BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015lhmu2z1qwqi24

Security leaders must prepare for likely threats, not sensationalized agentic attacks

A malicious dataset exploits code-execution paths in a remote-code dataset loader and a dataset configuration before compromising access credentials to move laterally through the target network. A frontier AI model publishes a malicious Python package to a public PyPI registry after identifying setup instructions within a fictional environment that point to a non-existent package name to win a capture-the-flag exercise. Another model exploits a misconfiguration of a sandboxed testing…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq0021hnu2szv4js4m

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015mhmu25uleyjqj

Securing AI agents: Key controls and best practices

Enterprises increasingly give AI agents the credentials, tools, and network access of privileged employees, but security experts warn that existing security controls designed to govern human access are insufficient. An AI agent operates at inhuman speed, can chain allowed actions into unauthorized outcomes, and can spawn additional sub-agents to help, turning one unwitting employee’s access into a team of rogue insiders before security teams can detect and block them. It’s not uncommon for…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq0022hnu24hx5ob1z

Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp5002ihku24kyk6wvt

PEEP browser backdoors, $320M Liquid exploit, BigBear beats MFA

PEEP turns browsers into backdoors Liquid loses $320M, hackers play hero BigBear claws past MFA Get the full show notes here: https://cisoseries.com/cybersecurity-news-september-8-2026/ Huge thanks to our episode sponsor, ThreatLocker An attacker uses AI to create a payload your security tools have never seen. Detection now has to recognize it before the payload can act. ThreatLocker approaches the problem earlier by controlling whether that code is permitted to run at all. Explore a deny by…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq0023hnu21vsuyf96

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq0024hnu23pwj1kfz

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq0025hnu29dnyh7z9

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management

CSO Online·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015nhmu2uqhskcwi

Sam Altman calls GPT-6 Astra rollout ‘messy’ as enterprise users wait for access

OpenAI’s rollout of its GPT-6 Astra model ran into early access issues after paying ChatGPT users were unable to use the system shortly after launch, prompting CEO Sam Altman to apologize and say the release had been “messy.” “First, sorry for the messy rollout,” OpenAI CEO Sam Altman acknowledged the issue in a post on X. “Second, when we screw up, we try to make it right.” OpenAI had said GPT-6 Astra would be rolled out across ChatGPT tiers and APIs, positioning it as its most advanced model…

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015ohmu292ldnwsz

Back-to-back N-able bugs send admins on a patching spree

A max-severity zero-day bug could be affecting cybersecurity firm N-able’s N-central remote monitoring and management platform, the company said, even as administrators were applying a hotfix for two vulnerabilities disclosed just a day earlier. The latest flaw, tracked as CVE-2026-86218, is a remote code execution bug that can give an attacker access to an N-central server without authentication. Through its incident page, the company said the new vulnerability is unrelated to the two flaws…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq0026hnu28ct4ao2o

Your Cloud Security Checklist Doesn't Work the Way You Think It Does

If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like. How risk differs across cloud providers

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq0027hnu2pg7mkyld

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq0028hnu2mtwm9vbb

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015phmu2y5cbxalg

New CISO appointments 2026

The upper ranks of corporate security are seeing a high rate of change as companies try to adapt to the evolving threat landscape. Many companies are hiring a chief security officer (CSO) or chief information security officer (CISO) for the first time to support a deeper commitment to information security. Follow this column to keep up with new appointments to senior-level security roles and perhaps gain a little insight into hiring trends. If you have an announcement of your own that you would…

The Hacker News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq0029hnu2xa4rz362

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015qhmu2lmk028tq

What do CISOs need to rest easy about future AI risks?

Security leaders’ confidence in their ability to navigate the security risks AI will pose over the next two years rests on several clear factors, according to IANS analysis of its AI Security Survey, fielded earlier this year. Of the 113 CISOs IANS surveyed in April and May, 41% expressed optimism about their organization’s ability to manage AI security risks over the next 24 months, versus 38% who were pessimistic. Delving deeper, IANS identified six strong organizational signals that…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002ahnu2quevydn0

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a

Cyber Security Headlines·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp5002jhku231n8rrh1

MikroTik routers hijacked, Russian data center threats, UK cybercrime losses surge

MikroTik routers hijacked through internet-exposed SSH Russian data centers face new security requirements UK account-hack losses surge thanks to new reporting system Get the show notes here: https://cisoseries.com/cybersecurity-news-mikrotik-routers-hijacked-russian-data-center-threats-uk-cybercrime-losses-surge/ Huge thanks to our episode sponsor, ThreatLocker AI is helping attackers research targets, create malicious code, and adapt faster. But the fundamentals have not changed. Code still…

Also reported by 1 other source
The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002chnu2wcv9kzv8

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

The Hacker News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq002dhnu2sra4xnp4

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is