BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

The Hacker News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvjn3xv1agrhmu2iq63jo82

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to

The Hacker News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvjn3xv1agshmu2ugiynfho

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvg6dbt16iqhmu2evo8mlfw

Hackers Pose as Domain Controllers to Steal Active Directory Password Hashes

Threat actors are increasingly abusing Active Directory replication to impersonate domain controllers and steal password hashes from enterprise networks. This technique, known as a DCSync attack, can let attackers obtain credential data for privileged accounts without deploying malware directly on a legitimate domain controller. Active Directory domain controllers manage authentication across Windows enterprise environments. They […] The post Hackers Pose as Domain Controllers to Steal Active…

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvg6dbt16irhmu25xb031wn

CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Fortinet vulnerability, tracked as CVE-2025-25249, to its Known Exploited Vulnerabilities catalog after confirming evidence of active exploitation. The flaw affects FortiOS, FortiSwitchManager, and FortiSASE products. It could allow attackers to execute unauthorized code or commands by sending specially crafted packets. CVE-2025-25249 is a heap-based […] The post CISA Warns of Fortinet Heap-based Buffer Overflow Flaw…

Cyber Security News·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvfynvs169khmu2fgelukyb

OpenSSL 4.1.0 Alpha1 Released With DTLS 1.3 and Faster Post-Quantum Cryptography

The OpenSSL Project has released OpenSSL 4.1.0 Alpha1, an early preview of its forthcoming feature release. This update adds support for Datagram Transport Layer Security (DTLS) 1.3, GREASE for more resilient TLS deployments, and architecture-specific performance enhancements for post-quantum cryptography operations. As an alpha release, it is intended for testing and development, not production deployment. […] The post OpenSSL 4.1.0 Alpha1 Released With DTLS 1.3 and Faster Post-Quantum…

Also reported by 1 other source
Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvfj7vd15r1hmu2f7napihc

Palo Alto PAN-OS Vulnerability Enables Arbitrary Code Execution as Root User

Palo Alto Networks has disclosed a high-severity PAN-OS vulnerability that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on affected PA-Series hardware firewalls. Tracked as CVE-2026-0310, the flaw exists in XML processing, and the vendor has assigned it the highest suggested urgency. The vulnerability is a buffer overflow, classified as […] The post Palo Alto PAN-OS Vulnerability Enables Arbitrary Code Execution as Root User appeared first on…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvg7nhu16j0hmu29ocrsxy3

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtve8x7p149fhmu236lp6lm9

OpenAI Builds ‘Defense Factory’ Where AI Agents Continuously Find and Fix Vulnerabilities

OpenAI has introduced a “Defense Factory,” an automated, agent-first cybersecurity operation that continuously discovers, validates, and remediates vulnerabilities. The company says traditional defenses may no longer be sufficient as long-running AI agents can chain exploits and scale attacks using increasingly available open-weight models. Modern AI agents can operate for extended periods, retain knowledge across sessions, […] The post OpenAI Builds ‘Defense Factory’ Where AI Agents…

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvd175h12xdhmu2z876plxt

The longitude problem: In the AI era, detection is won on facts, not guesses

For most of the age of sail, a captain could find his latitude in minutes and could not find his longitude at all. Latitude you could read off the sun. Longitude, your position east to west, offered no such trick. Three weeks into the Atlantic, a navigator knew how far north he was and could only estimate how far along he had come. The estimate was often wrong, and wrong on open water means rocks. After a British fleet was lost on home rocks in 1707, Parliament offered up to 20,000 pounds for…

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvcqwua12l5hmu209qddtm9

Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware

Mac users seeking AI tools face a malware trap. Attackers are using fake Claude and ChatGPT installers and sponsored search results to push MacSync, a macOS password stealer. The campaign relies on persuasion instead of a software flaw. A visitor is told that a download, connection, or verification step has failed, then instructed to copy […] The post Hackers Use Fake Claude and ChatGPT Installers to Infect Mac Users With Password-Stealing Malware appeared first on Cyber Security News.

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtv9lqpl0z0hhmu23uttchis

10 most critical LLM vulnerabilities

Enterprise adoption of generative AI technologies has exploded due to the rapid evolution of the technology and the emergence of a variety of business use cases. But large language models (LLMs) can accidentally produce harmful results, leak information, or become exposed to threat actors. These vulnerabilities are changing as the technology evolves and as attackers find new ways to compromise systems. For enterprises, this means the risk of bad publicity, compliance or cybersecurity exposure,…

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtv9j6zs0yy4hmu2oux4b6mr

Top 10 Best Server Security Solutions in 2026

Bottom line up front: servers are not big laptops. They run Linux as often as Windows, can’t tolerate agent-induced latency, host the data ransomware actually wants, and increasingly live as VMs, containers, or cloud instances. Deploying dedicated endpoint detection and response (EDR) on servers requires balancing performance overhead with deep telemetry. Trend Micro’s server heritage […] The post Top 10 Best Server Security Solutions in 2026 appeared first on Cyber Security News.

Also reported by 1 other source
Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtv9bghl0yozhmu2qfl70n0a

Top 10 Best Endpoint Encryption Software in 2026

Bottom line up front: the encryption engines are largely solved BitLocker and FileVault are strong, free, and built in. What you’re actually buying in 2026 is management: proof for auditors, key escrow and recovery, policy across mixed fleets, and pre-boot options where required. Buy management, not ciphers. That reframing decides most of this list, establishing […] The post Top 10 Best Endpoint Encryption Software in 2026 appeared first on Cyber Security News.

Also reported by 1 other source
Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtv8w0yq0y7ehmu20x27kqlj

Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks

Hackers have used commercial AI models to help break into government, transport and financial networks across Latin America. The activity shows how chat-based tools can speed up familiar intrusion work, from fixing faulty scripts to moving stolen information out of a compromised system. The campaigns did not rely on a new AI-built malware family alone. […] The post Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks appeared first on Cyber Security News.

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtv8w0yq0y7fhmu2isuenp9f

Top 10 Best Device Control & USB Security Tools in 2026

USB ports remain a two-way risk: malware walks in, data walks out. Device control governs what can connect by device class, vendor ID, even serial number and what connected devices may do, with encryption enforced on whatever leaves. Governing removable media is essential for preventing data exfiltration and maintaining a resilient Zero Trust Architecture. CoSoSys […] The post Top 10 Best Device Control & USB Security Tools in 2026 appeared first on Cyber Security News.

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtva7lsj0zp2hmu2nrb0hig9

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential. Anyone who holds it can read every