BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002ehnu2tocd6z50

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002fhnu2ds45nlmf

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002ghnu2260x24bi

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002hhnu24bu8rr60

Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002ihnu2zb14ht1x

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7002khku2oc8xztdc

The Department of Know: Astra launches, CISA cuts programs, McKesson breached

Read the full stories at CISOSeries.com This week's Department of Know is hosted by Rich Stroffolino, with guests Montez Fitzpatrick, director, information security, global head of cybersecurity, Energizer Holdings, and Jonathan Waldrop, CISO, Acoustic. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, KnowBe4 Your employees have…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002jhnu2c1orrn1e

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002khnu22qi8ak33

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002lhnu23u6ufk5k

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

CSO Online·Confirmed Breach2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015rhmu2qwq1ppaj

FBI investigates breach of 153 million driving license records at IDscan.net

Drivers in North America received a nasty shock this week when it was revealed that digital scans of 153 million drivers’ licenses were for sale on the dark web. Among the victims were US Defense Secretary Pete Hegseth – and investigative reporter Brian Krebs, who has dug deep into the data breach on his blog KrebsOnSecurity. The driving license details were offered for sale by a user of the Russian cybercrime forum Exploit, KrebsOnSecurity said. In addition to the 153 million driving licenses,…

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015shmu22vpid0k2

Bidding war for defunct Spirit Airlines’ employee data will not die

The destiny of Spirit Airline’s data is still undecided, months after the company sought bankruptcy protection. AI data company Micro1 has now offered $12.5 million to acquire a trove of the company’s emails, Teams chats, operations and employee productivity data, according to a report by aviation website Simply Flying, It said the data includes about 600 million email and chat records generated by 17,000 employees, as well as 17 million OneDrive files, 20.5 million SharePoint items, and more…

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e0314hmu2qr4krpbz

Catalyst Brands LLC: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 09/04/2026. Date of breach: 05/20/2026. 4,015 Washington residents affected. Information compromised: Name; Social Security Number; Driver's License or Washington ID Card Number; Financial & Banking Information; Full Date of Birth; Military ID Number; Passport Number; Email Address and Password/Security Question Answers; Other.

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e0313hmu2svjgwxb4

LHC Group, Inc.: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 09/04/2026. Date of breach: 04/07/2026. 6,602 Washington residents affected. Information compromised: Name; Social Security Number; Financial & Banking Information; Full Date of Birth; Health Insurance Policy or ID Number; Medical Information; Protected Health Information owned or licensed by a HIPAA covered entity.

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r0003hnu29bmldps7

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian…

CSO Online·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015thmu2mmm7f9l0

OpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity threshold

OpenAI launched GPT-6 Astra on Thursday, disclosing that the new flagship model has crossed the “Critical” threshold for cybersecurity risk under its Preparedness Framework, a classification the company said triggers additional deployment restrictions. “GPT‑6 Astra is rolling out today to a limited set of organizations and over the coming days will become available to all ChatGPT Plus, Pro, Business, and Enterprise users, as well as through the OpenAI API and AWS,” OpenAI said in a statement.…

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze95015uhmu2chmgvodj

The democratization of cyber warfare — and what it means for CISOs

For most of modern history, sophisticated and costly warfare had a high barrier to entry. In order to maintain a significant tactical advantage, you needed money, infrastructure and highly trained human resources. In the physical realm, you needed trained and capable warfighters along with relatively expensive and specialized weaponry, made by skilled tradesmen. In cyber, you needed operators who understood networks, vulnerabilities, exploitation and how to move through an environment without…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002mhnu2dlmm9go1

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002nhnu2tvc1cejx

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them. "We recommend all server owners and Desktop users