BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Also reported by 2 other sources (5 articles)
CyberScoop·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu750txr04ybhmu28nwudrql

International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data

The U.S., Japan, Germany and Australia said WaterPlum operators pose as prospective employers and have infected more than 30,000 devices worldwide. The post International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data appeared first on CyberScoop.

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu74uev804sahmu2vfdrg3i6

A zero-click RCE flaw in AI coding agents could have exposed enterprise systems

Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a zero-click attack that enabled attackers to execute malicious code, even without developer interaction, by swapping a trusted plugin from an online marketplace for a malicious one, potentially giving them a foothold in enterprise development environments. Researchers at cybersecurity startup AIR found and reported the flaw, which they are calling…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu74uf1m04suhmu28y44r6f1

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu73zlcv030yhmu2ycjtqhe9

GhostCode attackers abuse device codes to take over Microsoft 365 accounts

Microsoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in eSentire’s threat response unit identified the campaign in late August 2026. The kit abuses Microsoft’s OAuth 2.0 device authorization grant flow, a legitimate mechanism designed to enable authentication from IoT devices, smart TVs, printers, or other devices that cannot easily support a conventional…