BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Also reported by 1 other source
Also reported by 1 other source (5 articles)
The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu70t32o00vvhnu2uk6lxbfi

An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and documentation pages still carry hard-coded references to hostnames beneath it. The new owner holds

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu70t32o00vwhnu2wnyls9x9

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday. The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no

Also reported by 1 other source
The Hacker News·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu6ucbp91fajhou2nt3i4nm7

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu6rdluv1953hou2guu5fejp

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"