BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015ihmu282vlgf35

Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests

Specialized team of AI agents that discover, attack, and validate web vulnerabilities, leveraging pre-existing site context to eliminate noise and speed remediation. Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites. Multiple specialized AI agents discover, attack, and validate vulnerabilities across complex web environments, and because they start from an existing model of each site, they cover up to ten times more…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq001vhnu2jjdqa3tp

ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account

Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq001whnu29x87tc7o

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI

Also reported by 1 other source
SecurityWeek·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1ye8001ahnu2iupsa0da

Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft

The scammers purchased fleets of sports cars, flew on private jets, hired security guards and rented mansions in Miami and the Hamptons. The post Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft appeared first on SecurityWeek.

Bleeping Computer·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yfa001rhnu230mwoc3n

Webinar: The forgotten Google Workspace access that can lead to a breach

Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure. [...]

SEC EDGAR 8-K cyber incidents·Confirmed Incident3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7hgf5f000rhmu2xmvu4qv0

BOSTON SCIENTIFIC CORP: 8-K Item 1.05 — material cybersecurity incident

As previously disclosed in a Current Report on Form 8-K filed on August 26, 2026 with the Securities and Exchange Commission, on August 25, 2026, Boston Scientific Corporation (the “ Company ”) identified a cybersecurity incident that affected certain of its information technology systems and resulted in a global disruption to the Company’s operations. Upon detection, the Company activated its incident response protocols, and since then has been working, with the assistance of third-party…

Washington AG breach notices·Confirmed Breach2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7hge72000jhmu2gpojsd8e

Hibbett Retail, Inc.: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 09/08/2026. Date of breach: 04/22/2026. 510 Washington residents affected. Information compromised: Name; Social Security Number; Driver's License or Washington ID Card Number; Financial & Banking Information; Full Date of Birth; Student ID Number; Military ID Number; Passport Number; Health Insurance Policy or ID Number; Medical Information.

Also reported by 1 other source
CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r0002hnu2loi4040a

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability CVE-2026-86218 N-able N-central Static Code Injection Vulnerability These types of vulnerabilities…

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r0001hnu24vrkriql

China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies

Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation…

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r0000hnu2g0jz8pyq

CareCam Pro IP Cameras

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of CareCam Pro IP Cameras are affected: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083) CVSS Vendor Equipment Vulnerabilities v3 6.8 CareCam CareCam Pro IP Cameras Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Commercial Facilities…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq001xhnu216qg29uv

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq001yhnu2jd5q0cco

What It Took to Reach 1 Billion Build Manifests

In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally

CSO Online·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015jhmu2awlgr11p

Adobe Commerce max-severity bug comes under active attack

Online stores running Adobe Commerce and Magento Open Source have been hit by a max-severity, zero-day bug that lets unauthenticated attackers execute code on vulnerable servers. Security firm Sansec is calling the flaw StyleSmuggler because of the way attackers abused Magento’s Style properties to inject malicious code past existing safeguards. “When the attack succeeds, a backdoor background process is launched. This is a small Rust program that connects to the 99.84.67.186 C2 server and…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq001zhnu2s20vaf6u

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The

CSO Online·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015khmu2br45xa6j

BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA

A phishing-as-a-service operation targeting Microsoft 365 users has harvested thousands of session cookies that could be used to hijack authenticated sessions after victims complete multifactor authentication, CloudSEK said. The cybersecurity firm said in a report that it uncovered the operation, known as BigBear 2.0, in June after gaining access to its administrative panel. The panel contained 5,137 credential records linked to 461 targeted organizations across more than 40 countries. CloudSEK…

CyberScoop·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujqoav05gghmu2ncpma21m

In most cities, nobody owns the whole network

July’s intrusions reached water controllers that sat on a cellular link no city network scan would find. Naming an owner and paying for the fix are decisions a utility can make this fiscal year, out of money it already applies for. The post In most cities, nobody owns the whole network appeared first on CyberScoop.