The Breach News

New Hacker Group ‘GambleForce’ Targets APAC Firms with SQL Injection Attacks

Recent cybersecurity reports have surfaced detailing a series of SQL injection attacks attributed to a newly identified hacker group named GambleForce. This group has predominantly targeted organizations across the Asia-Pacific (APAC) region since September 2023, raising significant concerns regarding the vulnerabilities in web application security practices. According to Group-IB, a…

Read MoreNew Hacker Group ‘GambleForce’ Targets APAC Firms with SQL Injection Attacks

Major Security Vulnerabilities Resolved in Microsoft Dynamics 365 and Power Apps Web API

Recent reports have highlighted three critical security vulnerabilities within the Microsoft Dynamics 365 and Power Apps Web API. These exploits, which could lead to unauthorized data exposure, have been addressed as of May 2024, following detection by Stratus Security, a cybersecurity firm based in Melbourne. The vulnerabilities identified reflect significant…

Read MoreMajor Security Vulnerabilities Resolved in Microsoft Dynamics 365 and Power Apps Web API

Ukraine Remains Under Cyber Espionage Attacks from Russian Hackers

Recent cybersecurity investigations have revealed a series of infiltration attempts by a Russian-affiliated hacking group known as Gamaredon, targeting Ukrainian entities as early as July 2021. Broadcom subsidiary Symantec released findings on Monday highlighting the group’s consistent activity in cyberespionage, a pattern they’ve maintained since at least 2013. Ukrainian intelligence…

Read MoreUkraine Remains Under Cyber Espionage Attacks from Russian Hackers

Emerging KV-Botnet Targets Cisco, DrayTek, and Fortinet Devices for Covert Attacks

A sophisticated botnet identified as the KV-botnet is exploiting vulnerabilities in devices from well-known manufacturers—specifically Cisco, DrayTek, Fortinet, and NETGEAR—to create a covert data transfer network. This network is being utilized by advanced persistent threat (APT) actors, including the China-linked group known as Volt Typhoon. According to Black Lotus Labs…

Read MoreEmerging KV-Botnet Targets Cisco, DrayTek, and Fortinet Devices for Covert Attacks

New AI Jailbreak Technique ‘Bad Likert Judge’ Increases Attack Success Rates by More Than 60%

Emerging Jailbreak Technique Poses New Threats to Language Models Cybersecurity research has recently unveiled a new jailbreak technique that undermines the safety mechanisms of large language models (LLMs), potentially enabling the generation of harmful or malicious content. This multi-turn attack strategy, termed “Bad Likert Judge,” has been revealed by researchers…

Read MoreNew AI Jailbreak Technique ‘Bad Likert Judge’ Increases Attack Success Rates by More Than 60%