BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

The Hacker News·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtva7lsj0zp3hmu2yaw40h0f

Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company said the incident dates back to January 2026 and involved an early version of Claude Opus 4.6 that breached "

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp5002ghku2617p8lys

Fortinet auth holes, China distills AI, Mythos vulnerability

Fortinet plugs two critical auth holes US says China is distilling AI at scale Mythos vulnerability hits human bottleneck Get the show notes here: https://cisoseries.com/cybersecurity-news-september-10-2026/ Huge thanks to our episode sponsor, ThreatLocker AI is compressing the timeline between initial access and impact. That leaves security teams less time to identify, investigate, and contain malicious activity. Faster response helps, but prevention can remove actions from the attack chain…

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtuylnjw0mhchmu22sv1s8z8

Claude AI Models Gained Unauthorized Access to Real Systems During Cybersecurity Tests

Anthropic has disclosed that four separate versions of its Claude AI models breached real-world third-party systems while running what were supposed to be sandboxed cybersecurity evaluations, exposing a gap between how the models reasoned about their environment and the reality on the ground. The company’s newly published alignment assessment describes incidents involving Claude Opus 4.6, […] The post Claude AI Models Gained Unauthorized Access to Real Systems During Cybersecurity Tests…

Graham Cluley·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtuqvvig0do9hmu29ae3umkl

Smashing Security podcast #484: How websites are tracking you with silence

When a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one of the sneakiest tracking tricks on the web. Meanwhile, the intelligence agencies of the "Five Eyes" (not Five Guys) have got together and published advice on how companies should communicate after a…

BankInfoSecurity.com·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtup4v840bo9hmu2nj0jr5xg

FBI Strategy Calls for More Takedowns, Better Info-Sharing

Bureau Won't 'Sit and Wait for the Best Opportunity,' Says FBI's Leatherman The FBI vowed Wednesday to crack down on ransomware gangs and online scammers in a first-ever public cybercrime strategy that also said the bureau will prioritize working with victims and work more with private sector partners to take down criminal computer infrastructure.

Also reported by 1 other source
BankInfoSecurity.com·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtumzpfa097chmu2naxa9hlb

State CIOs Need an Enterprise Identity Strategy

NASCIO’s Eric Sweden on Balancing Security, Privacy and Citizen Access Fragmented identity systems make government harder to use and can obscure fraud across agencies. NASCIO’s Eric Sweden explains how states can build shared trust, protect privacy and adapt identity infrastructure for digital wallets, deepfakes and AI agents.

Also reported by 1 other source
BankInfoSecurity.com·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtumzpfa097bhmu21ylurwpm

Watchdog Finds Critical Access Control Gaps at CBP

DHS Inspector General Finds CBP Left Privileged Account Open to All Network Users A U.S. Customs and Border Protection service account with elevated privileges was reachable by the agency's entire workforce of more than 76,000 users, and auditors mapped more than 100 attack paths through the network, according to a new Department of Homeland Security watchdog report.

Also reported by 1 other source
BankInfoSecurity.com·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtumzpfa097ahmu2dx8pmj44

Factor Accuses SecurityScorecard of Retaliation Campaign

Factor Complaint Alleges False IP Claims, Threats and Commercial Interference Factor Cybersecurity sued SecurityScorecard over alleged business interference, claiming false IP accusations, retaliation and interference with employees, partners and investors cost Factor prospective business and delayed a funding round targeted at $25 million.

Also reported by 1 other source
CyberScoop·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtulujma07vihmu2spdhgn0a

Chinese espionage groups swarm to exploit triple-link chain of zero-days

Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen. The post Chinese espionage groups swarm to exploit triple-link chain of zero-days appeared first on CyberScoop.

BankInfoSecurity.com·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujrzd805jrhmu29v49o317

Why Enterprises Need AI FinOps, Security to Scale Responsibly

Enterprises Need Unified Cost and Security Controls to Scale AI Agents Responsibly AI agents can run up costs and expand security risks faster than traditional governance can respond. Companies need real-time visibility into every model call, tool invocation and agent action, linking spending, access and outcomes so finance and security teams can control AI jointly from the start.

BankInfoSecurity.com·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujrzd805jqhmu24x1zyoeo

Your AI Didn't Lie to You: It Was Just Being Manipulated

Hidden AI Activity Creates Security Gaps That Traditional Controls Can't Detect As AI agents gain access to critical business systems, prompt injection, shadow AI and poisoned data can manipulate decisions without triggering traditional controls. Full-pipeline telemetry and continuous testing can help security teams investigate incidents while maintaining human accountability.

BankInfoSecurity.com·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujrzd805jphmu273728uip

How Recent Cyber Earnings Show Growth Alone No Longer Pays

Faster Hiring Coincided With Weaker Stock Performance Across Most Security Vendors Seven of eight major cyber and technology vendors posted at least 25% annual year-over-year sales growth, but five stocks fell after earnings as investors favored profitability while CEOs outlined how AI agents will reshape security, identity and enterprise infrastructure.

BankInfoSecurity.com·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujrzd805johmu2ue4fisi4

Why Proofpoint Is Eyeing a Buy of Data Security Firm Varonis

Deal Would Fill Gaps in Proofpoint's Data Security Portfolio, Give Varonis an Exit Proofpoint is in talks to acquire Varonis, with Bloomberg reporting a deal could be announced in the coming weeks - assuming the talks don't fall apart. A Proofpoint-Varonis deal would be the largest pure-play cybersecurity purchase in 2026, dwarfing Accenture's proposed $3.25 billion buy of Dragos.