// DATA BREACHES

// ВИТОКИ ДАНИХ

9 articles
All Zero-Day Ransomware Phishing Supply Chain AI Security Data Breaches Malware Vulnerabilities Attacks Security
Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware

Microsoft disclosed an active malware campaign targeting developers through fake Next.js job repositories designed to deliver in-memory malware. The coordinated attack uses job-themed lures to trick developers into executing malicious code, establishing persistent access to compromised systems.

Claude Code Flaws Exposed Developer Devices to Silent Hacking

Anthropic patched vulnerabilities in Claude Code that could expose developer devices to silent hacking attacks. Security researchers at Check Point demonstrated the impact by creating malicious configuration files that exploited these flaws.

Google Disrupts UNC2814 GRIDTIDE Campaign After 53 Breaches Across 42 Countries

Google disrupted UNC2814 (GRIDTIDE), a China-linked cyber espionage group that breached at least 53 organizations across 42 countries, primarily targeting governments and telecommunications companies globally. This represents an actual active malware campaign with real victims across multiple sectors and regions.

Medical device maker UFP Technologies warns of data stolen in cyberattack

UFP Technologies, a medical device manufacturer, disclosed a cyberattack that compromised its IT systems and data. This is an actual security incident involving a real organization and confirmed data theft, making it a legitimate breach disclosure.

Chinese cyberspies breached dozens of telecom firms, govt agencies

Google's Threat Intelligence Group, Mandiant, and partners disrupted a confirmed espionage campaign attributed to a Chinese threat actor that targeted dozens of telecom firms and government agencies. The attackers used SaaS API calls to conceal malicious traffic in their operations against these organizations.

PayPal Data Breach Led to Fraudulent Transactions

PayPal experienced a data breach caused by an application error that exposed customer personal information for approximately 6 months, resulting in fraudulent transactions. This represents an actual security incident affecting real victims with confirmed impact.

ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT Malware

Cybersecurity researchers discovered an active ClickFix campaign that exploits compromised legitimate websites to distribute a previously undocumented RAT malware called MIMICRAT. The campaign demonstrates sophisticated operations using multi-stage delivery across compromised sites in various industries and geographic regions.

Data breach at French bank registry impacts 1.2 million accounts

A cybersecurity incident at a French bank registry has compromised 1.2 million accounts, as confirmed by the French Ministry of Finance. This represents an actual data breach affecting a significant number of victims at a financial institution.

PayPal discloses data breach that exposed user info for 6 months

PayPal disclosed an actual data breach where a software error in their loan application exposed sensitive user information including Social Security numbers for approximately 6 months. This is a confirmed security incident affecting real victims with documented exposure of personal data.