BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

The Hacker News·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtx40fxx05jkhpu2qm4jff39

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where "GTG" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight

Bleeping Computer·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtx184fb02bvhpu2l7hg4y4d

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. [...]

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtx09es601bqhpu2b50akj8j

Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments

A large email fraud campaign used fake CEO messages and invoices to push employees toward payments of nearly $50,000. The operation did not rely on a malicious attachment or software flaw. Instead, it used ordinary email to deliver a scam. The attackers sent over one million messages to users between August 3 and 5. Most […] The post Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments appeared first on Cyber Security News.

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtwzejf900aphpu2qlcxsvq8

Windows 11 Security Update KB5124008 Breaks Always-On VPN Connections

Microsoft’s September 2026 security update KB5124008 is knocking some Windows 11 enterprise clients off Always On VPN after the Patch Tuesday package landed on September 8. Administrators who can reproduce the failure say certificate-based tunnels that worked immediately before the patch stop connecting afterward, then recover as soon as the cumulative update is removed and […] The post Windows 11 Security Update KB5124008 Breaks Always-On VPN Connections appeared first on Cyber Security News.

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtwxwiu22vs0hmu2lxf7plbk

Conti Ransomware Hacker Sentenced After Group Attacked Over 1,000 Victims Worldwide

A Ukrainian national has been sentenced to four years in U.S. prison for his role in the Conti ransomware operation, which compromised more than 1,000 victims worldwide and generated at least $150 million in ransom payments. Oleksii Oleksiyovych Lytvynenko, 44, previously living in Cork, Ireland, was sentenced for conspiracy to commit wire fraud. U.S. prosecutors […] The post Conti Ransomware Hacker Sentenced After Group Attacked Over 1,000 Victims Worldwide appeared first on Cyber Security…

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtwx9dis2v1whmu2h7vlxgd2

New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims

A newly uncovered Android threat combines ransomware with spying, creating a trap for people who install apps from untrusted links. Called Mantax Otax, the malware can lock files, watch the screen, intercept verification codes and secretly use a phone’s cameras, making one infection both an extortion and privacy crisis. The campaign appears built around standalone […] The post New Android Ransomware Records Screens, Steals OTPs and Secretly Takes Photos of Victims appeared first on Cyber…

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtwwtxzf2ujuhmu2no2aj5z5

Ubuntu 24.04.5 LTS Released With Linux 7.0 Kernel and Latest Security Updates

Canonical has officially rolled out Ubuntu 24.04.5 LTS, the fifth maintenance update to the “Noble Numbat” long-term support release, delivering a fresh installation image packed with the latest security patches, bug fixes, and an upgraded hardware enablement stack built around the Linux 7.0 kernel. For a distribution that underpins millions of servers, cloud instances, and […] The post Ubuntu 24.04.5 LTS Released With Linux 7.0 Kernel and Latest Security Updates appeared first on Cyber…

Also reported by 2 other sources (5 articles)
CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtxf33af0i6yhpu20gtpn8wo

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements…

Also reported by 1 other source
The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtx05js60157hpu2q56tjn9b

Your Critical Vulnerabilities Might Not Be Your Biggest Risk

Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtwvjnac2t3chmu23ckkhfte

cPanel ConfigServer Security & Firewall Vulnerability Allows Remote Attacker to Execute Arbitrary Commands

A critical vulnerability in ConfigServer Security & Firewall (CSF), used on cPanel and WHM servers, could allow an unauthenticated remote attacker to execute arbitrary commands through the software’s MESSENGER service. The issue is tracked as CVE-2026-65638 and affects CSF versions 14.00 through 16.29. CSF version 16.30 and later fixes the vulnerability. Administrators running affected installations […] The post cPanel ConfigServer Security & Firewall Vulnerability Allows Remote Attacker to…

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtwsz2rp2q76hmu2ebzmovus

How AI and cybersecurity are reshaping ServiceNow

The once stable era of IT service management (ITSM) has entered a period of disruption and uncertainty. At least if you’re an investor or enterprise customer with an interest in ITSM giant ServiceNow, the signals over recent months have been hard to ignore. Last year, the category leader delivered market-pleasing AI announcements, a record share price, and good quarterly revenue growth, as well as an interesting pivot toward cybersecurity with the December acquisition of partner Armis for $7.75…

Cyber Security News·Confirmed Breach2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtwsjmmv2pokhmu2jlqdquf7

IDScan Confirms Data Breach Following 153 Million Driver’s Licenses Leaked on the Dark Web

IDScan.net, a Louisiana-based identity verification firm whose technology underpins age and identity checks for retailers, bars, and other Fortune 500 clients, has confirmed a data breach after a criminal marketplace began advertising more than 153 million driver’s licenses from the United States and Canada. The company disclosed that it detected unauthorized access to its systems […] The post IDScan Confirms Data Breach Following 153 Million Driver’s Licenses Leaked on the Dark Web appeared…

CSO Online·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtws46v52p6ghmu2d7k7rsql

Attackers use passkey-themed scams to hijack Microsoft 365 accounts

Attackers are using passkey-themed social engineering to trick employees into giving them access to their Microsoft accounts. Microsoft Security Research said it has been tracking active cloud intrusions since May in which attackers impersonated IT helpdesk staff, told employees they needed to update or enroll a passkey, and then took them to adversary-in-the-middle (AiTM) phishing pages or Microsoft device-code authentication flows. The campaign ultimately gave attackers access to compromised…