BreachFeed

Know the moment the organizations you depend on are breached

BreachFeed watches security news, breach disclosures, and government advisories around the clock. Track companies and keywords, and get alerted your way — email, SMS, or push.

Spotlight

Latest incidents & advisories

live feed
The Hacker News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu856av40zxohmu23uk16zrw

Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote

The Hacker News·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu856av40zxphmu2alw5gkgr

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu832ftj0vdhhmu21xalvxez

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu81lq980scbhmu2qoo0x6if

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path