Real-time breach and ransomware intelligence for third-party risk management.
IDScan.net disclosed that an outside party accessed more than 153 million driver‑license records stored in its cloud platform. The breach highlights the need for continuous vendor oversight and auditable access‑control evidence to satisfy governance and risk frameworks.
A coordinated campaign used OpenAI‑generated agents to publish malicious RubyGems packages that were automatically consumed by RubyDoc, resulting in remote code execution on the documentation servers. The incident underscores the importance of continuous supply‑chain monitoring and vendor‑risk evidence for audit readiness.
A threat actor used large‑language‑model agents to automate attacks against unpatched PaperCut NG/MF servers, compromising 395 organizations and harvesting domain‑admin credentials. The incident underscores the importance of continuous access‑control assurance and rapid patch deployment for audit readiness.
FulcrumSec used hard‑coded GitHub and Azure DevOps tokens found in client‑side JavaScript to infiltrate Novo Nordisk’s cloud environment, exfiltrating more than 1 TB of drug research and patient data. The breach underscores the need for continuous credential‑management controls and audit‑ready evidence of secret‑handling policies.
Threat groups abused Anthropic’s Claude model to mass‑download and scan Android APKs, extracting hard‑coded credentials that were then used to breach SaaS providers, an airline, an energy firm, and a card‑shop operation. The episode highlights the need for AI‑governance controls and continuous vendor‑risk monitoring to maintain audit‑ready evidence.
The Florida Department of Highway Safety and Motor Vehicles confirmed that the ShinyHunters group accessed DMV records after stealing an officer’s login credentials from a personal device. The breach exposes driver‑license data and underscores the need for strict credential‑management controls in audit‑ready environments.
The Florida DMV confirmed that the ShinyHunters extortion group accessed the DAVID driver database using credentials from a Plant City police officer that were stored on a personal device. More than 200,000 driver records were reportedly stolen, illustrating a critical lapse in privileged‑account protection that directly impacts audit and compliance readiness.
Threat actors have used passkey‑styled phishing to steal Microsoft 365 credentials, leading to confirmed data exposure across multiple enterprises. The incident highlights the need for hardened authentication controls and continuous audit evidence for access‑control assurance.
Attackers exploited a SAML SSO flaw in Brevo, accessed 138 accounts and used them to send phishing emails to cryptocurrency firms' newsletter subscribers. The incident underscores the need for continuous third‑party risk monitoring and audit‑ready evidence of vendor controls.
A Ukrainian national involved in the Conti ransomware operation was sentenced to four years in U.S. prison after prosecutors detailed attacks on over 1,000 organizations and $150 M in ransom payments. The case highlights the importance of robust incident‑response controls and auditable evidence for ransomware readiness.
Threat groups are exploiting a critical authentication‑bypass flaw in Cisco Secure Firewall Management Center to install web shells, harvest credentials, and launch Qilin ransomware. The incident underscores the need for verifiable access‑control evidence and continuous monitoring to satisfy audit requirements.
A Russian‑speaking threat actor built exploits for two PaperCut NG/MF flaws and used AI agents to automate attacks, compromising 395 organizations in 48 countries. The incident underscores the importance of continuous vulnerability management and auditable patch‑deployment evidence for compliance readiness.
IDScan.net confirmed that an unauthorized party accessed its cloud platform and extracted over 153 million driver’s‑license scans, which later appeared for sale on a dark‑web marketplace. The breach highlights the need for continuous access‑control monitoring and defensible audit evidence for data‑protection controls.
A breach of Brevo, Trezor’s newsletter platform, allowed attackers to send fake security alerts to 347 k customers, resulting in 2,500 clicks on a malicious link. The event underscores the need for continuous third‑party monitoring and audit‑ready evidence in control‑assurance programs.
A critical SSRF vulnerability in SonicWall SMA1000 appliances (CVE‑2026‑15409) was weaponized in a mass‑exploitation campaign that stole Active Directory credentials from the Borough Council of King’s Lynn and West Norfolk. The incident underscores the need for continuous monitoring of network‑device configurations and robust credential‑access controls for audit readiness.
A Ukrainian national was sentenced to four years for his role in Conti ransomware attacks that hit 47 U.S. states and 31 countries, stealing data and encrypting systems. The case highlights why organizations must maintain auditable incident‑response controls to meet trust and assurance requirements.
ShinyHunters says it stole over 200,000 Florida driver records by exploiting a password‑reset weakness. The incident underscores the importance of hardened access‑management controls for audit readiness.
Surfshark disclosed that a mis‑configured internal test server was reachable from the Internet, allowing attackers to view service configurations and build credentials. No customer data was compromised, but the breach highlights the importance of continuous configuration monitoring for audit readiness.
In mid‑2025 a CISA director uploaded classified documents to the public ChatGPT model, causing confirmed data exposure. The event highlights the need for explicit AI‑agent accountability and continuous monitoring to satisfy audit and governance requirements.
Hackers accessed IDScan’s cloud database and posted over 153 million driver’s‑license scans for sale. The breach impacts any organization that uses IDScan for identity verification and underscores the need for continuous vendor‑risk monitoring and audit‑ready evidence.
Hundreds of AI agents automatically built and launched exploits for two PaperCut CVEs, breaching 395 organizations and harvesting credentials. The incident underscores the need for continuous vulnerability‑management and auditable privileged‑access controls for compliance readiness.
LiveThreat monitors this intelligence against your vendor portfolio and alerts you automatically.
Get critical and high-severity threats delivered to your inbox every morning. Unsubscribe anytime.
No credit card. No contract. Free vendor assessments.
Score 10 Vendors on Free Tier →