APT campaigns, nation-state threats, and security advisories analyzed through a third-party risk management lens.
A purported Carhartt data breach was debunked by security researcher Troy Hunt, showing no evidence of compromised data. The episode illustrates why SOC 2‑compliant organizations must verify breach reports before triggering incident‑response and audit processes.
Threat actors published npm packages that contain a single malicious HTML page mimicking a Cloudflare CAPTCHA. When accessed via npm mirrors (UNPKG, npmmirror), the page redirects browsers to attacker‑controlled phishing sites, creating a supply‑chain phishing vector that bypasses typical URL‑reputation defenses. This highlights the need for robust third‑party risk controls and continuous monitoring in SOC 2 programs.
AnonyMousKIT, a newly discovered phishing‑as‑a‑service platform, uses voice‑AI agents to call iPhone owners and steal passcodes, Apple‑ID credentials, and 2FA codes. The service’s scale and low cost make it a potent threat to any organization that manages Apple devices, highlighting the need for robust security awareness training and SOC 2‑aligned access‑control evidence.
The offer is open to subscribers on any tier, but it is location-based.
Norway’s Digitalisation Agency and its provider Vivicta faced a third DDoS attack in two months, knocking out shared authentication services and downstream citizen portals. The incident underscores the need for robust Availability controls and continuous evidence collection for SOC 2 readiness.
Uber was fined €825 million by the Dutch data‑protection authority for using AI to suspend driver accounts without human review, breaching GDPR’s ban on fully automated decisions that significantly affect individuals. The case highlights the need for documented human‑in‑the‑loop controls and audit‑ready privacy evidence in SOC 2 programs.
Anthropic now shares the memory store between Claude Chat and Claude Cowork, making prior conversation context available across both services unless a user opts out. This creates a privacy‑risk scenario that SOC 2 and privacy‑compliance programs must track and evidence.
Microsoft warns that the time between vulnerability discovery and patch deployment is collapsing, creating a gap attackers can exploit. This trend pressures SOC 2 controls around risk management and change management, making continuous evidence collection essential for audit readiness.
A coordinated DDoS flood targeted the shared digital infrastructure run by Norway’s Digitalisation Agency and its provider Vivicta, rendering public‑service logins, e‑IDs and e‑signatures intermittently unavailable. The incident underscores the importance of SOC 2 Availability controls and continuous evidence of mitigation for audit readiness.
Microsoft Teams now lets administrators automatically block detected external meeting bots, removing organizer approval. The change provides a concrete access‑control measure that aligns with SOC 2 audit requirements for logical access and evidencing policy enforcement.
Researchers observed threat actors submitting hostnames that resolve to the cloud metadata IP 169.254.169.254, allowing SSRF attempts to evade string‑based blocklists. The technique highlights a control‑gap that SOC 2 audits must address, and continuous monitoring can provide the needed audit evidence.
Oasis Security reported a zero‑day weakness in NVIDIA’s NemoClaw that lets a malicious webpage take control of a local Ollama instance and inject hidden instructions into the AI model. The issue highlights the need for SOC 2‑aligned control mapping and continuous evidence of model integrity.
Attackers are impersonating employees to bypass MFA during onboarding and password‑reset processes, a tactic linked to the 2025 M&S ransomware breach. The scenario highlights gaps in SOC 2 logical‑access controls and the need for documented, auditable identity‑verification procedures.
Interpol’s eight‑month Jackel IV operation arrested dozens of suspects and revealed a rising trend of sextortion against minors and large‑scale fraud. The episode underscores the need for robust security awareness programs to satisfy SOC 2 people‑control requirements.
Meta announced WhatsApp now supports multiple passkeys per account, letting users on iOS and Android log in with phishing‑resistant authentication. For compliance teams, the move underscores the need to align access‑control policies with modern credential standards.
Fideo Intelligence introduced Fideo Lens, a SaaS platform that visualises hidden connections among identities, accounts and devices to accelerate fraud investigations. For SOC 2‑ready firms, the tool provides continuous evidence that maps directly to security‑monitoring controls.
Cisco and Teleport announced a strategic partnership to deliver “Infrastructure Identity,” a cryptographic, short‑lived identity model for humans, workloads, and AI agents. The approach replaces static credentials, aligning with SOC 2 access‑control requirements and providing continuous audit evidence.
WhatsApp now lets users create separate passkeys for Android and iOS and replaces its six‑digit PIN with an alphanumeric password, helping to curb credential‑theft attacks—a direct relevance to SOC 2 access‑control requirements.
The UK is amending its Cyber Security and Resilience Bill to let ministers secretly block technology vendors deemed a national‑security risk, affecting energy, health, transport and other critical sectors. For SOC 2‑ready organisations this creates an immediate need for auditable third‑party monitoring and vendor‑risk documentation.
A sponsored ad redirects macOS users to a counterfeit OpenAI Codex page that instructs them to paste a malicious command into Terminal, installing a universal Mach‑O binary. The technique highlights the need for robust SOC 2 access‑control policies and security‑awareness training.
CISA’s red‑team assessments revealed that one organization failed to detect a full domain compromise while another contained it, underscoring the importance of SOC 2 detection and response controls for audit readiness.