BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Also reported by 2 other sources (3 articles)
The Hacker News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu6f9mj80jsvhou289x7vb9v

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. "HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading,

Also reported by 1 other source
Bleeping Computer·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5lva4y9mdghpu2tgwyixsb

What Recent AI-Powered Attacks Mean for Your Identity Security

AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted. [...]

CyberScoop·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5l0dqm9lfahpu228o4thyf

Authorities seize popular, long-running DDoS-for-hire service domains

Cybercriminals used NightmareStresser to launch hundreds of thousands of DDoS attacks since at least 2022. Threat actors behind the operation claimed links to Russia. The post Authorities seize popular, long-running DDoS-for-hire service domains appeared first on CyberScoop.

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5kostw9l1thpu2dtd1bjc6

Self-modifying AI agents expose a blind spot in enterprise security

As debate over AI safety intensifies, new research is drawing attention to a more immediate risk for enterprises: AI agents that can alter the models they rely on while carrying out routine tasks. Researchers at AI security firm Irregular asked a coding agent to solve a software maintenance problem involving an application built on a local AI model that was returning incorrect answers. Instead of limiting its changes to the application, the agent fine-tuned the open-weight model it used — a…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5l0eg39lh3hpu2fu7252mj

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with

Also reported by 1 other source