BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Cyber Security News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtwg43by2bhmhmu2so9uwhmb

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Spy Through Microphone

A security vulnerability in Skullcandy Dime 3 wireless earbuds could allow nearby attackers to pair with the device without the owner’s approval, hijack audio playback, and potentially capture live microphone audio. Tracked as Vulnerability Note VU#859658, the issue affects Skullcandy Dime 3 earbuds (model S2DCW) running firmware version 1.0.0.28. The flaw was publicly disclosed on […] The post Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Spy Through Microphone…

Cyber Security News·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtwcon8h27myhmu2r1hzmjms

Hackers Use Claude AI Agents to Automate Cyberattacks, Develop 0-Days and Evade Detection

Anthropic’s Threat Intelligence team has disclosed a sweeping new report detailing how state-sponsored espionage groups, financially motivated cybercriminals, and lone hacktivists weaponized its Claude AI models to automate entire cyberattack chains, generate zero-day exploits, and dynamically rewrite malware to slip past security defenses. The findings, covering activity disrupted between December 2025 and August 2026, mark […] The post Hackers Use Claude AI Agents to Automate Cyberattacks,…

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtw9gwzc23yyhmu2vnl798vf

Attackers are weaponizing the gap between Chromium fixes and Chrome patches

A new exploit kit is revealing the perils of the “patch later” mentality. According to the Proofpoint Threat Research team, espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities to allow them to launch targeted spear phishing campaigns. Proofpoint, which researched the new attack method along with Google’s Threat Intelligence Group, Microsoft’s Threat Intelligence Center, and cybersecurity company…

BankInfoSecurity.com·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtw4jg6b1ydnhmu24achzqme

TRM Labs Lands $2B Valuation as AI Expands Investigations

TRM Platform Uses AI to Marry Blockchain Data With Registries, Threat Intelligence TRM Labs reached a $2 billion valuation as it uses AI to combine blockchain transactions with ownership, corporate and threat intelligence data, giving investigators a broader view of criminal and nation-state networks and potential points for disruption.

Also reported by 1 other source
BankInfoSecurity.com·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtw4jg6b1ydlhmu2jt7259qm

OpenAI Calls for Mandatory National AI Safety Rules

Frontier Lab Says Capability-Based Oversight Must Keep Pace With More Powerful Models OpenAI called for mandatory, capability-based AI regulation that evolves as the technology does, in the latest case of an AI company saying the technology can be dangerous and needs oversight.

Also reported by 1 other source
BankInfoSecurity.com·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtw4jg6b1ydkhmu2cuev6nr1

White House Touts Local First Approach to Securing Water

Texas Pilot Will Pave Way for National Expansion, Says Sean Cairncross A White House effort dubbed Project Watershed 250 that's meant to help small or rural water utilities in Texas secure their systems against hackers with free technology donated by cybersecurity vendors will expand nationwide, the country's top cyber official said Thursday.

Also reported by 1 other source
Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtw4jfqi1yd2hmu2xrj41ou8

How JPMorgan Chase Scaled Secure Software Delivery

Centralized Controls Help the Bank Secure Thousands of Daily Software Builds JPMorgan Chase centralized its container pipeline to support thousands of daily builds while detecting vulnerabilities before deployment. As AI agents accelerate coding, standardized scans, security reviews and detailed specifications help keep speed from introducing unacceptable risk.

Also reported by 1 other source
BankInfoSecurity.com·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtw2ea7n1vy3hmu2bahcan0c

Cisco Firewall Bugs Let in Sandworm, Qilin

Cisco Observed 3 Distinct Intrusion Clusters Exploiting 1 or Both Flaws Cisco says a nation-state actor and a Qilin ransomware operator are actively exploiting two Secure Firewall Management Center flaws to gain root or credential-based access, steal sensitive data, deploy Sandworm-linked malware and prepare networks for encryption.

Also reported by 1 other source
BankInfoSecurity.com·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtw095c21thphmu2d28ju259

Quantum's Bigger Threat: Forged Identities, Not Data Theft

Applied Quantum's Marin Ivezic on Why Forged Signatures Beat Stolen Data as a Risk Data theft dominates quantum risk planning, but a quieter threat could prove even worse. Marin Ivezic, CEO at Applied Quantum, says quantum computers used to forge digital signatures at some point in the future could undermine trust across IT and OT systems alike.

Also reported by 1 other source
BankInfoSecurity.com·6 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtw095c21thohmu2q8xrs7s1

Breach Roundup: ShinyHunters Claims Florida DMV Hack

Also, N-Able Patches Critical N-Central Zero-Day, Nightmare Eclipse Zero-Day This week: ShinyHunters claims Florida DMV breach, N-able patch, Bimbo Bakeries breach, French police arrest suspected ZeroBytes hackers, Patch Tuesday, a new Nightmare Eclipse zero-day, Grindr agrees to $35 million U.K. privacy settlement, SAP patch.

Also reported by 1 other source
Bleeping Computer·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtvzptbq1ssehmu2u3kpteh7

September Windows Server updates break Remote Desktop Services

Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality. [...]