BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu1imbqr53rthpu2r4htbnbx

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

A Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems," Acronis Threat Research Unit (TRU) said in an

Data Breach Today·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu1fq63350m4hpu2ieaadqa4

Revolut Reveals Data Breach Tied to Faked Official Request

Financial Platform Was Socially Engineered Into Disclosing Sensitive Customer Data Digital financial platform Revolut is notifying customers that it suffered a data breach exposing their personal details after it fell for an official-looking "impersonation scam" involving a request for customer information sent using "a legitimate government agency domain email."

Also reported by 1 other source
The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu1hc0qe52c2hpu2t9hshq75

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "New plugins are reviewed before they enter the directory, but updates ship continuously after that," David Perez, WordPress Official Plugin

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu1ed9tx4z1vhpu2988yh4hr

⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of

Also reported by 1 other source
Bleeping Computer·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu1bejci4vsbhpu26rkqhbpn

Why Patch Automation Needs Brakes, Not Just an Accelerator

Patch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad updates can spread faster. Action1 explains how update rings, predefined success criteria, and human oversight can make automated patching faster without sacrificing control. [...]

SecurityWeek·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu1a9dyu4uhihpu2ozq269ax

New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate

Concerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims. The post New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate appeared first on SecurityWeek.

Bleeping Computer·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu17z2u94rzxhpu2s9yw1yzd

Webinar: How malicious OAuth apps can lead to Google Workspace breaches

Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them. [...]

Also reported by 1 other source (2 articles)
CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu1o1s8259rdhpu2ggaat1bh

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu17q2tj4rp8hpu230e3lma6

AI Changed the Exposure Problem. Validation Needs to Change With It.

There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action. In the first half of 2026, a whopping 35,853 CVEs were published, roughly 49% more than in the