BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

BankInfoSecurity.com·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu4218a57wufhpu2v5te6p46

Quorum Cyber Adds Autonomous SOC Through Ontinue Acquisition

Proposed Purchase Combines Agentic SOC Technology With Managed Security Expertise Quorum Cyber's planned acquisition of Swiss Microsoft Gold Partner Ontinue would combine Microsoft-focused managed security with agentic SOC technology designed to investigate threats at machine speed while giving customers control over when AI can act autonomously.

Also reported by 1 other source
CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu4jscpn8gcxhpu275pfxesf

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing…

Also reported by 1 other source
CISA Advisories·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu4bja9487amhpu2n6bgk2a0

Using Cyber Decoys to Strengthen Detection and Response

CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data. Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to…

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu43bi4m7y86hpu2gi8mxnj1

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud

Also reported by 1 other source
The Hacker News·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu40ymmb7vmohpu2477om3mf

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu40ymmc7vmphpu2sgk7afha

Threat Intelligence Alone Won't Close the Exploitation Gap

A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react.

The Hacker News·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu40ymmc7vmqhpu26okge4mb

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions - Acronis Backup plugin for cPanel & WHM (Linux

Also reported by 1 other source
CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu3vkfr47pnuhpu2v1q3t09e

You don’t have to join the hack-back program to inherit its risk

The obvious question about Washington’s new private offensive cyber program is which security vendors will join it. The CSO question is what happens to you when one of your vendors does. The August 12 National Security Presidential Memorandum, “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” directs the National Coordination Center to build a program for vetted “Participating Companies.” The Justice Department and the Department of Homeland Security run it jointly, and two…

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu3ua53l7o86hpu23l57uvkd

AI made software development unrecognizable. Is cybersecurity next?

The rapid emergence of AI has radically changed a host of professions, with software engineering and development perhaps the most transformed of all pursuits. The usual “solitary ritual” of a developer writing code for hours is giving way to collaboration with an army of chatbots. In its 2025 report on the State of AI-Assisted Software Development, Google Cloud researchers found that even then, LLM usage was almost universal among coders, with 90% of developer respondents using AI as part of…