BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7003ehku2reb1wvj4

Analog Devices breach, Copilot AI worm, Teams ransomware vishing

Semiconductor firm Analog Devices discloses data breach Copilot for Word POC copies hidden prompts into new documents Microsoft Teams vishing attacks lead to Chaos ransomware attacks Get the show notes here: https://cisoseries.com/cybersecurity-news-analog-devices-breach-copilot-ai-worm-teams-ransomware-vishing/ Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice.…

KrebsOnSecurity·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1ycq0010hnu273ch24pe

Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e031yhmu2vmqaxt1o

Microcode, Inc. (CommonSpirit Health): data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 07/30/2026. Date of breach: 01/19/2026. 4,096 Washington residents affected. Information compromised: Name; Social Security Number; Driver's License or Washington ID Card Number; Financial & Banking Information; Full Date of Birth; Passport Number; Medical Information.

Graham Cluley·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl38q700e4hmu2yo755x9v

North Korea’s elite hackers turned on their own government – and got caught

For years, North Korea's state-trained hackers have been one of the world's most prolific robbers of banks - stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country's weapons programme. But now, in a remarkable twist, some of the same elite hackers appear to have decided to rob their own government instead. And, it doesn't sound as if it has ended that well for them. Read more in my article on…

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7003fhku26a24mx2a

OpenAI agent reaches Modal, Minnesota water systems hacked, fake Russian companies steal real money

OpenAI agent's escape reaches a Modal customer Hackers hit Minnesota water systems Fake Russian companies, real stolen money Get the show notes here: https://cisoseries.com/cybersecurity-news-openai-agent-reaches-modal-minnesota-water-systems-hacked-fake-russian-companies-steal-real-money/ Huge thanks to our sponsor, Pindrop TIME named Pindrop one of the 10 Most Influential Software Companies of 2026. Deepfakes slip into your video meetings, contact centers, and hiring pipelines. Pindrop…

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7003ghku20qf6r28e

Leaky BMCs, Claude finds encryption flaws, Google's new names

Thousands of server BMCs leak password hashes Claude finds flaws in encryption Google gives old threat actors new names Get the show notes here: https://cisoseries.com/cybersecurity-news-leaky-bmcs-claude-finds-encryption-flaws-googles-new-names/ Huge thanks to our sponsor, Pindrop AI attacks on the enterprise are skyrocketing. Is your tech stack keeping up? Deepfake and synthetic voices are slipping through a channel your defenses were never built to cover—stealing credentials and exposing…

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7003hhku250uzsqzo

Nvidia opens AI security tent, Microsoft adds cyber sprinter to MDASH, Fairlife ransomware spills data

Nvidia opens the AI security tent Microsoft puts a cyber sprinter in MDASH Fairlife ransomware spills data Get the show notes here: https://cisoseries.com/cybersecurity-news-nvidia-opens-ai-security-tent-microsoft-adds-cyber-sprinter-to-mdash-fairlife-ransomware-spills-data/ Huge thanks to our sponsor, Pindrop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction—it happened. Deepfake video. AI voice. Completely convincing. It could be…

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e0321hmu25mvjhs7k

JRK Property Holdings, Inc.: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 07/27/2026. Date of breach: 03/26/2026. 5,667 Washington residents affected. Information compromised: Name; Social Security Number; Driver's License or Washington ID Card Number; Financial & Banking Information; Military ID Number; Passport Number; Other.

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7003ihku2wp9zut1o

Iran infrastructure warning, ChatGPT global outage, self-assembling malware

U.S. agencies warn of Iran-linked actors targeting water and energy control systems ChatGPT suffered brief global outage on Saturday Malvertising sends malware in pieces for an unsuspecting browser to build Get the show notes here: https://cisoseries.com/cybersecurity-news-iran-infrastructure-warning-chatgpt-global-outage-self-assembling-malware/ Huge thanks to our sponsor, Pindrop Your hiring processes are the newest entry point for security risks. Pindrop's data shows one in six engineering…

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7003jhku2fjyptzer

The Department of Know: OpenAI hacks Hugging Face, Chinese LLM ban, Kratos takedown

This week's Department of Know is hosted by Rich Stroffolino, with guests Nick Espinosa, host, Deep Dive Radio Show, and Dennis Pickett, vp, CISO, Westat. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission…

Also reported by 1 other source
Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e0324hmu2ocwh0ums

Eyemart Express, LLC: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 07/24/2026. Date of breach: 02/12/2026. 1,704 Washington residents affected. Information compromised: Name; Social Security Number; Driver's License or Washington ID Card Number; Financial & Banking Information; Full Date of Birth; Passport Number; Health Insurance Policy or ID Number; Medical Information; Protected Health Information owned or licensed by a HIPAA covered entity.

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e0323hmu2b1yolpde

CareCloud, Inc.: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 07/24/2026. Date of breach: 03/10/2026. 20,706 Washington residents affected. Information compromised: Name; Social Security Number; Driver's License or Washington ID Card Number; Financial & Banking Information; Full Date of Birth; Health Insurance Policy or ID Number; Medical Information.

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e0322hmu2j2ly2lgd

Bridgeway Benefit Technologies LLC: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 07/24/2026. Date of breach: 03/05/2026. 640 Washington residents affected. Information compromised: Name; Social Security Number; Full Date of Birth; Other; Protected Health Information owned or licensed by a HIPAA covered entity.

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp9003khku2yp5u188h

AI agents risk, Upbound Group breach, Dolphin X Stealer

AI Agents become fastest growing exposed attack surface Consumer finance company Upbound Group blames data breach for millions in losses Dolphin X Stealer uses AI profiling to prioritize targets Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-agents-risk-upbound-group-breach-dolphin-x-stealer/ Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had.…

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e0326hmu2w9dgpkjj

Safetyfirst Systems, LLC: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 07/23/2026. Date of breach: 01/16/2026. 1,157 Washington residents affected. Information compromised: Name; Social Security Number; Driver's License or Washington ID Card Number; Full Date of Birth.

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e0325hmu28nly5e3m

The Moody Bible Institute of Chicago: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 07/23/2026. Date of breach: 06/12/2026. 8,955 Washington residents affected. Information compromised: Social Security Number; Driver's License or Washington ID Card Number; Full Date of Birth.

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp9003lhku2zae6u26f

OpenAI behind Hugging Face hack, TrickBot tunnels through DNS, Acrobat extension opens WhatsApp

OpenAI behind Hugging Face hack TrickBot tunnels through DNS Acrobat extension opens WhatsApp Get the show notes here: Huge thanks to our sponsor, QuilrAI AI agents don't ask permission. They act -- moving data, triggering workflows, changing systems. QuilrAI is the permission layer they never had. Its Decision Engine evaluates the content, context, and intent of every action - before it completes. Alerts tell you later. QuilrAI decides now. Visit quilr.ai.

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e0327hmu2jdl8hjtw

Kootenai County, Idaho: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 07/22/2026. 746 Washington residents affected. Information compromised: Name; Social Security Number; Driver's License or Washington ID Card Number; Full Date of Birth; Health Insurance Policy or ID Number; Medical Information; Biometric Data.