BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttw21wa0apahmu2i447ny7i

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are

Cyber Security Headlines·6 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp5002hhku22ed83ne5

Florida DMV breach, zero-click WeChat worm, AI whistleblowers

ShinyHunters claimed it breached Florida DMV Zero-click WeChat worm spreads over incoming calls AI cheaters and whistleblowers emerge Get the show notes here: https://cisoseries.com/cybersecurity-news-florida-dmv-breach-zero-click-wechat-worm-ai-whistleblowers/ Huge thanks to our episode sponsor, ThreatLocker Attackers do not always bring their own tools. AI can help them find ways to misuse software already trusted by the organization. Today's tip: approval should not mean unlimited access.…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttw21wa0apbhmu2sli1gtab

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic

The Hacker News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttw21wa0apchmu2bhj9ix36

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP

The Hacker News·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttpeutg04fkhmu245n754si

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.

The Hacker News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttm74b701ejhmu2k3otx1tt

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a

Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl1ysk00dihmu2ul8xpja3

Why Enterprises Need AI FinOps, Security to Scale Responsibly

Enterprises Need Unified Cost and Security Controls to Scale AI Agents Responsibly AI agents can run up costs and expand security risks faster than traditional governance can respond. Companies need real-time visibility into every model call, tool invocation and agent action, linking spending, access and outcomes so finance and security teams can control AI jointly from the start.

Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl1ysk00dhhmu2iwagavez

Your AI Didn't Lie to You: It Was Just Being Manipulated

Hidden AI Activity Creates Security Gaps That Traditional Controls Can't Detect As AI agents gain access to critical business systems, prompt injection, shadow AI and poisoned data can manipulate decisions without triggering traditional controls. Full-pipeline telemetry and continuous testing can help security teams investigate incidents while maintaining human accountability.

Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl1ysk00dghmu2kw375wt0

How Recent Cyber Earnings Show Growth Alone No Longer Pays

Faster Hiring Coincided With Weaker Stock Performance Across Most Security Vendors Seven of eight major cyber and technology vendors posted at least 25% annual year-over-year sales growth, but five stocks fell after earnings as investors favored profitability while CEOs outlined how AI agents will reshape security, identity and enterprise infrastructure.

Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl1ysk00dfhmu2tvvmuqyw

Why Proofpoint Is Eyeing a Buy of Data Security Firm Varonis

Deal Would Fill Gaps in Proofpoint's Data Security Portfolio, Give Varonis an Exit Proofpoint is in talks to acquire Varonis, with Bloomberg reporting a deal could be announced in the coming weeks - assuming the talks don't fall apart. A Proofpoint-Varonis deal would be the largest pure-play cybersecurity purchase in 2026, dwarfing Accenture's proposed $3.25 billion buy of Dragos.

Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl1ysk00dehmu2o2rdrcq4

Addressing Quantum Readiness in Healthcare Security

Healthcare organizations should prepare for post-quantum cryptography without overreacting to hype, said John Frushour, CISO of New York-Presbyterian Hospital. Stronger encryption standards, commercial software support and attention to medical devices can help providers manage emerging risks.

Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl1ysj00ddhmu2enbixg32

How Cloud Security Risks Grow With Home-Based Care

As hospital-at-home programs expand and AI adoption accelerates, healthcare organizations face mounting cloud security demands. Anahi Santiago, CISO of ChristianaCare, discusses vendor accountability, identity management, clinical AI risks and the need for stronger cybersecurity foundations.

Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl1ysj00dchmu26ma7frp8

How Renown Health Is Reshaping Its Digital ID Strategy

Renown Health is reshaping digital ID management with a strategy that reduces friction for clinicians, strengthens security and prepares the organization for emerging AI-driven identity challenges, said Steven Ramirez, Renown Health's chief information security and technology officer.

Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl1ysj00dbhmu2h5y8thqi

How Agentic AI Is Reshaping the Modern SOC

Agentic AI is redefining security operations by embedding intelligence across detection, investigation and response. Optiv's Ben Spencer and Google Cloud's Wayne Kearns explain how AI-powered SOCs strengthen defense, why human expertise is essential and how MSSPs can accelerate enterprise adoption.

Data Breach Today·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttl1ysj00d3hmu2b1kwz1ra

Annual Report to Congress on Breaches of Unsecured Protected Health Information

The Department of Health and Human Services' Office for Civil Rights provided a report to Congress on health information breaches from September 2009 through 2010, as required under the HITECH Act. Nearly 7.9 million Americans were affected by almost 30,800 health information breaches, according to the report.