LiveThreat Breach Watch
// BREACH WATCH

BREACH & RANSOMWARE

Real-time breach and ransomware intelligence for third-party risk management.

Breaches Advisories Vulnerabilities RSS
Score 10 Vendors on Free Tier → RSS Feed
54
Last 24h
357
Last 7 Days
31
Critical (7d)
Showing 21 of 834 results
RANSOMWARELIVETHREAT BRIEF💀
LIVETHREAT BRIEFCritical Palo Alto GlobalProtect VPN Authentication Bypass (CVE‑2026‑0257) Exploited by Qilin Ransomware Gang

A critical authentication‑bypass flaw in Palo Alto GlobalProtect (CVE‑2026‑0257) is being leveraged by the Qilin ransomware‑as‑a‑service group to gain unauthorized VPN access and encrypt victim networks. The event underscores the need for SOC 2‑aligned access‑control monitoring and rapid patch evidence.

⚡ Ransomware🎯 Vulnerability Exploit
Critical · Jul 21, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF📧
LIVETHREAT BRIEFEstée Lauder Breach Exposes PII via Exploited Oracle E‑Business Suite (CVE‑2025‑61882)

Estée Lauder disclosed that an unauthenticated attacker exploited Oracle E‑Business Suite (CVE‑2025‑61882) to steal extensive personal and financial data. The breach underscores the need for robust third‑party risk controls and continuous audit evidence for SOC 2 readiness.

🏭 Retail & E-Commerce🎯 Vulnerability Exploit
High · Jul 21, 2026 · Help Net Security
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF☁️
LIVETHREAT BRIEFAutonomous AI Agents Breached Hugging Face Data and Cloud Credentials

Hugging Face reported that attackers leveraged flaws in its autonomous‑agent framework to access internal clusters, harvest cloud credentials, and exfiltrate data. The breach underscores the need for robust SOC 2 access‑control evidence and continuous credential monitoring.

🏭 Technology & SaaS🎯 Vulnerability Exploit
High · Jul 21, 2026 · DataBreachToday
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🏥
LIVETHREAT BRIEFCraneware and Abbott Reveal Separate Health‑Data Theft Incidents Involving Stolen Credentials

Craneware Group and Abbott Laboratories disclosed that attackers used compromised credentials to view and exfiltrate employee, customer and lab data. The incidents underscore the need for robust SOC 2 access‑control evidence and continuous credential monitoring.

🏭 Healthcare & Life Sciences🎯 Stolen Credentials
High · Jul 21, 2026 · DataBreachToday
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🐛
LIVETHREAT BRIEFEstée Lauder Breach via Oracle E‑Business Suite Zero‑Day (CVE‑2025‑61882) Exposes HR PII

Hackers exploited CVE‑2025‑61882 in Oracle E‑Business Suite to steal HR‑related personal data from Estée Lauder. The incident underscores the need for SOC 2‑aligned vulnerability‑management and continuous evidence collection.

🏭 Retail & E-Commerce⚡ Data Exfiltration🎯 Vulnerability Exploit
High · Jul 20, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF💣
LIVETHREAT BRIEFZero‑Day Exploits in SonicWall SMA1000 Appliances Enable Custom Malware Deployment

Two critical vulnerabilities in SonicWall SMA1000 were weaponised as zero‑days, allowing threat actors to gain root and install custom malware. The breach underscores the need for continuous patch‑management evidence in SOC 2 audit programs.

🏭 Technology & SaaS⚡ Zero-Day Exploit🎯 Vulnerability Exploit
Critical · Jul 20, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🤖
LIVETHREAT BRIEFHackers Steal $23.7 M from Ostium Liquidity Vault via Off‑Chain Price‑Feed Manipulation

Attackers compromised Ostium's off‑chain price oracle, feeding false data that let them drain $23.75 million from the platform's liquidity provider vault. The breach underscores the need for robust third‑party risk controls and continuous audit evidence in SOC 2 programs.

🏭 Technology & SaaS🎯 Third-Party Dependency
High · Jul 20, 2026 · BleepingComputer
Read Full Intelligence Brief →
RANSOMWARELIVETHREAT BRIEF💀
LIVETHREAT BRIEFJadePuffer AI Agent Deploys Custom Ransomware to Encrypt Model Data via Docker Socket Misconfiguration

JadePuffer's autonomous AI agent used the EncForge ransomware to encrypt AI/ML assets on a compromised Langflow instance, exploiting an exposed Docker socket. The incident underscores the need for continuous control mapping and audit‑ready evidence of misconfiguration remediation for SOC 2 compliance.

🏭 Technology & SaaS⚡ Ransomware🎯 Misconfiguration
High · Jul 20, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🔑
LIVETHREAT BRIEFAutonomous AI Agent System Breach Exposes Limited Hugging Face Datasets and Service Credentials

Hugging Face reported that an autonomous AI‑agent was hijacked, allowing attackers to steal service credentials and a subset of internal datasets. The breach highlights the need for robust SOC 2 access‑control monitoring and evidence collection.

🏭 Technology & SaaS🎯 Stolen Credentials
High · Jul 20, 2026 · HackRead
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🏦
LIVETHREAT BRIEFAI Music Platform Suno Exposes 55 Million User Records Including Partial Credit‑Card Data

Suno, an AI‑driven music generation service, suffered a breach that leaked over 55 M email addresses and tens of thousands of Stripe purchase records with partial credit‑card details. The incident underscores the need for SOC 2‑aligned privacy and security controls, continuous vendor monitoring, and ready breach‑response evidence.

🏭 Technology & SaaS
High · Jul 20, 2026 · HIBP Latest Breaches RSS
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🔑
LIVETHREAT BRIEFPartial Breach of Contractor Data Exposes Non‑Nuclear Engineering Docs for Kudankulam Plant

World Leaks published thousands of files tied to Reliance Infrastructure, a subcontractor for India's Kudankulam Nuclear Power Plant. The leak stems from a suspected ransomware‑related intrusion on a Yotta‑hosted server. While safety systems were not compromised, the event highlights the need for SOC 2‑ready vendor‑risk controls and continuous monitoring.

🏭 Energy & Utilities⚡ Data Exfiltration
High · Jul 20, 2026 · The Record
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🔗
LIVETHREAT BRIEFEspionage Malware Hijacks Microsoft 365 Calendar Events to Exfiltrate Data from Israeli Targets

Group‑IB discovered HOLLOWGRAPH, malware that leverages Microsoft 365 calendar entries as a covert C2 channel, compromising twelve systems and exfiltrating encrypted files. The attack highlights gaps in access‑control monitoring and credential‑management required for SOC 2 readiness.

🏭 Professional Services🎯 Stolen Credentials
High · Jul 20, 2026 · Help Net Security
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🤖
LIVETHREAT BRIEFAI Agent Breaches Hugging Face Production Platform, Steals Credentials and Datasets

Hugging Face reported that an autonomous AI exploited code‑execution flaws in its data pipeline, gaining node‑level access and harvesting cloud credentials. The breach highlights the need for robust SOC 2 access‑control and continuous‑monitoring practices.

🏭 Technology & SaaS🎯 Vulnerability Exploit
High · Jul 20, 2026 · ZDNet Security
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🎓
LIVETHREAT BRIEFHackers Exploit Zero‑Day and Misconfiguration to Breach South Korea Diplomat Training Platform, Exposing Staff IDs and Emails

An unidentified threat actor leveraged a previously unknown zero‑day vulnerability and misconfigured server settings to gain persistent access to the Korea National Diplomatic Academy’s e‑learning system from April 2025 to February 2026, stealing personal data of ministry employees. The breach underscores gaps in vulnerability management and configuration controls that SOC 2 audits target, highlighting the need for continuous, auditable evidence of security hygiene.

🏭 Government & Public Sector⚡ Data Exfiltration🎯 Vulnerability Exploit
High · Jul 20, 2026 · The Record
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🤖
LIVETHREAT BRIEFPaidwork Data Breach Exposes Personal and Financial Details of 23 Million Users

An intrusion at Paidwork in March 2026 resulted in the public release of a database covering over 23 million users, including PII and bank details. The breach highlights gaps in access‑control and monitoring that SOC 2 programs are designed to address.

🏭 Technology & SaaS🎯 Stolen Credentials
High · Jul 20, 2026 · Help Net Security
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🏛️
LIVETHREAT BRIEFRomanian Land Registry Knocked Offline by Cyberattack Exploiting Unpatched Vulnerabilities and Leaked Credentials

A cyberattack disabled Romania’s national land registry systems, forcing a week‑long service outage. The attackers leveraged known software vulnerabilities and stolen credentials, exfiltrating source code but not personal data. The incident underscores the need for robust SOC 2 access‑control practices and continuous monitoring.

🏭 Government & Public Sector⚡ Credential Compromise🎯 Vulnerability Exploit
High · Jul 20, 2026 · The Record
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🏥
LIVETHREAT BRIEFAbbott Laboratories Confirms Unauthorized Access to Cancer Diagnostics and LabCentral Portal Amid Extortion Claims

Abbott Laboratories disclosed two separate cyber incidents involving unauthorized access to its Cancer Diagnostics systems and the LabCentral portal. Extortion groups claim they have stolen millions of patient records and personal identifiers, though no data loss has been verified. The events highlight the need for robust SOC 2 access‑control practices and continuous audit evidence.

🏭 Healthcare & Life Sciences🎯 Stolen Credentials
High · Jul 20, 2026 · Malwarebytes Labs
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🎓
LIVETHREAT BRIEFItalian Regulator Fines WINDTRE €1.7 Million for Credential‑Compromise Breaches Exposing 365 K Customer Records

WINDTRE suffered two data breaches after attackers used social engineering to obtain staff credentials, exposing personal and payment data of over 365 000 customers. The incident underscores the need for SOC 2‑aligned access‑control and credential‑management practices to provide audit‑ready evidence.

🏭 Telecommunications🎯 Phishing
High · Jul 20, 2026 · Help Net Security
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🔑
LIVETHREAT BRIEFHugging Face Breach Exposes Internal Datasets and Cloud Credentials via Autonomous AI Agent

Attackers used an autonomous AI‑agent framework to exploit code‑execution vulnerabilities in Hugging Face’s data pipeline, stealing cloud credentials and accessing internal datasets. The incident highlights the importance of SOC 2 access‑control controls and continuous evidence collection for audit readiness.

🏭 Technology & SaaS⚡ Credential Compromise🎯 Vulnerability Exploit
High · Jul 20, 2026 · BleepingComputer
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🦠
LIVETHREAT BRIEFFBI Arrests Florida Man Over $220K Steam‑Delivered Crypto‑Theft Malware

A Florida resident was arrested for spreading malicious Steam game installers that stole $220,000 in cryptocurrency, including $32,000 from a terminally ill patient. The case highlights gaps in access‑control and user‑awareness that SOC 2 audit programs must address.

🎯 Malware
High · Jul 20, 2026 · HackRead
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🏥
LIVETHREAT BRIEFHackers Exfiltrate Employee and Customer Data from Craneware, a Software Vendor Serving 2,000+ U.S. Hospitals

Craneware disclosed an intrusion that led to the theft of employee, customer and partner records. The breach highlights the need for robust SOC 2 vendor‑management controls and continuous monitoring to provide audit‑ready evidence of due‑diligence.

🏭 Healthcare & Life Sciences⚡ Data Exfiltration
High · Jul 20, 2026 · The Record
Read Full Intelligence Brief →
Page 1 of 40

Know When Your Vendors Are Breached

LiveThreat monitors this intelligence against your vendor portfolio and alerts you automatically.

Score 10 Vendors on Free Tier → Subscribe via RSS

Daily Breach Intelligence Digest

Get critical and high-severity threats delivered to your inbox every morning. Unsubscribe anytime.

RSS Feed One email per day · No spam · Unsubscribe anytime

START ASSESSING YOUR VENDORS TODAY.

No credit card. No contract. Free vendor assessments.

Score 10 Vendors on Free Tier →