BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002ohnu219uwmu6n

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7002lhku2p051q986

Court records breach, Breeze Comet hits Brazil, Aesto records breach

U.S. and Canadian court records breached in Thomson Reuters incident Cybercrime Breeze Comet causing problems in Brazil Aesto record system hit by data breach Get the full show notes here: https://cisoseries.com/cybersecurity-news-court-records-breach-breeze-comet-hits-brazil-aesto-records-breach/ Huge thanks to our episode sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video…

The Hacker News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002phnu24vd2kvzl

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework. "Astra is state-of-the-art on computer use, browsing, software engineering,

Insecure.Org·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujmtjv05djhmu24bcb7fh4

HP Easy Start for macOS: CVE-2026-12554 / CVE-2026-12555 / CVE-2026-12556

Posted by Nir Yehoshua on Sep 03 Hello Full Disclosure list, Cipher Security Labs has published technical details for three High-severity vulnerabilities affecting HP Easy Start for macOS. The issues were coordinated with HP and are addressed in HP Easy Start 2.16.7.260722 and later under HPSBPI04124. Research title: Rooted in Trust: Breaking HP Easy Start’s macOS Privilege Boundaries Affected product: HP Easy Start for macOS Affected versions: Versions prior to...

Insecure.Org·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujmtjv05dkhmu2xfi1vq2g

Next.js 16.4.0-canary.13 Image Optimizer DNS Rebinding TOCTOU SSRF Still Exists

Posted by Ron E on Sep 03 Next.js 16.4.0-canary.13 contains a DNS rebinding TOCTOU Server-Side Request Forgery vulnerability in the Image Optimizer's fetchExternalImage() functionality. Next.js attempts to prevent requests to private network resources by resolving the supplied hostname and checking the resulting addresses using isPrivateIp(): const records = await lookup(hostname, { family: 0, all: true, hints: ALL, }) const privateIps = records.map((record)...

Insecure.Org·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujmtjv05dlhmu22z7ld2er

O-CMS 1.0.0 Authenticated OS Command Injection via ai_cli_script

Posted by Ron E on Sep 03 Description O-CMS version 1.0.0 contains an authenticated OS command injection vulnerability in the AI CLI configuration functionality. An authenticated attacker with sufficient privileges can supply shell metacharacters and additional commands through the ai_cli_script parameter of /admin/settings/save. When the configured AI provider is subsequently tested through /admin/settings/test-ai, the attacker-controlled CLI value is executed in a...

Insecure.Org·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujmtjv05dmhmu2qrdda0ha

Flextype v1.0.0-alpha.3 CMS registerShortcodes() Remote Code Execution via Attacker-Controlled File Inclusion

Posted by Ron E on Sep 03 Description Flextype CMS contains a remote code execution vulnerability in the interaction between the Entries API and Shortcodes::registerShortcodes(). The /api/v1/entries endpoint accepts an attacker-controlled entry identifier that can contain path traversal sequences, allowing content containing PHP code to be written outside the intended entries directory. The /api/v1/query endpoint subsequently permits an attacker-controlled path to reach...

Insecure.Org·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujmtjv05dnhmu23g76q00m

Flextype v1.0.0-alpha.3 Stored Fetch Shortcode Allows Server-Side Request Forgery

Posted by Ron E on Sep 03 Description Flextype CMS v1.0.0-alpha.3 contains a stored server-side request forgery (SSRF) vulnerability in its shortcode-processing functionality. Attacker-controlled entry fields can be automatically processed by Flextype's shortcode parser. The built-in fetch shortcode accepts an attacker-controlled resource and passes the resulting value to the server-side fetch() helper without sufficient destination restrictions. An attacker...

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze95015vhmu29oobq3x6

OpenAI targets small utilities with $1 billion cyber defense initiative

In a keynote speech during a summit at OpenAI’s headquarters attended by 300 enterprise security leaders and CISOs from Fortune 1000 companies, OpenAI President Greg Brockman announced Daybreak for Frontline Defenders, a new global initiative to help frontline defenders use frontier cyber AI to protect essential services in the United States and around the world. The initiative entails a $1 billion global commitment to expand subsidized access to Daybreak cyber models, training, technical…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002qhnu2nrhu8ift

ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002rhnu2l2v8fcfq

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002shnu22xxa5gp4

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002thnu2eho1y7ed

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e0318hmu2pa8nks5x

The Lighthouse for the Blind, Inc.: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 09/03/2026. Date of breach: 04/09/2026. 520 Washington residents affected. Information compromised: Name; Social Security Number; Driver's License or Washington ID Card Number; Full Date of Birth; Health Insurance Policy or ID Number; Medical Information.

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e0317hmu2b9zet6ot

Virta Health Corp. and Virta Medical, PC (Department of Health And Human Services): data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 09/03/2026. Date of breach: 03/19/2026. 134 Washington residents affected. Information compromised: Name; Social Security Number; Full Date of Birth; Health Insurance Policy or ID Number; Medical Information; Protected Health Information owned or licensed by a HIPAA covered entity.

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e0316hmu2fw9f0z9q

Mogren, Glessner & Ahrens, P.S.: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 09/03/2026. Date of breach: 06/09/2026. 1,379 Washington residents affected. Information compromised: Name; Social Security Number; Financial & Banking Information; Full Date of Birth; Medical Information; Username and Password/Security Question Answers; Email Address and Password/Security Question Answers; Protected Health Information owned or licensed by a HIPAA covered entity.

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r000ehnu22ldxszt1

Rockwell Automation 1756-ENBT Module

View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-ENBT Module Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Critical Manufacturing, Food and Agriculture,…

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r000dhnu2911ki93l

Tycon Systems TPDIN-Monitor-WEB2 (Update A)

View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected: TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985) CVSS Vendor Equipment Vulnerabilities v3 9.8 Tycon Systems Tycon Systems TPDIN-Monitor-WEB2 Missing…

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r000chnu25zbwa3mt

Inductive Automation Ignition

View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition <=8.1.53 (CVE-2026-77393) CVSS Vendor Equipment Vulnerabilities v3 8.8 Inductive Automation Inductive Automation Ignition Incorrect Default Permissions Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Information Technology Countries/Areas Deployed: Worldwide Company…

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r000bhnu2guswiprs

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CVE-2026-77477) CVSS Vendor Equipment Vulnerabilities v3 4.6 OPCFoundation OPCFoundation OPC UA LocalDiscoveryServer (LDS) Execution with Unnecessary Privileges Background Critical Infrastructure…