BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Also reported by 1 other source (2 articles)
The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5l0eg39lh5hpu2da56u6nc

CISO's Expert Guide to Agentic Pentesting for Websites

Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one at production. TL;DR Exploitation is now the front door. It starts 31% of breaches (Verizon DBIR

r/sysadminReddit·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rdb81013zhmu2tp01nzc2

Story Time: The time 'summer break' caused a major systems outage....

War story time - this was 'some years back' when I worked at a large mostly office enterprise org as a 'storage engineer'. We had some big EMC storage arrays - Symmetrix DMX - which I still remember fondly as a time when they were nigh on indestructible. Running mostly on SAS drives with big and clever RAM caches, because SSDs barely existed (I mean, technically they did, but they certainly weren't widespread in enterprise systems at this time). About this time of year - September, when the…

The Hacker News·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5l0eg39lh6hpu2i167bqpi

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News

The Hacker News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5l0eg39lh7hpu2hktrc850

OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads

OpenAI on Wednesday disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to improve transparency. "As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu59tum39942hpu2adnf8mq8

16 governance tools for securing your AI fleet

Every DevOps team member knows that dealing with an AI is like being a circus lion tamer. The boss and the audience are happy when the lions sit on the pedestal and roar on cue, but there’s always the danger that they’ll go rogue and bring the whole show to a quick and disastrous end. The reality is that running LLMs in production means being ready to handle hallucinations, data leakage, misinformation, madness, or worse. Lately, a range of companies have emerged to offer tools, platforms, and…