BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvmbk961dinhmu228e46rlw

Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware

Cybercriminals are exploiting intense interest in Grand Theft Auto VI by pushing fake game downloads that install several types of malware instead of a playable game. The campaign targets people looking for an early build, leaked copy, or unofficial demo before the title’s release. The malicious downloads are distributed through poisoned search results, gaming forums, […] The post Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware appeared first on Cyber…

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvlw4mi1d09hmu2kla19idx

WordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites

WordPress has rolled out an automated, AI-driven security review that screens every plugin release before it reaches the WordPress.org update API, adding a critical checkpoint to a distribution pipeline that had previously lacked one. The move follows a real-world incident in which a backdoor was slipped into an update for a plugin with roughly 20,000 […] The post WordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites appeared first on Cyber Security News.

Cyber Security News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvloevx1crvhmu2jj9a3bbw

Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers

A new phishing campaign is moving fake login pages into victims’ browsers. Rather than sending people to a malicious website, its operators use browser-generated blob URLs to assemble the page in local memory, leaving less for security tools to inspect before it appears. The operation starts with a DocuSign-themed email carrying a calendar invitation. Its […] The post Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers appeared first on Cyber Security…

Bleeping Computer·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvltk0w1cyqhmu2h3etcwru

The Top 4 Threats We Found by Investigating Every Alert for a Quarter

Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked. [...]

Cyber Security News·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvkltz81bjphmu24t9s1jde

Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware

Cisco Talos has confirmed active exploitation of two vulnerabilities affecting Cisco Secure Firewall Management Center (FMC) Software, with state-sponsored hacking groups and a ransomware affiliate leveraging the flaws to seize root access, plant malware, and stage attacks on enterprise networks. The disclosure marks one of the year’s more serious enterprise security incidents, given FMC’s role […] The post Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware…

Graham Cluley·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvkyoxx1c03hmu2q6np0qxy

‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars

Here's a tip for any budding cybercriminals out there. If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub. Read more in my article on the Hot for Security blog.

SecurityWeek·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvkpp6u1bq8hmu2s0gnmu7h

Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation

Join the webinar for a focused, 20-minute discussion on Frontier Pace Governance, an approach to balancing automation, policy, and business risk as IT operations accelerate. The post Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation appeared first on SecurityWeek.

Cyber Security News·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvke47n1bbchmu2hzxwbz2l

CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks

CISA added a critical Citrix NetScaler authentication bypass flaw (CVE-2026-19490) to its Known Exploited Vulnerabilities catalog after observing in-the-wild attacks targeting the issue. Federal civilian agencies must apply vendor mitigations by September 12, 2026. CVE-2026-19490 affects Citrix NetScaler ADC and NetScaler Gateway appliances configured as an Authentication, Authorization and Auditing virtual server or as a […] The post CISA Warns of Citrix NetScaler Authentication Bypass…

Also reported by 1 other source
Cyber Security News·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvk6ejo1b24hmu2t9s86cqz

Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data

Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. It can defeat MFA protections. The campaign starts with calls and texts to employees. Attackers pose as IT support, claim a passkey, MFA, or single sign-on setting needs attention, and direct targets to lookalike sign-in pages. Compromised accounts can […] The post Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data appeared first on Cyber Security…

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvjcu001a61hmu2fwn8rdya

Hackers Can Turn AI Workflows Into Privileged Data-Stealing Proxies Without Jailbreaking Models

Enterprise AI workflows can be vulnerable to misuse that exposes sensitive information without prompt injection, account compromise, or jailbreaking a large language model. This vulnerability, termed Workflow Identity Hijacking, exploits authorization gaps between external requesters and the privileged identities used by AI automation. Workflows linked to public-facing email inboxes, web forms, GitHub issues, shared documents, […] The post Hackers Can Turn AI Workflows Into Privileged…

Cyber Security News·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvij8np1971hmu2gmtfrgmr

Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks

Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score of 9.8 and both capable of allowing unauthenticated remote code execution under specific conditions. Check Point’s own research team uncovered the flaws, and the company says it has found no evidence of active exploitation or […] The post Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks appeared first on Cyber…

Also reported by 1 other source
Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvibiwd18xvhmu2dcse8cab

LiteLLM Flaws Let Attackers Execute Code as Root and Steal Cloud Credentials

LiteLLM deployments can expose far more than an organization’s AI spending. Newly disclosed weaknesses in the open-source gateway could let attackers run code as root inside a container, reach connected tools, and retrieve cloud credentials that open a path into a wider environment. The risk is serious where the service is internet-facing or retains its […] The post LiteLLM Flaws Let Attackers Execute Code as Root and Steal Cloud Credentials appeared first on Cyber Security News.

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvhj95n1827hmu2eamm8p2p

AI workflows may be creating a dangerous new authorization blind spot

A newly identified AI attack technique can let unauthenticated users trigger privileged workflows and access enterprise systems, highlighting a gap in how identity and access controls apply to AI agents, according to research from Noma Labs. The report, authored by Noma Labs lead researcher Sasi Levi, describes the issue as “workflow identity hijacking,” where attackers bypass standard controls by sending normal, benign requests through an unauthenticated entry point such as a support inbox,…

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvyuy9l1rskhmu2kuuy2n1d

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational…

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvp1art1gnvhmu29r8m8owl

AVEVA Pipeline Integrity Monitor

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA Pipeline Integrity Monitor are affected: AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513 (CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824) CVSS Vendor Equipment Vulnerabilities v3 8.4 AVEVA AVEVA Pipeline Integrity Monitor Use of Hard-coded…

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvp1art1gnuhmu2j1jd6l0b

ST Engineering iDirect iQ-Series Terminals (Update A)

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected: Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058) 3315‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058) 9‑Series terminals…

CISA Advisories·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvp1art1gnthmu2orxjsr7e

NextGen Healthcare Mirth Connect

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition. The following versions of NextGen Healthcare Mirth Connect are affected: Mirth Connect <=v4.7.1 (CVE-2026-82583, CVE-2026-78224, CVE-2026-82578) CVSS Vendor Equipment Vulnerabilities v3 8.3 NextGen Healthcare NextGen Healthcare Mirth Connect Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), Improper Restriction…

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvp1art1gnshmu29zpt94gj

Orthanc DICOM Server

View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition. The following versions of Orthanc DICOM Server are affected: Orthanc DICOM Server <1.13.0. (CVE-2026-87020) CVSS Vendor Equipment Vulnerabilities v3 8.1 Orthanc Orthanc DICOM Server Integer Overflow or…

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvgw3sx17cbhmu2dova009w

Stealth rootkit targeting F5 BIG-IP could expose enterprise identity gateways

A newly analyzed Linux rootkit is believed to have given attackers a way to hide shells inside recently compromised F5 BIG-IP Access Policy Management (APM) environments, without leaving the malicious PHP code on disk. Sophos said the malware, found in compromised BIG-IP APM environments using Apache and PHP components, uses custom ELF loading, function hooking, and runtime code patching to establish persistent access. The implant, it said in a blog post, appears to be tailored specifically to…