BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r000mhnu2ucviz57x

Rockwell Automation Logix Platform

View CSAF Summary The following versions of Rockwell Automation Logix Platform are affected: ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) CompactLogix 5380 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) GuardLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637)…

Also reported by 1 other source (5 articles)
Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7002ohku2h9yfbie9

Claude sessions hijacked, AI jolts global finance, agents get too many keys

Claude sessions get hijacked Anthropic is warning that common infostealer malware is stealing active Claude browser sessions, letting attackers get into accounts and burn through paid usage without needing a password or two-factor code. The company is signing affected users out, removing stored payment methods and refunding unauthorized charges. But revoking the session doesn't remove the malware, so victims still need to clean the device, change credentials and revoke other active sessions.…

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1y7r000nhnu2rznijirg

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates…

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7002phku2dovbjf9e

ServiceNow vulnerabilities warning, PaperCut zero-day, McKesson healthcare breach

ServiceNow warns of three maximum severity security vulnerabilities PaperCut zero-day exploited in attacks Healthcare giant McKesson discloses breach Get the full show notes here: https://cisoseries.com/cybersecurity-news-servicenow-vulnerabilities-warning-papercut-zero-day-mckesson-healthcare-breach/ Huge thanks to our episode sponsor, KnowBe4 Your employees have always been the target, but the threats they face are evolving. AI empowers cybercriminals to clone a coworker's voice, fake a video…

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp7002qhku2qcc70zdh

The Department of Know: Power plant attack, NSA hacker reunion, Hugging Face hack report

Read the full stories at CISOSeries.com. This week's Department of Know is hosted by Rich Stroffolino, with guests Jason Elrod, CISO, MultiCare Health System, and Chris Ray, field CTO, GigaOm. Missed the live show? Check it out on YouTube. The Department of Know is live every Friday at 4:00 p.m. ET. Join us each week by registering for the open discussion at CISOSeries.com. A huge thanks to our sponsor, ThreatDown Managing an enterprise-sized attack surface without a dedicated SOC? As attackers…

Washington AG breach notices·Confirmed Breach
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu7q4v8e031ahmu2is3mrnof

RB American Group LLC: data breach notification (Washington Attorney General)

Reported to the Washington Attorney General on 08/28/2026. Date of breach: 04/08/2026. 974 Washington residents affected. Information compromised: Name; Social Security Number; Driver's License or Washington ID Card Number; Financial & Banking Information; Full Date of Birth; Unique Private Key (e.g. used to authenticate or sign an electronic record); Student ID Number; Military ID Number; Passport Number; Health Insurance Policy or ID Number; Medical Information; Biometric Data; Username and…

Graham Cluley·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl38q700dphmu2mmeorxro

Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more

More than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm - two men now face charges over TeamPCP's global hacking spree. Read more in my article on the Hot for Security blog.