BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu10q0pn4k0xhpu2ts0o7e9a

What the 3M ChatGPT case reveals about AI governance

One detail in the Watson Grinding explosion litigation involving 3M changed the way I think about prompt governance. An engineering expert retained by 3M had been using ChatGPT while developing his analysis, and among the conversations that later surfaced was a prompt telling the system to “show how 3M is 0% at fault.” The reporting does not establish that 3M instructed the expert to use ChatGPT or directed him to enter that prompt, and that distinction matters. What matters just as much is…

Also reported by 1 other source
CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu0zfq2m4ilthpu2jrnb7l2m

How to level up from security pro to security leader

There comes a time in a cybersecurity professional’s life when being a tech expert is no longer enough. The next step may lead to management or the C-suite, but the goal demands a different kind of expertise. Technical skills will continue to serve a new CISO well, but the role demands additional capabilities built on that foundation. That may mean prioritizing investments amid tight budgets or helping business leaders weigh the security tradeoffs behind a product launch. “The strongest CSOs…

The Hacker News·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu0z5fvy4i9lhpu2oy59vqe3

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla Firefox Add-Ons store - Chrome -

Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp5002dhku21d3opmg2

Passkey phishing attack, Anthropic's blockbuster report, airline cybersecurity loophole

Attackers use passkey phishing to hijack Microsoft cloud accounts Anthropic blockbuster report reveals sophisticated hacks Airlines compliance with new cybersecurity regulations means fewer passenger conveniences Get the show notes here: https://cisoseries.com/cybersecurity-news-september-14-2026/ Huge thanks to our episode sponsor, Vanta Risk and regulation ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust…

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu00aanx3fq0hpu2z9cbtpdj

Critical Dell ObjectScale Vulnerabilities Allows Malicious Users to Compromise the Affected system

Dell Technologies released a security advisory about multiple vulnerabilities affecting Dell ObjectScale and Elastic Cloud Storage (ECS) deployments. Including a critical remote code execution flaw that could let an unauthenticated attacker compromise vulnerable systems. The advisory, tracked as DSA-2026-393, was published on September 10, 2026. The most severe issue is CVE-2026-70416, a critical untrusted-data deserialization […] The post Critical Dell ObjectScale Vulnerabilities Allows…

SecurityWeek·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtzutjhc39ovhpu2pwxee1ec

Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up

Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet. The post Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up appeared first on SecurityWeek.

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtznurln31rehpu2049r9zfc

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtzco8mz2oy5hpu25u8zilhj

Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers

A newly disclosed vulnerability in Plesk Backup Manager could allow low-privileged users to escalate privileges and gain full root access on affected Linux servers. Tracked as CVE-2026-68488, the flaw stems from a symlink race condition during subscription-content restore operations. The issue affects Plesk Obsidian installations running Plesk for Linux versions 18.0.80.6 and earlier, as well […] The post Plesk Backup Manager Flaw Lets Low-Privileged Users Gain Root Access to Servers appeared…

Also reported by 1 other source
The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtynpbks1wiyhpu2lgcx6pfc

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows - CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtyhmp5n1pm2hpu2oj9l2mmf

Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory

Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory. The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0 through 3.0.23 and require a victim to open a specially crafted media file or playlist entry. Fabian Wahle of Hap […] The post Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory appeared first on Cyber Security News.

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtya5xb81h4dhpu2sqqs2lou

Containing Machine Speed Cyber Attacks Inside AI Infrastructure

A critical flaw in current security operations is assuming time is on our side. Historically, attacks progressed slowly, allowing analysts and response teams time to detect, discuss, and respond. Even severe incidents operated at a human pace. Our defenses have relied on human error, human speed, and human limitations. That era is over. AI-driven adversaries […] The post Containing Machine Speed Cyber Attacks Inside AI Infrastructure appeared first on Cyber Security News.

Cyber Security News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmty9is1t1gdnhpu2q7g0hyvt

Beyond the Perimeter: Building Resilience Against Cloud and SaaS Supply-Chain Attacks

A critical zero-day vulnerability in Oracle PeopleSoft exposed the Council of Europe and scores of other organizations to data theft and extortion in May and early June 2026. The ShinyHunters hacking group exploited the flaw across about 100 organizations and 300 instances worldwide, according to reports cited by The Register. The attackers targeted the management and configuration layers of enterprise resource-planning systems, stealing sensitive records. […] The post Beyond the Perimeter:…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmty9zhr71gwghpu24pk8nyfm

When the Whole Company Adopts AI: What It Does to Your SOC

Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and non-technical staff signing consumer AI tools into corporate