BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtuigdjo046thmu2dlqcxf3o

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel…

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtu1zjt10gaqhmu2vcxkxmnt

SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise

Ninety-five percent of organizations believe they have visibility into their AI and machine identity exposures, yet only 36% are actually monitoring them. SpyCloud, the leader in identity threat protection, today released its annual SpyCloud Identity Threat Report, a survey-based study finding that non-human identities (NHIs) – the AI agents, service accounts, API keys, and authentication tokens that connect to internal systems – have become the most common route attackers take into the…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtu3rts40hz0hmu22euc4vq7

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters more

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtu1ce880fphhmu2gwspdrrh

ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel

A flaw in OpenAI’s ChatGPT allowed attackers to extract data from a victim’s connected Gmail account by passing hidden instructions between separate user sessions, according to research from Check Point. In a proof-of-concept, Check Point demonstrated that a victim’s ChatGPT session could retrieve email data and relay it to an attacker-controlled session within a single, seemingly normal interaction. “Check Point Research discovered a covert cross-account command channel through which an…

CSO Online·6 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtu0p8ep0f2uhmu21l3qkkuz

ShinyHunters claims Florida DMV breach, puts data on the clock

ShinyHunters is claiming to have broken into a Florida government database containing sensitive information on the state’s drivers. The notorious extortion group said it has breached the Florida Department of Highway Safety and Motor Vehicles’ Driver and Vehicle Information Database (DAVID) and claims to have stolen more than 200,000 records. As evidence, the attackers published a screenshot of a record belonging to Jeffrey Epstein that showed sensitive information, including an address, Social…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtu0rsva0f52hmu2gbgjiei7

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtu0rsva0f53hmu2bzrqw4y3

Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttxqhqi0c9ghmu2updw3uiz

When the prompt becomes the payload: A practical pen-testing guide for GenAI, LLM and RAG applications

Generative AI has moved well beyond the stand-alone chatbot. It now drafts code, searches internal knowledge, reviews contracts, opens support cases and, in some deployments, takes action through connected tools. That broader role changes the security question. A tester is no longer looking only for a model that will say something it should not. The real concern is whether manipulated language can reach protected data or trigger an unauthorized business action. That makes an LLM application…

SecurityWeek·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttxk2jt0c5yhmu2x8w609ul

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek.

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtu0rsva0f54hmu2bp55ok9t

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttw21wa0ap8hmu2vkyiz0d6

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to

CSO Online·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttvlbyd0a9jhmu2pyk62trs

Post-quantum cryptography adoption and the national security implications

Quantum computers have advanced significantly in capability and compute power in the last several years and are turning theoretical vulnerabilities in modern cryptography into real-world threats. The shift to post-quantum cryptography (PQC) needs to start now, but several challenges need to be overcome. One is: How do you convince people of the urgency that this not-quite-ready new technology represents? I will argue that this technology will favor the nation-state actors over cyber criminals…

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttub17n091shmu20tz0zm5p

50% of CISOs see Mythos as a sign to exit the profession

CISOs already have it tough, but the straw that breaks the back of many IT security executives may be the rapidly advancing capabilities of frontier AI models, enterprise insistence on rapid and widespread AI experimentation, and the compounding risk responsibilities and personal liabilities surrounding all that. “There are days where it feels exhausting,” says one CISO at a large enterprise in the software industry, who did not want to be quoted by name. “There are days when it feels like this…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttw21wa0ap9hmu2nilznnnq

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.

Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttsrriv07lvhmu2ixdgmwe4

AI Across the SOC: Investigate Faster Without Adding More Tools

An OnDemand Webinar from Elastic The security operations center (SOC) is more interconnected — and more complex — than ever. As security teams manage an expanding ecosystem of security tools and data, the challenge isn't just in detecting threats, but in harnessing insights wherever they live.