BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Also reported by 2 other sources
Data Breach Today·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtx9h7gp0bslhpu2mqougp5o

AI Agents Used in PaperCut Attacks on 395 Organizations

GreyNoise Says Attacker Used Hundreds of Agents in 48-Country Campaign A likely Russian-speaking attacker used hundreds of AI agents to exploit PaperCut systems, compromising at least 440 systems at 395 organizations in 48 countries. GreyNoise said the attacker used the agents to develop exploits, find targets and attack systems in parallel.

Also reported by 1 other source
Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtx9h7gp0bskhpu2ekdcyhu9

Novo Nordisk Data Breach Tied to Stolen GitHub Access Tokens

Cyber Extortion Group Continues to Target Exposed Cloud-Based Data Over Endpoints Cyber extortion group FulcrumSec continues to find hardcoded credentials in public-facing IT infrastructure and exploit them as part of what it's dubbed a "Hardcoded Horrorshow" that counts Ozempic maker Novo Nordisk among its victims. Here are defenses organizations need to put in place now.

Also reported by 1 other source
CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtx7h6ck09i6hpu2xzhtzql9

Update your firewall rules: Teams and Copilot are changing address

Microsoft is changing the destination address of two of its most popular services: starting this month, it will redirect M365 and Teams web users to copilot.cloud.microsoft and teams.cloud.microsoft, respectively. The Teams move is already under way, and Microsoft has now added M365 to the mix. The company announced the changes in two MessageCenter posts: MC1465764 (mirror) and MC1462915 (mirror). Organizations using these products are advised to update their systems and documentation to ensure…

CSO Online·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtx5z5um07shhpu25185stqt

ConnectWise patches critical ScreenConnect authentication failure after five days

ConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation. The company warned customers on Sept. 3 of the problem with support and access sessions in ConnectWise Remote Access, advising admins to log in and remove the “TransferFiles” permission from any users with an open session. The vulnerability, tracked as CVE-2026-84869, has…

The Hacker News·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtx831fz0a6ahpu27psnx4nt

Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a "teacher" to

Also reported by 1 other source
CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtx41ptl05lbhpu2i7nxxf5j

India’s STPI serves TerminalFix-style attack via fake Cloudflare check

A website linked to India’s Software Technology Parks of India (STPI) is serving a spoofed Cloudflare verification page that silently copies a malicious string to visitors’ clipboards and prompts them to execute it via Windows Terminal, in a technique consistent with emerging TerminalFix-style attacks. STPI, a Government of India organization that supports the country’s IT services and startup ecosystem, operates platforms used by technology firms, developers, and public-sector stakeholders.…

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtx26uhg03h1hpu2gk6e65nr

Russia-Aligned Hackers Use GuardBreaker Prompt Injection to Disrupt AI Malware Analysis

Russia-aligned operators are testing a new way to make artificial intelligence overlook malicious code. The technique, called GuardBreaker, hides a safety-sensitive request inside an otherwise ordinary script comment, hoping that an AI code scanner refuses to continue its work. The activity was observed during an early-stage intrusion against a target in Ukraine. The VBScript was […] The post Russia-Aligned Hackers Use GuardBreaker Prompt Injection to Disrupt AI Malware Analysis appeared first…

SecurityWeek·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtx1nkru02w7hpu23diaijam

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY. The post In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review appeared first on SecurityWeek.

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtx1rf3f02zjhpu28klyvzna

New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks

KATARU is a newly observed IoT malware strain that can turn poorly secured devices into DDoS attack nodes. The sample was captured after an attacker used repeated Telnet password guesses against a honeypot, then downloaded an ARM payload. It shows how old entry points still give attackers a foothold. The malware resembles the Mirai botnet […] The post New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks appeared first on Cyber Security News.

CSO Online·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtx1ietr02pchpu2j2h1qu70

Anthropic finds evidence of a fourth AI escaping from containment

Anthropic has owned up to a fourth security incident involving its AI model, Claude, escaping onto the open internet and attacking other organizations during a test of cybersecurity abilities on what was believed to be a closed system. The company revealed three such incidents in July after a preliminary investigation. However, on reexamining the 141,000 chat transcripts it believed could have been at risk, Anthropic discovered a fourth incident of unauthorized access to computer systems, this…