BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Dark Reading·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu32li0h6to8hpu2lrhqithg

Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident

The 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI At this Black Hat USA 2026 talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face incident and examine its implications for AI security, cyber resilience, and alignment. Throughout the session, they will share insights that address key topics raised by the Black Hat Review Board, including model safeguards, evaluation and containment practices,…

Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu31t7y76sunhpu21o0m2oob

Crypto Industry Figures Blackmailed by Revolut's Hacker

Payments Platform Socially Engineered With Hacked Government Agency Email Account Personally identifiable information for multiple cryptocurrency industry figures was targeted and stolen by the threat actor who hacked payments platform Revolut, prompting warnings for these customers' personal safety, with some receiving direct extortion threats.

Also reported by 1 other source
The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu31drg36sbhhpu2or33tqh5

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu2zvs826qqfhpu23g9q6j3y

Crypto Agility: Digital Trust Is Becoming a Full-Time Job

Shrinking Certificates, ACME, mTLS and PQC Redefine Enterprise Security Posture Certificate lifespans are shrinking, making automated life cycle management essential. ACME is replacing manual renewal, mTLS is extending cryptographic identity across internal services, and post-quantum deadlines are approaching. Here's how leaders can build crypto agility now.

Also reported by 1 other source
Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu2zo1p76qh0hpu26q1ammhi

Iranian Hackers Dodging Corporate Defenses to Reach Critics

Joint Advisory Details Chosen Brick Spyware Used Against Iran's Critics Abroad Iranian state hackers are steering dissidents, activists and journalists away from corporate devices and onto personal computers to plant spyware that can capture screens, record audio and steal messages, according to a joint advisory from British, U.S. and Dutch intelligence agencies.

Also reported by 1 other source
Also reported by 1 other source
The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu2ylgid6p89hpu2ztp0varc

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record

CyberScoop·6 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu2uiuok6krfhpu24nmh1dj6

Cisco warns customers of actively exploited zero-day in email gateways

The company confirmed the defect was exploited before it was disclosed and patched, but it did not describe the nature of the attacks or the scope of impact across its customer base. The post Cisco warns customers of actively exploited zero-day in email gateways appeared first on CyberScoop.

The Hacker News·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu2ub4tq6khfhpu2o49elf98

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.

Also reported by 1 other source
CSO Online·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu2s3ecs6i09hpu2yzpyfmvj

Exposed Vite servers are being probed for AWS and Azure credentials

Attackers have opened a new front in their war on software developers: Vite servers, which they are probing for sensitive data including cloud credentials, infrastructure configuration and environment files. Vite was created as a build tool for Vue, a JavaScript framework for building user interfaces and web applications, but has now become a widely used development server and build tool across the JavaScript ecosystem. F5 Labs reported that attackers sent more than 32,000 attempts to scan…

Bleeping Computer·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu2qmo9h6gdnhpu2ytl1c7oq

What Zero-Day Response Should Be in the Post-Mythos Era

AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive. [...]

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu2op86y6e8uhpu2w71kbmm3

Exaforce extends its AI security tool to monitor more than just Claude

Exaforce is offering to help enterprise security teams discover and monitor AI agents using security telemetry they already collect, rather than requiring yet another endpoint sensor. By combining usage data from agentic AI platforms with endpoint, cloud, SaaS and code data, Exaforce AI Security can identify risks, detect suspicious behavior, and respond to threats, the company said. “Exaforce uses data the SOC already collects to inventory every AI app and agent, connect each one to the…