The Breach News

Meta Issues Warning on FreeType Vulnerability (CVE-2025-27363) Amid Active Exploitation Threats

Meta has issued a critical warning regarding a security vulnerability in the FreeType open-source font rendering library, indicating that it may have been actively exploited in the wild. This vulnerability is cataloged under the CVE identifier CVE-2025-27363 and carries a high severity CVSS score of 8.1. It is characterized as…

Read MoreMeta Issues Warning on FreeType Vulnerability (CVE-2025-27363) Amid Active Exploitation Threats

Ukraine Warns of Potential Massive Cyberattacks by Russia Targeting Critical Infrastructure

In a recent advisory, the Ukrainian government alerted that “massive cyberattacks” are imminent, targeting the critical infrastructure of Ukraine and its allies. The Ministry of Defense’s Main Directorate of Intelligence (GUR) has identified the energy sector as a primary target. The agency indicated that these cyberattacks would likely be designed…

Read MoreUkraine Warns of Potential Massive Cyberattacks by Russia Targeting Critical Infrastructure

Breach Update: Microsoft and Cloudflare Take Down RaccoonO365

Cybercrime, Fraud Management & Cybercrime Colt Services Faces Ongoing Outages; Finland Charges U.S. National in Vastaamo Hack Anviksha More (AnvikshaMore) • September 18, 2025 Image: Shutterstock/ISMG Each week, Information Security Media Group compiles cybersecurity incidents worldwide. Recently, Microsoft dealt a significant blow to RaccoonO365, outages at Colt Technology Services continue,…

Read MoreBreach Update: Microsoft and Cloudflare Take Down RaccoonO365

New Assault on ChatGPT Research Agent Exfiltrates Secrets from Gmail Inboxes

ShadowLeak Vulnerability Exposes Risks in Language Models Recent developments in the cybersecurity landscape have unveiled a significant vulnerability involving prompt injection attacks on large language models (LLMs), spotlighted by the alarming case of ShadowLeak. This method primarily utilizes indirect prompt injections embedded within untrusted documents and emails, enabling malicious actors…

Read MoreNew Assault on ChatGPT Research Agent Exfiltrates Secrets from Gmail Inboxes

Leading VC Firm Alerts Thousands to Potential Data Breach—Here’s How to Protect Yourself

Insight Partners Affected by Ransomware Attack: Over 12,000 Individuals Compromised In a significant cybersecurity incident reported by venture capital firm Insight Partners, approximately 12,657 individuals have been confirmed as victims of a ransomware attack that occurred in October 2024. Insight Partners has begun notifying those affected as part of their…

Read MoreLeading VC Firm Alerts Thousands to Potential Data Breach—Here’s How to Protect Yourself

GitHub Discovers New Vulnerabilities in ruby-saml That Enable Account Takeover Attacks

High-Severity Vulnerabilities Discovered in Ruby-SAML Library, Posing Authentication Risks Two significant security vulnerabilities have been identified in the open-source ruby-saml library, which poses a risk of allowing malicious actors to bypass Security Assertion Markup Language (SAML) authentication protections. The discovered vulnerabilities are classified as CVE-2025-25291 and CVE-2025-25292, carrying a high…

Read MoreGitHub Discovers New Vulnerabilities in ruby-saml That Enable Account Takeover Attacks