Skip to content
Breachfolio
News archive

Cybersecurity intelligence, curated and contextual.

In-depth analysis, threat research and industry perspective to help you stay ahead of what's next – new CVEs, model releases and attack patterns, without the breathless coverage.

Latest from the wire

NEWS

The Real AI Threat Is Blind Trust: Why Autonomous Execution Without Oversight Is Dangerous

AI models left to both interpret and execute commands eliminate critical cybersecurity oversight. When systems perform actions autonomously, they become vulnerable to adversarial prompt injection that can lead to large-scale unauthorized activity. Organizations must move away from automated execution for sensitive tasks to prevent systemic failures. To protect your environment, implement mandatory manual approval workflows for all AI-initiated actions that modify system states or data.

Read
NEWS

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT: Supply Chain Risks Expand

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem. The campaign, dubbed ViteVenom, uses blockchain-based infrastructure to hide C2 communication and deliver a remote access trojan. This attack highlights the ongoing risk of malicious dependencies in modern software development. Audit your development dependencies for unauthorized packages immediately.

Read
NEWS

Government Agencies Falling Victim to Ransomware Daily, Warns Study: High-Stakes Public Impact

Government organizations are increasingly targeted by ransomware operators who understand that public service disruption is unacceptable. These attackers exploit critical IT infrastructure and sensitive citizen databases to force ransom payments. Implement a zero-trust architecture and ensure you have immutable, offline, and frequently tested backups to protect against operational disruption and data extortion.

Read
15 results
Aug 23, 20267 min read

Car screens were infected through their own update channel

Kaspersky documents the first malware campaign with an infection chain built for car head units. It arrived through TWCore, the legitimate system app that handles analytics and updates, delivered over the MQTT update channel. It calls home every 90 minutes and supports nine commands.

Vulnerabilities AndroidBotnet
Daniel A. & Óscar S.
Breachfolio
Source →
Cars in a car park linked by glowing network lines, each vehicle a node
Aug 20, 20266 min read

A vCenter flaw was exploited five days after the patch shipped

CVE-2026-59310 allows unauthenticated code execution on VMware vCenter. Broadcom shipped the fix on 29 July; exploitation began five calendar days later. 361 victim IPs across 47 countries, with Germany and France in the top five, and a Babuk-derived ransomware as the payload.

Vulnerabilities VMwareRansomware
Daniel A. & Óscar S.
Breachfolio
Source →
Security operations team watching a world map light up with intrusion alerts
Aug 13, 20264 min read

Adobe patches a Magento flaw that hands over customer accounts

CVE-2026-71362 lets an attacker switch into another customer's session on Adobe Commerce, with no account, no admin rights and nothing for the victim to click. CVSS 9.1, patched in the August update. Adobe reports no known exploitation; Sansec says its WAF is already blocking attempts.

Vulnerabilities Account takeoverMagento
Daniel A. & Óscar S.
Breachfolio
Source →
Cybersecurity intelligence, curated and contextual.
Jul 19, 20263 min read

Microsoft warns of surge in ACR Stealer attacks against enterprise customers

Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. The malware effectively bypasses standard defenses by targeting active sessions. To mitigate this risk, implement strict conditional access policies and mandate frequent re-authentication for all cloud resources.

Threat research MalwareCredential Theft
Daniel A. & Óscar S.
Breachfolio
Source →
Cybersecurity intelligence, curated and contextual.
Jul 19, 20263 min read

The Real AI Threat Is Blind Trust – Why Autonomous Execution Without Oversight Is Dangerous

AI models left to both interpret and execute commands eliminate critical cybersecurity oversight. When systems perform actions autonomously, they become vulnerable to adversarial prompt injection that can lead to large-scale unauthorized activity. Organizations must move away from automated execution for sensitive tasks to prevent systemic failures. To protect your environment, implement mandatory manual approval workflows for all AI-initiated actions that modify system states or data.

AI security AI SecurityAutomation
Daniel A. & Óscar S.
Breachfolio
Source →
Cybersecurity intelligence, curated and contextual.
Jul 18, 20263 min read

Inc Ransomware Exploits SonicWall SMA Zero-Days – Full Root Access Achieved via Chaining

When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall's mobile access appliances. This exploitation facilitates unauthorized network access and potential ransomware deployment. Patch your appliances immediately to the latest firmware version to defend against this critical threat.

Ransomware RansomwareSonicWall
Daniel A. & Óscar S.
Breachfolio
Source →
Cybersecurity intelligence, curated and contextual.
Jul 18, 20263 min read

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT – Supply Chain Risks Expand

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem. The campaign, dubbed ViteVenom, uses blockchain-based infrastructure to hide C2 communication and deliver a remote access trojan. This attack highlights the ongoing risk of malicious dependencies in modern software development. Audit your development dependencies for unauthorized packages immediately.

Supply chain Supply Chainnpm
Daniel A. & Óscar S.
Breachfolio
Source →
Cybersecurity intelligence, curated and contextual.
Jul 18, 20263 min read

Government Agencies Falling Victim to Ransomware Daily, Warns Study – High-Stakes Public Impact

Government organizations are increasingly targeted by ransomware operators who understand that public service disruption is unacceptable. These attackers exploit critical IT infrastructure and sensitive citizen databases to force ransom payments. Implement a zero-trust architecture and ensure you have immutable, offline, and frequently tested backups to protect against operational disruption and data extortion.

Ransomware RansomwareGovernment
Daniel A. & Óscar S.
Breachfolio
Source →
Cybersecurity intelligence, curated and contextual.
Jul 17, 20264 min read

Global Cyber Roundup: Iran Tracking, macOS Malware, and Defense Sector Ransomware

Noteworthy reports indicate Iranian state-affiliated actors are tracking U.S. military personnel via mobile telemetry, while a new macOS malware, CrashStealer, has emerged. Additionally, AI agents like OpenClaw have been exploited via WhatsApp, and defense contractor TKMS confirmed a ransomware attack. To protect your organization, treat all AI-integrated agents as high-risk components, conduct rigorous security assessments before deployment, and ensure mobile device location permissions are strictly managed to prevent sensitive data exposure.

Threat research Threat ResearchMalware
Daniel A. & Óscar S.
Breachfolio
Source →
Cybersecurity intelligence, curated and contextual.
Jul 17, 20264 min read

Ukraine Appoints Intelligence Expert as Acting Defense Minister to Strengthen Strategy

Ukrainian President Volodymyr Zelensky has appointed Yevhenii Khmara, formerly the acting head of the Security Service of Ukraine (SBU), as the nation's new acting defense minister. Khmara, a major general with extensive counterintelligence and unconventional warfare experience, is tasked with modernizing military command and integrating intelligence-led operations into the national defense strategy. Partners and contractors are advised to review communication security protocols and prepare for tighter oversight in defense procurement processes.

Threat research DefenseUkraine
Daniel A. & Óscar S.
Breachfolio
Source →
Cybersecurity intelligence, curated and contextual.
Jul 16, 20261 min read

Identity Attacks Overtake Exploits as Top Ransomware Cause

Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.

Threat Research EmailMFA
Daniel A. & Óscar S.
Breachfolio
Source →
Cybersecurity intelligence, curated and contextual.
Jul 15, 20264 min read

Progress confirms zero-day vulnerability behind ShareFile disruption – vendor issues patch to restore service

Progress Software has confirmed that a zero-day vulnerability in its ShareFile product was the cause of recent service disruptions for customers using the Storage Zones Controller. The company has since released a fix to address the security flaw and is actively working to restore services for impacted users. While initial reports highlighted instability, the company's subsequent patch is intended to remediate the underlying exploit. If you are operating a ShareFile Storage Zones Controller environment, verify that you have applied the latest vendor-supplied patch immediately to regain service stability and mitigate potential compromise.

Vulnerabilities Zero-dayShareFile
Daniel A. & Óscar S.
Breachfolio
Source →
Cybersecurity intelligence, curated and contextual.
Jul 10, 20268 min read

SharePoint RCE lands on CISA's must-patch list: the bulletin came weeks after the fix

Microsoft shipped the fix for CVE-2026-45659 in May's cumulative update but published the bulletin weeks later. CISA has confirmed active exploitation and added it to the KEV catalog: the CVSS 8.8 flaw is RCE via unsafe deserialization. On-prem SharePoint? Confirm you're on the May cumulative update.

Vulnerabilities RCESharePoint
Daniel A. & Óscar S.
Breachfolio
Source →
Cybersecurity intelligence, curated and contextual.
Jul 10, 20266 min read

A perfect 10.0 in SimpleHelp puts MSPs back in the supply-chain blast radius

CVE-2026-48558 scores maximum CVSS severity in SimpleHelp, an RMM tool widely used by managed service providers; exploitation is tracked via the "TaskWeaver" loader. One vulnerable MSP endpoint can fan out into every client network that MSP touches – if you outsource IT, this is the week to ask your provider directly.

Supply chain RMMMSP
Daniel A. & Óscar S.
Breachfolio
Source →
Cybersecurity intelligence, curated and contextual.
Jul 10, 20267 min read

JetBrains patches auth bypass and RCE across Hub, YouTrack, IntelliJ and more

A cluster of critical flaws across JetBrains' on-prem tools chains into auth bypass, account takeover and RCE – the sharpest a CVSS 9.8 from predictable account-restore codes. An IDE runs with your privileges: patch before opening untrusted repositories in any JetBrains product.

Vulnerabilities Auth bypassDev tooling
Daniel A. & Óscar S.
Breachfolio
Source →
Cybersecurity intelligence, curated and contextual.
Jul 10, 20266 min read

Anthropic ships Claude Sonnet 5 as the new default – agentic performance near Opus, at Sonnet pricing

Claude Sonnet 5 went live June 30 and is the new default for Free and Pro users, pitched squarely at agentic work: planning, tool use and autonomous runs at a level that used to need a pricier model. If Claude is wired into your tooling, benchmark against your own eval set before switching wholesale.

AI Security LLMModel release
Daniel A. & Óscar S.
Breachfolio
Source →
Cybersecurity intelligence, curated and contextual.