BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Also reported by 3 other sources
Cyber Security Headlines·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp5002chku2cxus3hyw

China hits fast-forward on AI security, Hacking Cat shows its claws, Vite servers spill cloud secrets

China hits fast-forward on AI security Hacking Cat shows its claws Vite servers spill cloud secrets Get the show notes here: https://cisoseries.com/cybersecurity-news-september-15-2026/ Huge thanks to our episode sponsor, Vanta Risk and regulation are ramping up—and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC program,…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu2eg5ed62zmhpu275f5dgkf

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers, many customers' sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself,

The Hacker News·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu2ag43t5yjbhpu21f6aumcg

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The

CSO Online·7 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu1yrl0i5lllhpu26mq0opdi

A maximum severity GitLab flaw could turn your CI/CD server into an attacker’s treasure trove

Yet another security vulnerability has been discovered in GitLab infrastructure, this one a perfect 10 in severity. CVE-2026-85706, the second flaw GitLab has disclosed in just a month, is a maximum-severity vulnerability that allows attackers to read arbitrary files in a single HTTP request. The path traversal flaw results from improper confinement and lack of authentication enforcement in GitLab’s repository commits API, the company reported. Threat actors could exploit it “under certain…

Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu1uqa1g5h6qhpu2v3yayj3w

AI CEOs Call for Slower Frontier Development as Stocks Fall

Amodei, Altman and Musk Back AI Pacing as Trump Rejects New Guardrails Discourse about the potential of unchecked AI systems and frontier labs' ability to control rogue AI agents culminated in several AI executives calling for slower AI development, a move that saw AI-related stocks fall and drew rebuke from the U.S. president.

Also reported by 1 other source
Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu1uqa1g5h6phpu22f8wbqh0

No UK Regulators Can Stop Risky AI Models, Panel Warns

Lawmakers Find AI Security Institute Has No Power to Compel or Block Model Releases British lawmakers are calling for new legislation to address the threat AI may pose to human rights, including demands that the riskiest systems clear regulatory hurdles before deployment - and warning that no U.K. regulator can currently stop a model from shipping.

Also reported by 1 other source
Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu1sl4vq5et5hpu2urrupezc

Cymphony Raises $30M to Turn Access Data Into Remediation

Israeli Startup Focuses on What Compromised Identities Can Do With Existing Access Israeli startup Cymphony raised $30 million from Sequoia Capital and SMBC Fin Atlas Beyond Fund to continuously map identities, permissions and activity as attackers and AI tools make dormant access-control weaknesses more easy to discover and exploit.

Also reported by 1 other source
BankInfoSecurity.com·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu1sl42v5esnhpu26bk7qlzf

UK Panel Calls for Fresh Approach to Regulating Medical AI

Commission Says Premarket Reviews Alone Fall Short for Evolving AI Technologies AI-enabled medical devices and healthcare software in the United Kingdom should be regulated with a life-cycle risk approach, especially as the technologies evolve, rather than the one-time premarket approval model that's predominate today, according to a new government commission report.

Also reported by 1 other source
Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu1qfywx5cgehpu298ei449s

Finnish Police Alert Europe Over Fugitive Vastaamo Hacker

Aleksanteri Tomminpoika Kivimäki Has Eluded Finnish Authorities for Months Finnish authorities issued a European Arrest Warrant for convicted Vastaamo hacker Aleksanteri Kivimäki after he failed to return to prison, widening the search for the man who stole 33,000 psychotherapy records and extorted patients.