BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e031fhmu2dcpjpe14

Pan American Group LLC: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 08/24/2026. Date of breach: 04/08/2026. 12,309 Washington residents affected. Information compromised: Name; Social Security Number; Driver's License or Washington ID Card Number; Financial & Banking Information; Full Date of Birth; Unique Private Key (e.g. used to authenticate or sign an electronic record); Student ID Number; Military ID Number; Passport Number; Health Insurance Policy or ID Number; Medical Information; Biometric Data; Username…

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7002vhku20bbydqi2

UK power plant hack, AI zero click, children's hospital breach

UK power plant disabled for four days by Iran-linked hackers Zero-click Grok and Gemini chat history theft possible through cryptographic context injection Canada's Hospital for Sick Children suffers another cyberattack Get the show notes here: https://cisoseries.com/cybersecurity-news-uk-power-plant-hack-ai-zero-click-childrens-hospital-breach/ Huge thanks to our episode sponsor, ThreatDown SMBs face enterprise-level, AI-driven threats every day, often sacrificing robust security in favor of…

Troy Hunt·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl4j1w00ebhmu21y50yfi4

Welcoming the Sri Lankan Government to Have I Been Pwned

Today, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri Lanka. Sri Lanka CERT now has access to monitor Sri Lankan government domains against the data in HIBP, helping identify exposed government accounts and respond when they appear in new data breaches.

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7002whku2rm7rcsnm

The Department of Know: Living off Azure, OpenAI's "defender window," and AI-driven PLC attacks

Read the full sotry at CISOSeries.com This week's Department of Know is hosted by Rich Stroffolino, with guests Bil Harmer, CISO, Supabase, and David B. Cross, CISO, Atlassian. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, Vanta Still stuck on the quarterly audit treadmill? Meet Calm-pliance. Vanta combines compliance, risk, and…

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e031ghmu2iy4q08vf

ASOS US Sales LLC: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 08/21/2026. Date of breach: 07/28/2026. 1,929 Washington residents affected. Information compromised: Name; Financial & Banking Information; Full Date of Birth; Email Address and Password/Security Question Answers.

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7002xhku24vmngxu4

CISA MLFlow warning, Siemens PLCs warning, CareCloud confirms breach

CISA warns of hackers exploiting critical MLflow vulnerability ICS operators warned of AI-driven attacks on Siemens PLCs Electronic health record company CareCloud confirms millions affected by breach Get the show notes here: https://cisoseries.com/cybersecurity-news-cisa-mlflow-warning-siemens-plcs-warning-carecloud-confirms-breach/ Huge thanks to our sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance,…

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e031ihmu2fu2qvw2r

Rockwood Retirement Communities (Spokane United Methodist Homes): data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 08/20/2026. Date of breach: 02/15/2026. 7,136 Washington residents affected. Information compromised: Name; Social Security Number; Driver's License or Washington ID Card Number; Financial & Banking Information; Full Date of Birth; Passport Number; Health Insurance Policy or ID Number; Medical Information; Email Address and Password/Security Question Answers; Protected Health Information owned or licensed by a HIPAA covered entity.

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7002yhku2bhwrtqr1

OpenAI rewrites safety rules, US charges 17 Iranian hackers, Defender crashes fixed

OpenAI rewrites safety rules after threshold warning US charges 17 in Iranian hacking campaign Microsoft fixes Windows Defender crash bug Get the show notes here: https://cisoseries.com/openai-safety-rules-iranian-hackers-defender-crashes/ Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects compliance, risk, and trust at…

Graham Cluley·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl38q700duhmu224gofknx

Smashing Security podcast #481: Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold statuettes of Mozart have vanished from the streets. This has happened to the same artist before.…

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e031jhmu2992m1960

Nebraska Orthopaedic Center (Aesto, LLC): data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 08/19/2026. Date of breach: 12/02/2025. 992 Washington residents affected. Information compromised: Name; Social Security Number; Full Date of Birth; Medical Information.

Graham Cluley·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl38q700dvhmu2g3rcnb9k

Prison for data analyst who tried to extort $2.5 million from his employer

When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume. But what the 27-year-old from Charlotte, North Carolina, did instead was turn to extortion. Read more in my article on the Hot for Security blog.

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7002zhku2vhupcu1r

AI "mind virus," malware living off Azure, an Irregular post-mortem

Persistent prompts prove potentially pernicious The malware is coming from inside Microsoft Irregular releases AI sandbox escape post-mortem Get the show notes here: https://cisoseries.com/cybersecurity-news-ai-mind-virus-living-off-azure-an-irregular-post-mortem/ Huge thanks to our sponsor, Vanta Your GRC team is dealing with more and more frameworks, vendors, and risk. The board wants it all in one place, but your compliance data lives all over. Vanta's agentic trust platform connects…