BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Data Breach Today·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl1ysj00d2hmu2k38lfj7y

Better AI Returns Start With Stronger Foundations

Data Quality and Governance Help Technology Leaders Scale AI Organizations with mature AI governance and data practices were 15 times more likely to report strong returns, SAS and IDC found. As agentic AI moves into production, CIOs need explainability, oversight and reliable data to scale the technology with confidence.

Data Breach Today·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl1ysj00d1hmu2u0asw83m

FDA Pilot Gives AI Health Tools a Real-World Test Bed

4 Manufacturers Will Test Tools for Diabetes, Hypertension and Mental Health The FDA's TEMPO pilot allows selected AI-enabled health devices to reach chronic care patients before formal marketing authorization while manufacturers collect real-world evidence regulators can use to evaluate safety, performance and patient outcomes.

Data Breach Today·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl1ysj00d0hmu2b8yvdacj

US Warns Chinese AI Firms Are Illicitly Distilling Models

CISA Says DeepSeek, Alibaba and Others Extracted Billions of Tokens From US Frontier AI Systems The U.S. government warned that Chinese AI companies are illicitly distilling American-made AI models, formally acknowledging complaints from frontier labs like Anthropic and OpenAI.

Data Breach Today·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl1ysj00czhmu24hsjce4i

Ukraine Must Cultivate 'Security-Minded' Cyber Defense

Ask 'Why Has It Been Compromised?' Says Security Service of Ukraine Official Ukrainian cyber defenders, now in their fifth year of fending off a Russian invasion that includes combined cyber operations and kinetic strikes, need a more "security-minded" point of view, one of the country's top cyber defense officials said Tuesday.

Also reported by 1 other source
CSO Online·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015ehmu2flgk54ej

September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows

Possibly wormable bugs and two zero-day holes highlight the almost 1,000 fixes issued today by Microsoft in its September Patch Tuesday release. The 964 vulnerabilities, another record since Microsoft began using AI in the middle of the year to find holes, require customer action. Excluded are 174 third-party/open-source CVEs and 23 Chromium/Edge CVEs, as well as nine Microsoft mitigated vulnerabilities in applications like Azure, Entra, and Copilot Studio where no customer action is required.…

Also reported by 1 other source
CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015fhmu24sqkcmug

Cisco bundles fixes for multiple vulnerabilities, some critical, into one patch

Cisco is looking to get ahead of attackers with a new set of more than a half-dozen fixes, some of them critical, for its IOS XR Linux-based network operating system (OS). As part of its regular testing, Cisco’s software engineering team flagged “multiple internally-discovered vulnerabilities,” the company said. These flaws could allow attackers to perform remote code execution (RCE) and gain root access on a router, thereby allowing them to intercept traffic. Other potential risks could…

CyberScoop·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujqoav05gbhmu204hy4hs6

Microsoft discloses two actively exploited zero-days among 974 vulnerabilities

While the vendor hit another monthly record, it hasn’t resulted in a flood of active exploits. Researchers encourage customers to focus on their specific areas of risk and exposure. The post Microsoft discloses two actively exploited zero-days among 974 vulnerabilities appeared first on CyberScoop.

Also reported by 2 other sources
CyberScoop·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujqoav05gchmu2cd0mdeg8

Feds accuse China of ‘systematic’ distillation of U.S. AI models

A joint advisory alleges Chinese companies are using sophisticated systems to route millions of data requests to US AI models across different accounts and platforms. The post Feds accuse China of ‘systematic’ distillation of U.S. AI models appeared first on CyberScoop.

CyberScoop·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujqoav05gdhmu2e7asf8v1

Russian national extradited to US for alleged involvement in bank-account takeover scheme

Authorities accuse the 36-year-old and co-conspirators of collecting more than 5,000 victim login credentials to various banks. The post Russian national extradited to US for alleged involvement in bank-account takeover scheme appeared first on CyberScoop.

Bleeping Computer·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yfa001ghnu2lhnfp8iu

The EU CRA's Real Question: What Shipped, and When Did You Know?

The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements. [...]

CyberScoop·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujqoav05gfhmu2qtb6i63i

Why federal cyber defense demands an offense-driven mindset

Static checklists and annual penetration tests leave agencies with dangerous blind spots. True resilience requires moving from reactive attestation to continuous, automated validation. The post Why federal cyber defense demands an offense-driven mindset appeared first on CyberScoop.