BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r000ahnu2ihm1y2n8

Preparing for the Post-Quantum Era: A Call to Action

CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing threats. The G7 Cyber Security Working Group’s call to action outlines five priorities for a successful transition to PQC: Raising awareness of quantum…

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r0009hnu2d1u87nkb

Rockwell Automation ArmorStart LT

View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page. The following versions of Rockwell Automation ArmorStart LT are affected: ArmorStart LT <=v2.001 (CVE-2026-19471, CVE-2026-19472) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation ArmorStart LT Improper Neutralization of Input During…

Also reported by 1 other source
CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r0008hnu27udtg2pd

Tycon Systems TPDIN-Monitor-WEB3

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684) CVSS Vendor Equipment Vulnerabilities v3 8.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB3 Use of Hard-coded Credentials, Cross-Site…

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r0007hnu27tkzrvu2

Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products (Update A)

View CSAF Summary Schneider Electric is aware of a vulnerability in the following products: The Easergy C5 is a scalable and interoperable bay controller, protection and merging unit for large and critical infrastructure electrical distribution systems. The Easergy MiCOM P30 is a family of multifunction protection and control relays designed for medium, high and extra high voltage electrical networks. The Easergy MiCOM P40 is a protection relay series for Medium Voltage, High Voltage and Extra…

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r0006hnu294wfqtxx

IXON VPN Client

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges. The following versions of IXON VPN Client are affected: VPN Client <1.4.7 (CVE-2026-75925) CVSS Vendor Equipment Vulnerabilities v3 9.6 IXON IXON VPN Client Improper Neutralization of CRLF Sequences ('CRLF Injection') Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy,…

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r0005hnu2px3ut20t

Pyramid Solutions NetStaX EtherNet/IP Stack

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected: EtherNet/IP Adapter DLL Kit (EIPA) EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE) EtherNet/IP Adapter Development Kit (EADK) EtherNet/IP Adapter…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002uhnu2qqzg0pni

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze95015whmu2412o7a7q

Decade-old PostgreSQL flaw turns backup account into a backdoor

A critical vulnerability in PostgreSQL had remained hidden for more than a decade, potentially turning a routine backup account into a path to full database and server compromise. The issue, dubbed PostGREShell by Cyera Research, exists in the database’s replication functionality and could allow an attacker with a low-privilege account carrying the REPLICATION attribute to load and execute arbitrary code. “The flaw lets a low-privilege “backup” account load and execute arbitrary code on the…

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze95015xhmu27ut4z6m1

Counterfeit installers turn routine software downloads into enterprise breaches

Microsoft has warned that attackers are breaching enterprise systems via counterfeit download sites impersonating software including Microsoft Edge, Kaspersky and Razer, delivering trojanized installers for persistent access. “Once executed, the malicious installers deploy malware that establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure,” Microsoft security researchers wrote in a blog post. The campaign, tracked by Microsoft…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002vhnu23eh209lz

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. "The technique's appeal is that node.exe (the

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002whnu22xiimtv1

Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002xhnu2j6rptm26

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said. "We found high-confidence indicators of

Cyber Security Headlines·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7002mhku2vrnylw21

153M licenses for sale, Anthropic reverses course, Astra enters the red zone

Dark web shop stocks 153 million driver's licenses Nexus, a new dark web service, claims it's selling scans of more than 153 million US and Canadian driver's licenses, plus over 10 million ID cards, three million travel and international IDs, and at least 579,000 medical cards. The images appear tied to Louisiana-based IDScan.net, which provides identity verification to retailers, rental-car companies, and others. KrebsOnSecurity matched some records to licenses scanned during Hertz rentals.…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002yhnu2ku9h4892

Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002zhnu2o7nag1nq

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated

Graham Cluley·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl38q700dnhmu2n2409yw4

Smashing Security podcast #483: This AI helps thieves steal your iPhone

You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone. Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees of drama - that their AI agents have "broken out of the sandbox" and gone hacking. James takes a…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq0030hnu2ir8ut4x0

Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq0031hnu2s6rg4vlw

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft

Graham Cluley·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl38q700dohmu2otw9yvqa

Revolut scam wave steals £180,000 from Jersey residents in just four weeks

If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls. Because local police on the largest of the Channel Islands have warned that over a single four-week period, an astonishing 75% of all scam crime reports they have received have involved Revolut accounts Read more in my article on the Hot for Security blog.

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq0032hnu29s1gnqj6

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive