BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Cyber Security Headlines·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu5rjzp5002bhku2o55vvzgc

Cisco zero-day goes straight to root, BambooToken branches into Linux, CenterPoint breach claim hits 7M+

Cisco zero-day goes straight to root BambooToken branches into Linux CenterPoint breach claim hits 7M+ Get the show notes here: https://cisoseries.com/cybersecurity-news-september-16-2026/ Huge thanks to our episode sponsor, Vanta Risk and regulation are ramping up, and customers expect proof of security just to do business. Vanta's automation brings compliance, risk, and customer trust together on one AI-powered platform. So whether you're prepping for a SOC 2 or running an enterprise GRC…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu3q8to97jruhpu2ut9k836o

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu3q8to97jrvhpu2mefyzrm8

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu3epgi1773ghpu2j39h0ywo

Hundreds of OpenAI agents attack RubyGems platform

A swarm of hundreds of OpenAI agents uploaded “malicious packages” to RubyGems and tried to steal API keys, the Ruby community gem hosting service revealed Friday. OpenAI confirmed part of the disclosure, saying, “our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We’ll continue to investigate as part of our broader review of agent activity during training and evaluation.” The agents’ goals were unclear, as was whether they…

Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu3adv2272bfhpu2orceafcr

US Lawmakers Eye Stronger Healthcare Cyber Defenses

House Subcommittee Hearing Highlights Threats to Rural Hospitals and Patient Care As U.S. hospitals, clinics and other medical providers continue to face an onslaught of hacking incidents and disruptive cyberattacks this year, the House Energy and Commerce Committee's health subcommittee examined on Tuesday two proposed bills aimed at strengthening health sector cybersecurity.

Also reported by 1 other source
BankInfoSecurity.com·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu380zki6zprhpu2q79ozfam

CVE Authorities Make Score 8 Look More Like the New 10

Exploit Maturity Can Lower Scores Until Attack Evidence or PoCs Emerge CVSS 4.0 lets threat intelligence alter a vulnerability's enriched score without changing its Base severity, prompting experts to warn that vendors and defenders must continuously reassess exploitation, exposure and patch priority.

Also reported by 1 other source
Data Breach Today·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu363jle6xl4hpu2tkwjs1jp

Defining What Counts as AI Spending

CIOs Build New Budget Models for Agents, Tokens and Failed Experiments AI spending no longer fits neatly into software or cloud budgets. As model access, agents, data preparation and governance drive costs across the enterprise, CIOs are creating new ways to track experimentation, control consumption and demonstrate long-term business value.

Also reported by 1 other source
SecurityWeek·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu34hnb56vrphpu2p2ade5lk

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.

CSO Online·6 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu33lhpy6urghpu2st0y0cz2

Critical Cisco Secure Email Gateway zero-day gives attackers root access

Cisco released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take over the device by simply sending malicious crafted emails to users. The flaw was already being exploited in the wild when the fixes were released. Tracked as CVE-2026-76461, the vulnerability is described by Cisco as an SQL injection caused by insufficient validation in the product’s email parsing code. Parsing incoming email messages for threats is this…