BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Cyber Security News·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujpe6s05efhmu2ih24qb21

Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit Attacks

Multiple espionage-motivated threat actors have rapidly adopted a newly discovered exploit kit that chains Chrome browser and Microsoft Windows vulnerabilities to deploy backdoors and surveillance tools against government, defense, and commercial targets worldwide. Security researchers at Proofpoint have named the kit “BlueMoon,” identifying its use by at least four distinct threat clusters since late August […] The post Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit…

Also reported by 1 other source
Cyber Security News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujpe6s05eghmu2at15fcyg

Veradigm Confirms Patient Data Exposed in Third-Party Data Breach

Healthcare technology company Veradigm Inc. disclosed that a cybersecurity incident at one of its third-party vendors exposed sensitive patient data, including Social Security numbers, for a limited group of the company’s customers. The disclosure, filed with the U.S. Securities and Exchange Commission on September 8, 2026, marks the latest in a string of vendor-related breaches […] The post Veradigm Confirms Patient Data Exposed in Third-Party Data Breach appeared first on Cyber Security News.

Also reported by 1 other source
Also reported by 1 other source
Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujpe6s05ehhmu2yxs5ersl

New N0va Phishkit Targets North America and EU: A Growing Identity Risk for SOCs

Recently, ANY.RUN researchers uncovered N0va, a new phishkit targeting organizations across North America and the EU, including government, technology, consulting, and healthcare. What makes N0va especially relevant for SOC leaders is how it spreads the attack across different layers. Legitimate authentication, trusted brand lures, compromised websites, and cloud infrastructure can leave security teams with only part of the picture, […] The post New N0va Phishkit Targets North America and EU: A…

CyberScoop·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujqoav05g9hmu269ea7su9

FBI cyber chief worries private sector not sharing enough cyber threat information

Brett Leatherman said that industry has the wrong idea about what the FBI does with the data it collects during incidents, which is used to help victims and investigations alike. The post FBI cyber chief worries private sector not sharing enough cyber threat information appeared first on CyberScoop.

Cyber Security News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujpe6s05eihmu2d4p22j27

Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise 440 Servers Worldwide

A Russian-speaking threat actor has weaponized artificial intelligence at an unprecedented scale, deploying hundreds of autonomous AI agents to exploit critical vulnerabilities in PaperCut NG/MF print management software and compromise at least 440 servers across 395 organizations in 48 countries. Security researchers at GreyNoise identified the campaign through their Global Observation Grid, a network of […] The post Hackers Use Hundreds of AI Agents to Exploit PaperCut Flaws and Compromise…

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujpe6s05ejhmu264vy22tp

ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools

ClearFake has expanded a fake CAPTCHA scam into a chain that steals cryptocurrency and credentials while disabling endpoint protection. It turns compromised websites into launchpads, relying on visitors to run a command that appears routine. The operation begins with injected browser code, blockchain-hosted instructions, and a ClickFix prompt styled as a Google CAPTCHA. After a […] The post ClearFake Deploys Crypto Stealer That Uses Vulnerable Driver to Kill EDR Security Tools appeared first on…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtu77a9v0l87hmu2ndtv0thm

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujpe6s05ekhmu2ufvs830f

Hackers Use Fake LinkedIn Job Offers to Infect Developers With New Cross-Platform RATs

Software developers are being targeted with fake job offers that turn routine coding tests into a path for remote access malware. The campaign uses recruiter personas on LinkedIn and other employment platforms to deliver projects that appear safe enough to run. The operation is attributed to the Iran-linked group Mirage Kitten, also known as UNC1549. […] The post Hackers Use Fake LinkedIn Job Offers to Infect Developers With New Cross-Platform RATs appeared first on Cyber Security News.

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujpe6s05elhmu2ay2z4ibd

MapLibre Vulnerability Exposes 2.7M Users to Zero-Click Attacks

A critical cross-site scripting vulnerability in the widely used MapLibre GL JS library could expose applications and an estimated 2.7 million users to zero-click attacks. The flaw, tracked as CVE-2026-85061 and GitHub Security Advisory GHSA-jrc7-96c5-q579, affects maplibre-gl versions 6.4.0 and earlier. MapLibre GL JS is an open-source JavaScript mapping library used by websites and web […] The post MapLibre Vulnerability Exposes 2.7M Users to Zero-Click Attacks appeared first on Cyber…

Bleeping Computer·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtu679t00k9chmu2l1jsxjpr

MFA's Weakest Link: Account Recovery Is the New Attack Path

MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. [...]

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujpe6s05emhmu2vejfu6rp

Microsoft Expands Windows Family Safety With Built-In Age Verification and Parental Controls

Microsoft is expanding Windows Family Safety with account-based age verification, privacy-focused age signals, and improved parental controls. The company said the updates are designed to help Windows apps, games, services, and AI experiences provide protections that match a user’s age. The initiative uses the Microsoft account as the central identity layer for family safety on […] The post Microsoft Expands Windows Family Safety With Built-In Age Verification and Parental Controls appeared…

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujpe6s05enhmu2s90h472d

Critical ArangoDB Flaws Allow Authentication Bypass and Remote Code Execution as Root

Two critical flaws in ArangoDB can let an outsider bypass login controls, read or alter database data, and then gain root-level code execution on the underlying host. The issues affect installations through version 3.12.10.1, creating serious risk for internet-facing databases and container deployments. The attack does not rely on stolen passwords, a user click, or […] The post Critical ArangoDB Flaws Allow Authentication Bypass and Remote Code Execution as Root appeared first on Cyber Security…

CyberScoop·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujqoav05gahmu21nv1w5ed

FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching

The remarks, to both CyberScoop and at the Billington CyberSecurity Summit, dovetail with the release of a new bureau cyber strategy. The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching appeared first on CyberScoop.

SecurityWeek·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtu2wz3x0h7shmu2b3vh4ckc

US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model. The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek.

Washington AG breach notices·Confirmed Breach2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7hge72000ihmu29a0h20se

Quatrro Business Support Services, Inc.: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 09/09/2026. Date of breach: 11/11/2025. 10,008 Washington residents affected. Information compromised: Name; Social Security Number; Driver's License or Washington ID Card Number; Financial & Banking Information; Passport Number; Health Insurance Policy or ID Number; Medical Information.

Also reported by 1 other source