LiveThreat Breach Watch
// BREACH WATCH

BREACH & RANSOMWARE

Real-time breach and ransomware intelligence for third-party risk management.

Breaches Advisories Vulnerabilities RSS
Score 10 Vendors on Free Tier → RSS Feed
0
Last 24h
324
Last 7 Days
43
Critical (7d)
Showing 21 of 1328 results
BREACHLIVETHREAT BRIEF👤
LIVETHREAT BRIEFIDScan.net Confirms Massive Data Breach Exposing Over 153 Million Driver Licenses

IDScan.net disclosed that an outside party accessed more than 153 million driver‑license records stored in its cloud platform. The breach highlights the need for continuous vendor oversight and auditable access‑control evidence to satisfy governance and risk frameworks.

🌐 idscan.net
🏭 Technology & SaaS
Critical · Sep 12, 2026 · DataBreachToday
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🔗
LIVETHREAT BRIEFOpenAI Agents Power RubyGems Supply‑Chain Attack, Achieving RCE on RubyDoc Servers

A coordinated campaign used OpenAI‑generated agents to publish malicious RubyGems packages that were automatically consumed by RubyDoc, resulting in remote code execution on the documentation servers. The incident underscores the importance of continuous supply‑chain monitoring and vendor‑risk evidence for audit readiness.

🌐 mend.io
🏭 Technology & SaaS🎯 Third-Party Dependency
High · Sep 12, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🐛
LIVETHREAT BRIEFAI Agents Exploit PaperCut Vulnerabilities, Compromise 395 Organizations Across 48 Countries

A threat actor used large‑language‑model agents to automate attacks against unpatched PaperCut NG/MF servers, compromising 395 organizations and harvesting domain‑admin credentials. The incident underscores the importance of continuous access‑control assurance and rapid patch deployment for audit readiness.

🏭 Education & Research🎯 Vulnerability Exploit
High · Sep 11, 2026 · DataBreachToday
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF☁️
LIVETHREAT BRIEFNovo Nordisk Breach Exposes Over 1 TB of Sensitive Data via Stolen GitHub Access Tokens

FulcrumSec used hard‑coded GitHub and Azure DevOps tokens found in client‑side JavaScript to infiltrate Novo Nordisk’s cloud environment, exfiltrating more than 1 TB of drug research and patient data. The breach underscores the need for continuous credential‑management controls and audit‑ready evidence of secret‑handling policies.

🏭 Healthcare & Life Sciences🎯 Stolen Credentials
High · Sep 11, 2026 · DataBreachToday
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🏦
LIVETHREAT BRIEFHackers Leverage Anthropic’s Claude AI to Harvest Secrets from 1.8 M Android Apps and Compromise Hundreds of Organizations

Threat groups abused Anthropic’s Claude model to mass‑download and scan Android APKs, extracting hard‑coded credentials that were then used to breach SaaS providers, an airline, an energy firm, and a card‑shop operation. The episode highlights the need for AI‑governance controls and continuous vendor‑risk monitoring to maintain audit‑ready evidence.

🏭 Technology & SaaS🎯 Third-Party Dependency
High · Sep 11, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🔑
LIVETHREAT BRIEFFlorida DMV Data Breach Linked to Officer’s Stolen Credentials on Personal Device

The Florida Department of Highway Safety and Motor Vehicles confirmed that the ShinyHunters group accessed DMV records after stealing an officer’s login credentials from a personal device. The breach exposes driver‑license data and underscores the need for strict credential‑management controls in audit‑ready environments.

🏭 Government & Public Sector🎯 Stolen Credentials
High · Sep 11, 2026 · The Record
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🔑
LIVETHREAT BRIEFFlorida DMV Database Breached via Stolen Police Account – Over 200K Driver Records Exposed

The Florida DMV confirmed that the ShinyHunters extortion group accessed the DAVID driver database using credentials from a Plant City police officer that were stored on a personal device. More than 200,000 driver records were reportedly stolen, illustrating a critical lapse in privileged‑account protection that directly impacts audit and compliance readiness.

🏭 Government & Public Sector⚡ Data Exfiltration🎯 Stolen Credentials
High · Sep 11, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🎣
LIVETHREAT BRIEFPasskey‑Themed Phishing Attacks Harvest Microsoft 365 Credentials and Data

Threat actors have used passkey‑styled phishing to steal Microsoft 365 credentials, leading to confirmed data exposure across multiple enterprises. The incident highlights the need for hardened authentication controls and continuous audit evidence for access‑control assurance.

🏭 Technology & SaaS🎯 Phishing
High · Sep 11, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🎣
LIVETHREAT BRIEFSupply‑Chain Phishing Campaign Hits Crypto Newsletter Subscribers After Brevo Email‑Marketing Breach

Attackers exploited a SAML SSO flaw in Brevo, accessed 138 accounts and used them to send phishing emails to cryptocurrency firms' newsletter subscribers. The incident underscores the need for continuous third‑party risk monitoring and audit‑ready evidence of vendor controls.

🏭 Financial Services & FinTech⚡ Data Exfiltration🎯 Phishing
High · Sep 11, 2026 · Malwarebytes Labs
Read Full Intelligence Brief →
RANSOMWARELIVETHREAT BRIEF💀
LIVETHREAT BRIEFUkrainian Hacker Sentenced to Four Years for Conti Ransomware Campaign Targeting 1,000+ Victims

A Ukrainian national involved in the Conti ransomware operation was sentenced to four years in U.S. prison after prosecutors detailed attacks on over 1,000 organizations and $150 M in ransom payments. The case highlights the importance of robust incident‑response controls and auditable evidence for ransomware readiness.

🎯 Malware
High · Sep 11, 2026 · The Record
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF💀
LIVETHREAT BRIEFCritical Authentication Bypass in Cisco FMC (CVE‑2026‑20079) Enables Qilin Ransomware Deployment

Threat groups are exploiting a critical authentication‑bypass flaw in Cisco Secure Firewall Management Center to install web shells, harvest credentials, and launch Qilin ransomware. The incident underscores the need for verifiable access‑control evidence and continuous monitoring to satisfy audit requirements.

🏭 Technology & SaaS🎯 Vulnerability Exploit
Critical · Sep 11, 2026 · Security Affairs
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF☁️
LIVETHREAT BRIEFAI Agents Exploit PaperCut NG/MF Vulnerabilities (CVE‑2026‑81578, CVE‑2026‑82078) to Breach 395 Organizations

A Russian‑speaking threat actor built exploits for two PaperCut NG/MF flaws and used AI agents to automate attacks, compromising 395 organizations in 48 countries. The incident underscores the importance of continuous vulnerability management and auditable patch‑deployment evidence for compliance readiness.

🏭 Education & Research⚡ Credential Compromise🎯 Vulnerability Exploit
High · Sep 11, 2026 · Help Net Security
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF☁️
LIVETHREAT BRIEFIDScan Breach Exposes 153 Million Driver’s Licenses on Dark Web

IDScan.net confirmed that an unauthorized party accessed its cloud platform and extracted over 153 million driver’s‑license scans, which later appeared for sale on a dark‑web marketplace. The breach highlights the need for continuous access‑control monitoring and defensible audit evidence for data‑protection controls.

🌐 idscan.net
🏭 Technology & SaaS
High · Sep 11, 2026 · Help Net Security
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🎣
LIVETHREAT BRIEFTrezor Users Phished After Brevo Email‑Provider Breach Affects 347,000 Addresses

A breach of Brevo, Trezor’s newsletter platform, allowed attackers to send fake security alerts to 347 k customers, resulting in 2,500 clicks on a malicious link. The event underscores the need for continuous third‑party monitoring and audit‑ready evidence in control‑assurance programs.

🏭 Financial Services & FinTech🎯 Phishing
High · Sep 11, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🔑
LIVETHREAT BRIEFMass Exploitation of SonicWall SMA1000 SSRF Flaw (CVE‑2026‑15409) Leads to Credential Theft at UK Council

A critical SSRF vulnerability in SonicWall SMA1000 appliances (CVE‑2026‑15409) was weaponized in a mass‑exploitation campaign that stole Active Directory credentials from the Borough Council of King’s Lynn and West Norfolk. The incident underscores the need for continuous monitoring of network‑device configurations and robust credential‑access controls for audit readiness.

🌐 hunt.io
🏭 Government & Public Sector🎯 Vulnerability Exploit
Critical · Sep 11, 2026 · Security Affairs
Read Full Intelligence Brief →
RANSOMWARELIVETHREAT BRIEF💀
LIVETHREAT BRIEFConti Ransomware Gang Member Sentenced to 4 Years for Multi‑Nation Attacks

A Ukrainian national was sentenced to four years for his role in Conti ransomware attacks that hit 47 U.S. states and 31 countries, stealing data and encrypting systems. The case highlights why organizations must maintain auditable incident‑response controls to meet trust and assurance requirements.

🎯 Malware
High · Sep 11, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF💣
LIVETHREAT BRIEFShinyHunters Claims Access to Florida DMV Driver Records, Exposing 200K+ Personal Profiles

ShinyHunters says it stole over 200,000 Florida driver records by exploiting a password‑reset weakness. The incident underscores the importance of hardened access‑management controls for audit readiness.

🏭 Government & Public Sector⚡ Data Exfiltration🎯 Vulnerability Exploit
High · Sep 10, 2026 · DataBreachToday
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF👤
LIVETHREAT BRIEFSurfshark VPN Test Server Misconfiguration Leads to Hackers Accessing Internal Proxy Environment

Surfshark disclosed that a mis‑configured internal test server was reachable from the Internet, allowing attackers to view service configurations and build credentials. No customer data was compromised, but the breach highlights the importance of continuous configuration monitoring for audit readiness.

🏭 Technology & SaaS🎯 Misconfiguration
High · Sep 10, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🤖
LIVETHREAT BRIEFCISA Uploads Sensitive Government Docs to Public ChatGPT, Exposing AI Governance Gaps

In mid‑2025 a CISA director uploaded classified documents to the public ChatGPT model, causing confirmed data exposure. The event highlights the need for explicit AI‑agent accountability and continuous monitoring to satisfy audit and governance requirements.

🏭 Government & Public Sector🎯 Insider
High · Sep 10, 2026 · TechRepublic Security
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF📰
LIVETHREAT BRIEFIDScan Breach Exposes 153 Million Driver’s License Scans on Dark Web

Hackers accessed IDScan’s cloud database and posted over 153 million driver’s‑license scans for sale. The breach impacts any organization that uses IDScan for identity verification and underscores the need for continuous vendor‑risk monitoring and audit‑ready evidence.

🏭 Financial Services & FinTech
High · Sep 10, 2026 · The Record
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF☁️
LIVETHREAT BRIEFAI‑Powered Campaign Exploits PaperCut Vulnerabilities, Compromising 395 Organizations

Hundreds of AI agents automatically built and launched exploits for two PaperCut CVEs, breaching 395 organizations and harvesting credentials. The incident underscores the need for continuous vulnerability‑management and auditable privileged‑access controls for compliance readiness.

🏭 Education & Research🎯 Vulnerability Exploit
High · Sep 10, 2026 · BleepingComputer
Read Full Intelligence Brief →
Page 1 of 64

Know When Your Vendors Are Breached

LiveThreat monitors this intelligence against your vendor portfolio and alerts you automatically.

Score 10 Vendors on Free Tier → Subscribe via RSS

Daily Breach Intelligence Digest

Get critical and high-severity threats delivered to your inbox every morning. Unsubscribe anytime.

RSS Feed One email per day · No spam · Unsubscribe anytime

START ASSESSING YOUR VENDORS TODAY.

No credit card. No contract. Free vendor assessments.

Score 10 Vendors on Free Tier →