated that this vulnerability might be…

Read MoreGoogle Addresses Newly Discovered Android Kernel Vulnerability Actively Being Exploited

Microsoft Addresses 61 Vulnerabilities, Including Two Actively Exploited Zero-Day Threats

Microsoft Addresses 61 Security Vulnerabilities in May Patch Update In its latest Patch Tuesday update for May 2024, Microsoft has resolved 61 newly identified security vulnerabilities across its software products, amongst them two zero-day flaws that have been actively exploited in the wild. These updates follow a proactive security strategy…

Read MoreMicrosoft Addresses 61 Vulnerabilities, Including Two Actively Exploited Zero-Day Threats

Marriott’s $52 Million Data Breach Settlement Highlights a Rising Trend – Law.com

Marriott’s $52 Million Data Breach Settlement Highlights Growing Concerns in Cybersecurity In a significant development in the realm of cybersecurity, Marriott International has agreed to a $52 million settlement stemming from a data breach that exposed sensitive information of millions of customers. This settlement underscores a troubling trend as organizations…

Read MoreMarriott’s $52 Million Data Breach Settlement Highlights a Rising Trend – Law.com