Real-time breach and ransomware intelligence for third-party risk management.
A critical authentication‑bypass flaw in Palo Alto GlobalProtect (CVE‑2026‑0257) is being leveraged by the Qilin ransomware‑as‑a‑service group to gain unauthorized VPN access and encrypt victim networks. The event underscores the need for SOC 2‑aligned access‑control monitoring and rapid patch evidence.
Estée Lauder disclosed that an unauthenticated attacker exploited Oracle E‑Business Suite (CVE‑2025‑61882) to steal extensive personal and financial data. The breach underscores the need for robust third‑party risk controls and continuous audit evidence for SOC 2 readiness.
Hugging Face reported that attackers leveraged flaws in its autonomous‑agent framework to access internal clusters, harvest cloud credentials, and exfiltrate data. The breach underscores the need for robust SOC 2 access‑control evidence and continuous credential monitoring.
Craneware Group and Abbott Laboratories disclosed that attackers used compromised credentials to view and exfiltrate employee, customer and lab data. The incidents underscore the need for robust SOC 2 access‑control evidence and continuous credential monitoring.
Hackers exploited CVE‑2025‑61882 in Oracle E‑Business Suite to steal HR‑related personal data from Estée Lauder. The incident underscores the need for SOC 2‑aligned vulnerability‑management and continuous evidence collection.
Two critical vulnerabilities in SonicWall SMA1000 were weaponised as zero‑days, allowing threat actors to gain root and install custom malware. The breach underscores the need for continuous patch‑management evidence in SOC 2 audit programs.
Attackers compromised Ostium's off‑chain price oracle, feeding false data that let them drain $23.75 million from the platform's liquidity provider vault. The breach underscores the need for robust third‑party risk controls and continuous audit evidence in SOC 2 programs.
JadePuffer's autonomous AI agent used the EncForge ransomware to encrypt AI/ML assets on a compromised Langflow instance, exploiting an exposed Docker socket. The incident underscores the need for continuous control mapping and audit‑ready evidence of misconfiguration remediation for SOC 2 compliance.
Hugging Face reported that an autonomous AI‑agent was hijacked, allowing attackers to steal service credentials and a subset of internal datasets. The breach highlights the need for robust SOC 2 access‑control monitoring and evidence collection.
Suno, an AI‑driven music generation service, suffered a breach that leaked over 55 M email addresses and tens of thousands of Stripe purchase records with partial credit‑card details. The incident underscores the need for SOC 2‑aligned privacy and security controls, continuous vendor monitoring, and ready breach‑response evidence.
World Leaks published thousands of files tied to Reliance Infrastructure, a subcontractor for India's Kudankulam Nuclear Power Plant. The leak stems from a suspected ransomware‑related intrusion on a Yotta‑hosted server. While safety systems were not compromised, the event highlights the need for SOC 2‑ready vendor‑risk controls and continuous monitoring.
Group‑IB discovered HOLLOWGRAPH, malware that leverages Microsoft 365 calendar entries as a covert C2 channel, compromising twelve systems and exfiltrating encrypted files. The attack highlights gaps in access‑control monitoring and credential‑management required for SOC 2 readiness.
Hugging Face reported that an autonomous AI exploited code‑execution flaws in its data pipeline, gaining node‑level access and harvesting cloud credentials. The breach highlights the need for robust SOC 2 access‑control and continuous‑monitoring practices.
An unidentified threat actor leveraged a previously unknown zero‑day vulnerability and misconfigured server settings to gain persistent access to the Korea National Diplomatic Academy’s e‑learning system from April 2025 to February 2026, stealing personal data of ministry employees. The breach underscores gaps in vulnerability management and configuration controls that SOC 2 audits target, highlighting the need for continuous, auditable evidence of security hygiene.
An intrusion at Paidwork in March 2026 resulted in the public release of a database covering over 23 million users, including PII and bank details. The breach highlights gaps in access‑control and monitoring that SOC 2 programs are designed to address.
A cyberattack disabled Romania’s national land registry systems, forcing a week‑long service outage. The attackers leveraged known software vulnerabilities and stolen credentials, exfiltrating source code but not personal data. The incident underscores the need for robust SOC 2 access‑control practices and continuous monitoring.
Abbott Laboratories disclosed two separate cyber incidents involving unauthorized access to its Cancer Diagnostics systems and the LabCentral portal. Extortion groups claim they have stolen millions of patient records and personal identifiers, though no data loss has been verified. The events highlight the need for robust SOC 2 access‑control practices and continuous audit evidence.
WINDTRE suffered two data breaches after attackers used social engineering to obtain staff credentials, exposing personal and payment data of over 365 000 customers. The incident underscores the need for SOC 2‑aligned access‑control and credential‑management practices to provide audit‑ready evidence.
Attackers used an autonomous AI‑agent framework to exploit code‑execution vulnerabilities in Hugging Face’s data pipeline, stealing cloud credentials and accessing internal datasets. The incident highlights the importance of SOC 2 access‑control controls and continuous evidence collection for audit readiness.
A Florida resident was arrested for spreading malicious Steam game installers that stole $220,000 in cryptocurrency, including $32,000 from a terminally ill patient. The case highlights gaps in access‑control and user‑awareness that SOC 2 audit programs must address.
Craneware disclosed an intrusion that led to the theft of employee, customer and partner records. The breach highlights the need for robust SOC 2 vendor‑management controls and continuous monitoring to provide audit‑ready evidence of due‑diligence.
LiveThreat monitors this intelligence against your vendor portfolio and alerts you automatically.
Get critical and high-severity threats delivered to your inbox every morning. Unsubscribe anytime.
No credit card. No contract. Free vendor assessments.
Score 10 Vendors on Free Tier →