BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjr0033hnu2mp7uj2bj

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports betting. Check Point Research said it has tracked the campaign since mid-2025. The modules

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjr0034hnu2kwefmfrc

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise. The incident window ran from approximately August 28 at 20:57

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjr0035hnu2laqsbb6s

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said the campaign's advertisement focused on Spain and reached an estimated 570,950 Meta accounts in the European Union

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e0319hmu2wvjav76u

See’s Candies, Inc.: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 09/02/2026. Date of breach: 04/11/2026. 628 Washington residents affected. Information compromised: Name; Social Security Number; Driver's License or Washington ID Card Number; Full Date of Birth; Passport Number; Medical Information.

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r000ghnu2ush9fpwr

CISA Adds Seven Known Exploited Vulnerabilities to Catalog

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-83548…

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r000fhnu2i781qf79

Communicating Under Pressure: Best Practices for Service Providers

Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors. Outages at one…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjr0036hnu2su570eii

How to Secure Enterprise AI: From Adoption to Incident Readiness

The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of cyber risk. Download the full eBook here. The Business Reality In Sygnia’s 2026 CISO Survey Report, which

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7002nhku2ea7aejzq

Fable 5.1 released, USPS "untested" IT, Exchange hijack vulnerability

Anthropic announces safety changes and new models USPS installs "untested" IT systems for mail-in ballots Thousands of Exchange servers vulnerable to hijacks Get the full show notes here: https://cisoseries.com/cybersecurity-news-fable-5-1-released-usps-untested-it-exchange-hijack-vulnerability/ Huge thanks to our episode sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video call…

KrebsOnSecurity·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1ycq000vhnu2hb42geis

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI)…