BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

KrebsOnSecurity·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1ycq0011hnu2ag8h901h

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e0328hmu2spuiotn2

Unlimited Technology Systems, LLC: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 07/21/2026. Date of breach: 10/05/2025. 724 Washington residents affected. Information compromised: Name; Social Security Number; Driver's License or Washington ID Card Number; Full Date of Birth; Health Insurance Policy or ID Number; Medical Information; Other; Protected Health Information owned or licensed by a HIPAA covered entity.

Compuquip·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttm0odu018lhmu2glim66d6

What to Look for in an AI-Managed SOC Partner

Choosing an AI-managed SOC partner is not just a question of who has the strongest AI story. It is a question of who can operationalize AI in a way that is visible, controlled, and accountable once the service is live. In this blog, we look at what security leaders should actually evaluate when comparing AI-managed SOC partners, and why trust in the model depends more on workflow design than on claims of autonomy.

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp9003nhku2jdwfs8tf

Hugging Face fights AI hacks, World Cup streamers get red cards, WordPress enters a patching race

Hugging Face fights AI hacks with AI World Cup streamers get a red card WordPress enters a patching race Get the show notes here: Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp9003ohku2u62tpatd

Fairlife dairy cyberattack, ACR Stealer surge, Abbott Labs incidents

Dairy company Fairlife suffers cyberattack Microsoft warns of surge in ACR Stealer attacks on customers Abbott Labs investigates two cyber incidents amid extortion claims Get the show notes here: https://cisoseries.com/cybersecurity-news-fairlife-dairy-cyberattack-acr-stealer-surge-abbott-labs-incidents/ Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision…

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp9003phku2a4rxeobi

The Department of Know: CMMC suspended, ShareFile shutdown, Context Bombing strikes back

"Context Bombing" flips the script on prompt injections Pentagon suspends CMMC Phase II requirements Old tech, new problems Get the show notes here: https://cisoseries.com/the-department-of-know-cmmc-suspended-sharefile-shutdown-context-bombing-strikes-back/ This week's Department of Know is hosted by Rich Stroffolino, with guests Tom Hollingsworth, networking technology advisor, Futurum Group, and Mark Eggleston, former CISO, CSC. Missed the live show? Check it out on YouTube. The Department…

Also reported by 1 other source
Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e0329hmu2kuy7942t

The Estée Lauder Companies (Oracle): data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 07/17/2026. Date of breach: 08/09/2025. 2,110 Washington residents affected. Information compromised: Name; Social Security Number; Financial & Banking Information; Full Date of Birth; Passport Number; Medical Information; Other.

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp9003qhku2wcj1lga5

ClickLock's kill loops, TELEPUZ ClickFix tricks, 1Password's agentic login

ClickLock stealer uses kill loops to force password entry TELEPUZ malware uses ClickFix to steal data and run commands 1Password's new Agentic Mode lets Claude log into accounts Notes: https://cisoseries.com/cybersecurity-news-clicklocks-kill-loops-telepuz-clickfix-tricks-1passwords-agentic-login/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind…

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e032chmu2s1neq8tx

DentaQuest, LLC: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 07/16/2026. Date of breach: 05/17/2026. 148,300 Washington residents affected. Information compromised: Name; Social Security Number; Full Date of Birth; Health Insurance Policy or ID Number; Medical Information; Protected Health Information owned or licensed by a HIPAA covered entity.

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp9003rhku20mk2qvqo

Zoom's wake-up call, zero-day SonicWall patch, 23andMe's growing breach bill

Zoom's account takeover wake-up call Two zero-days, one urgent SonicWall patch 23andMe's breach bill keeps growing Show Notes: https://cisoseries.com/cybersecurity-news-zooms-wake-up-call-zero-day-sonicwall-patch-23andmes-growing-breach-bill/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind…

KrebsOnSecurity·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1ycq0012hnu2fel0146r

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp9003thku2voh7gf1y

Russia's router access routes, MemGhost haunts AI memory, DHS alert got waved off twice

Russia's router access routes MemGhost haunts AI memory DHS alert got waved off… twice Get the show notes here: https://cisoseries.com/cybersecurity-news-russias-router-access-routes-memghost-haunts-ai-memory-dhs-alert-got-waved-off-twice/↗ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption. Behind AI. Behind automation. And behind…

KrebsOnSecurity·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1ycq0013hnu25m8aud90

Lessons Learned from CISA’s Recent GitHub Leak

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb.

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp9003uhku22ojbxumc

Multifunction Windows backdoor, NSA revives TAO, urgent ShareFile warning

Windows backdoor stuffs multiple wipers and ransomware code into a single package NSA brings back Tailored Access Operations name for elite hacking unit Progress urges ShareFile customers to shut down storage zone controllers Show notes: https://cisoseries.com/cybersecurity-news-multifunction-windows-backdoor-nsa-revives-tao-urgent-sharefile-warning/ Huge thanks to our sponsor, ThreatLocker Every security leader is being asked the same question right now: How do we enable innovation without…

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzpa003vhku2l3ltv4jr

The Department of Know: France gets ready for quantum, JadePuffer ransomware, UK's Cyber Shield

Link to the episode This week's Department of Know is hosted by Rich Stroffolino, with guests Davi Ottenheimer, principal, Flying Penguin, and Chris Ray, field CTO, GigaOm. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news:…

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzpa003whku2psnwsf3n

Interpol's global fraud sweep, China's Claude Code flag, old Github account tricks

Interpol's fraud sweep goes global China flags Claude Code Old GitHub accounts, new tricks Get the show notes here: https://cisoseries.com/cybersecurity-news-interpols-global-fraud-sweep-chinas-claude-code-flag-old-github-account-tricks/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring the risk,…

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzpa003xhku2b8hdb6fc

Mexico's big cyber test, Roundcube mailserver snooped on, Cash App found lax

Mexico's first cyber test gets tested Snoops break into Roundcube mailservers Cash App owner pays up over lax security Get the show notes here: https://cisoseries.com/cybersecurity-news-mexicos-big-cyber-test-roundcube-mailserver-snooped-on-cash-app-found-lax/ Thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also your 67th security blind spot. The good news: The Vanta Agent works like a GRC engineer in the background, finding every app your team…