The Breach News

Researchers Raise Concerns About Flaws in Commonly Used Industrial Gas Analysis Tools

Security Vulnerabilities in Emerson Rosemount Gas Chromatographs Exposed Recent findings have revealed multiple security vulnerabilities in Emerson Rosemount gas chromatographs, specifically the GC370XA, GC700XA, and GC1500XA models. These vulnerabilities could potentially be exploited by malicious actors to gain unauthorized access to sensitive information, disrupt services leading to denial-of-service (DoS) conditions,…

Read MoreResearchers Raise Concerns About Flaws in Commonly Used Industrial Gas Analysis Tools

Hackers Target Ivanti VPN Vulnerabilities to Distribute KrustyLoader Malware

Recently reported zero-day vulnerabilities in Ivanti Connect Secure (ICS) virtual private network (VPN) devices have been actively exploited to deploy a Rust-based payload known as KrustyLoader. This malicious software component is specifically designed to install the open-source Sliver adversary simulation tool, which has gained traction among threat actors. The security…

Read MoreHackers Target Ivanti VPN Vulnerabilities to Distribute KrustyLoader Malware

FortiGate Administrators Report Active Exploitation of 0-Day Vulnerability, Vendor Remains Silent.

Fortinet, a prominent provider of network security solutions, has recently come under scrutiny for concealing a significant vulnerability that has reportedly been exploited by attackers to execute unauthorized code on servers belonging to sensitive organizations. This silence persisted for over a week, raising concerns among users and cybersecurity experts alike…

Read MoreFortiGate Administrators Report Active Exploitation of 0-Day Vulnerability, Vendor Remains Silent.

Dental Center Chain Resolves Data Breach Lawsuit with $2.7 Million Settlement

2023 Cybersecurity Breach Impacts 1.9 Million Individuals at Great Expressions Dental Centers In a significant cybersecurity incident, Great Expressions Dental Centers, a Michigan-based dental organization operating 250 locations across nine states, has reached a preliminary settlement of $2.7 million over a hacking event that compromised the personal data of more…

Read MoreDental Center Chain Resolves Data Breach Lawsuit with $2.7 Million Settlement

Equifax Data Breach: Over 30 Lawsuits Filed Across the U.S. Following Massive Hack

Equifax Faces Wave of Lawsuits Following Major Data Breach Exposing Personal Information of Millions Equifax, one of the largest credit reporting agencies in the United States, is facing over 30 lawsuits in the wake of a significant data breach that exposed personal information belonging to approximately 143 million Americans. This…

Read MoreEquifax Data Breach: Over 30 Lawsuits Filed Across the U.S. Following Massive Hack

New “ALBeast” Misconfiguration Reveals Vulnerabilities in AWS Application Load Balancer

Recent investigations have uncovered a significant cybersecurity vulnerability affecting approximately 15,000 applications that utilize Amazon Web Services’ (AWS) Application Load Balancer (ALB) for authentication purposes. This configuration issue could enable malicious actors to bypass access controls, thereby compromising the security of these applications. The research, conducted by the Israeli cybersecurity…

Read MoreNew “ALBeast” Misconfiguration Reveals Vulnerabilities in AWS Application Load Balancer

Great Expressions Dental Centers Reaches $2.7 Million Settlement in Data Breach Lawsuit – HIPAA Journal

Great Expressions Dental Centers has reached a settlement in a data breach lawsuit that totaled $2.7 million, underscoring the serious implications of cybersecurity inadequacies within the healthcare sector. The lawsuit initiated following a breach that exposed sensitive personal and medical information, highlighting vulnerabilities that can jeopardize patient trust and compliance…

Read MoreGreat Expressions Dental Centers Reaches $2.7 Million Settlement in Data Breach Lawsuit – HIPAA Journal

GitLab Issues Patch for Critical CI/CD Pipeline Vulnerability Alongside 13 Additional Fixes

GitLab Security Updates Address Critical Vulnerabilities in CI/CD Pipelines GitLab has announced a series of security updates aimed at rectifying 14 identified vulnerabilities within its software, including a severe flaw that poses a significant risk to its continuous integration and deployment (CI/CD) pipelines. The updates, which target both the GitLab…

Read MoreGitLab Issues Patch for Critical CI/CD Pipeline Vulnerability Alongside 13 Additional Fixes

U.S. Federal Authorities Disable China-Linked “KV-Botnet” Aimed at SOHO Routers

The U.S. government announced on Wednesday that it has taken significant action to disrupt a botnet composed of hundreds of small office and home office (SOHO) routers based in the United States. This botnet, referred to as the KV-botnet, is linked to Volt Typhoon, a state-sponsored threat actor associated with…

Read MoreU.S. Federal Authorities Disable China-Linked “KV-Botnet” Aimed at SOHO Routers