BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5l0eg39lh8hpu2qt0emnh7

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG

The Hacker News·Confirmed Breach4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5l0eg39lh9hpu2l2er1e9l

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up Gyazo image links. Helpfeel said

Also reported by 1 other source
Also reported by 1 other source
Also reported by 2 other sources
Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp5002ahku2cbrl2yzq

Flock gets plucked, OpenAI agents arrived even earlier, inside China's AI spy shop

Flock gets plucked OpenAI agents arrived early China's AI spy shop Get the show notes here: https://cisoseries.com/cybersecurity-news-september-17-2026/ Huge thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program, Vanta keeps you secure—and keeps…

The Hacker News·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5l0eg39lhbhpu2g2tgv0v6

U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks

The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser. The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the site are now greeted by a seizure banner that states - "This domain has been seized by the