LiveThreat Advisory
// ADVISORIES & THREAT INTEL

ADVISORIES & THREAT INTEL

APT campaigns, nation-state threats, and security advisories analyzed through a third-party risk management lens.

Breaches Advisories Vulnerabilities 📡 RSS
Time: Severity: 6155 items
THREAT INTELLT BRIEF🔍
LIVETHREAT BRIEFFalse Carhartt Data Breach Claim Highlights Need for Verification

A purported Carhartt data breach was debunked by security researcher Troy Hunt, showing no evidence of compromised data. The episode illustrates why SOC 2‑compliant organizations must verify breach reports before triggering incident‑response and audit processes.

Medium · Aug 25, 2026 · Troy Hunt Blog
Read Full Intelligence Brief →
THREAT INTELLT BRIEF🎣
LIVETHREAT BRIEFHackers Abuse npm Registry Mirrors to Host Phishing Pages Impersonating Cloudflare CAPTCHAs

Threat actors published npm packages that contain a single malicious HTML page mimicking a Cloudflare CAPTCHA. When accessed via npm mirrors (UNPKG, npmmirror), the page redirects browsers to attacker‑controlled phishing sites, creating a supply‑chain phishing vector that bypasses typical URL‑reputation defenses. This highlights the need for robust third‑party risk controls and continuous monitoring in SOC 2 programs.

High · Aug 25, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTELLT BRIEF🎣
LIVETHREAT BRIEFAI‑Powered Voice Phishing‑as‑a‑Service Harvests iPhone Passcodes and Bypasses Activation Lock

AnonyMousKIT, a newly discovered phishing‑as‑a‑service platform, uses voice‑AI agents to call iPhone owners and steal passcodes, Apple‑ID credentials, and 2FA codes. The service’s scale and low cost make it a potent threat to any organization that manages Apple devices, highlighting the need for robust security awareness training and SOC 2‑aligned access‑control evidence.

High · Aug 25, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTELLT BRIEF🔍
LIVETHREAT BRIEFSome Spectrum internet customers can get free Amazon Prime - see if you're eligible

The offer is open to subscribers on any tier, but it is location-based.

Low · Aug 25, 2026 · ZDNet Security
Read Full Intelligence Brief →
THREAT INTELLT BRIEF🌊
LIVETHREAT BRIEFNorway’s Shared Digital Government Infrastructure Hit by a Third DDoS Attack

Norway’s Digitalisation Agency and its provider Vivicta faced a third DDoS attack in two months, knocking out shared authentication services and downstream citizen portals. The incident underscores the need for robust Availability controls and continuous evidence collection for SOC 2 readiness.

High · Aug 25, 2026 · Security Affairs
Read Full Intelligence Brief →
ADVISORYLT BRIEF📋
LIVETHREAT BRIEFUber Hit with €825M GDPR Fine for Fully Automated Driver Suspensions

Uber was fined €825 million by the Dutch data‑protection authority for using AI to suspend driver accounts without human review, breaching GDPR’s ban on fully automated decisions that significantly affect individuals. The case highlights the need for documented human‑in‑the‑loop controls and audit‑ready privacy evidence in SOC 2 programs.

High · Aug 25, 2026 · Security Affairs
Read Full Intelligence Brief →
THREAT INTELLT BRIEF🔍
LIVETHREAT BRIEFAnthropic Merges Claude Chat and Cowork Memory, Enabling Cross‑Product Data Sharing Unless Users Opt Out

Anthropic now shares the memory store between Claude Chat and Claude Cowork, making prior conversation context available across both services unless a user opts out. This creates a privacy‑risk scenario that SOC 2 and privacy‑compliance programs must track and evidence.

Medium · Aug 25, 2026 · ZDNet Security
Read Full Intelligence Brief →
THREAT INTELLT BRIEF🔍
LIVETHREAT BRIEFShrinking Patch Window Forces Organizations to Rethink Their Control Plane

Microsoft warns that the time between vulnerability discovery and patch deployment is collapsing, creating a gap attackers can exploit. This trend pressures SOC 2 controls around risk management and change management, making continuous evidence collection essential for audit readiness.

Medium · Aug 25, 2026 · Microsoft Security Blog
Read Full Intelligence Brief →
THREAT INTELLT BRIEF🌊
LIVETHREAT BRIEFMassive DDoS Attack Disrupts Norway’s Government Digital Services, Affecting Public‑Login and eSignature Platforms

A coordinated DDoS flood targeted the shared digital infrastructure run by Norway’s Digitalisation Agency and its provider Vivicta, rendering public‑service logins, e‑IDs and e‑signatures intermittently unavailable. The incident underscores the importance of SOC 2 Availability controls and continuous evidence of mitigation for audit readiness.

High · Aug 25, 2026 · BleepingComputer
Read Full Intelligence Brief →
ADVISORYLT BRIEF📋
LIVETHREAT BRIEFMicrosoft Teams Adds Admin Policy to Auto‑Block External Meeting Bots

Microsoft Teams now lets administrators automatically block detected external meeting bots, removing organizer approval. The change provides a concrete access‑control measure that aligns with SOC 2 audit requirements for logical access and evidencing policy enforcement.

Informational · Aug 25, 2026 · TechRepublic Security
Read Full Intelligence Brief →
THREAT INTELLT BRIEF🔍
LIVETHREAT BRIEFAttackers Obfuscate IP Addresses as Hostnames to Bypass Cloud Metadata Service Filters (SSRF)

Researchers observed threat actors submitting hostnames that resolve to the cloud metadata IP 169.254.169.254, allowing SSRF attempts to evade string‑based blocklists. The technique highlights a control‑gap that SOC 2 audits must address, and continuous monitoring can provide the needed audit evidence.

Medium · Aug 25, 2026 · SANS Internet Storm Center
Read Full Intelligence Brief →
ADVISORYLT BRIEF📋
LIVETHREAT BRIEFCritical Vulnerability in NVIDIA NemoClaw Enables Malicious Webpage to Poison Local AI Models

Oasis Security reported a zero‑day weakness in NVIDIA’s NemoClaw that lets a malicious webpage take control of a local Ollama instance and inject hidden instructions into the AI model. The issue highlights the need for SOC 2‑aligned control mapping and continuous evidence of model integrity.

High · Aug 25, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTELLT BRIEF🔍
LIVETHREAT BRIEFSocial Engineering Exploits Identity Verification in Onboarding & Account Recovery, Raising SOC 2 Access Control Concerns

Attackers are impersonating employees to bypass MFA during onboarding and password‑reset processes, a tactic linked to the 2025 M&S ransomware breach. The scenario highlights gaps in SOC 2 logical‑access controls and the need for documented, auditable identity‑verification procedures.

High · Aug 25, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTELLT BRIEF🔍
LIVETHREAT BRIEFInterpol Operation Jackel IV Exposes Surge in Sextortion and Fraud by West African Crime Rings

Interpol’s eight‑month Jackel IV operation arrested dozens of suspects and revealed a rising trend of sextortion against minors and large‑scale fraud. The episode underscores the need for robust security awareness programs to satisfy SOC 2 people‑control requirements.

High · Aug 25, 2026 · Help Net Security
Read Full Intelligence Brief →
ADVISORYLT BRIEF🎣
LIVETHREAT BRIEFWhatsApp Adds Multi‑Passkey Support for Phishing‑Resistant Sign‑Ins on iOS and Android

Meta announced WhatsApp now supports multiple passkeys per account, letting users on iOS and Android log in with phishing‑resistant authentication. For compliance teams, the move underscores the need to align access‑control policies with modern credential standards.

Informational · Aug 25, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTELLT BRIEF🔍
LIVETHREAT BRIEFFideo Lens Enables Rapid Mapping of Hidden Identity and Device Relationships for Fraud Detection

Fideo Intelligence introduced Fideo Lens, a SaaS platform that visualises hidden connections among identities, accounts and devices to accelerate fraud investigations. For SOC 2‑ready firms, the tool provides continuous evidence that maps directly to security‑monitoring controls.

Informational · Aug 25, 2026 · Help Net Security
Read Full Intelligence Brief →
ADVISORYLT BRIEF📋
LIVETHREAT BRIEFCisco‑Teleport Partnership Pushes “Infrastructure Identity” to Secure Machine‑to‑Machine Access

Cisco and Teleport announced a strategic partnership to deliver “Infrastructure Identity,” a cryptographic, short‑lived identity model for humans, workloads, and AI agents. The approach replaces static credentials, aligning with SOC 2 access‑control requirements and providing continuous audit evidence.

Informational · Aug 25, 2026 · Cisco Security Blog
Read Full Intelligence Brief →
ADVISORYLT BRIEF📋
LIVETHREAT BRIEFWhatsApp Rolls Out Multi‑Passkey Support and Alphanumeric Two‑Step Verification

WhatsApp now lets users create separate passkeys for Android and iOS and replaces its six‑digit PIN with an alphanumeric password, helping to curb credential‑theft attacks—a direct relevance to SOC 2 access‑control requirements.

Medium · Aug 25, 2026 · BleepingComputer
Read Full Intelligence Brief →
THREAT INTELLT BRIEF🔍
LIVETHREAT BRIEFUK Government Proposes Secret Powers to Ban “Risky” Tech Suppliers Across Critical Sectors

The UK is amending its Cyber Security and Resilience Bill to let ministers secretly block technology vendors deemed a national‑security risk, affecting energy, health, transport and other critical sectors. For SOC 2‑ready organisations this creates an immediate need for auditable third‑party monitoring and vendor‑risk documentation.

High · Aug 25, 2026 · The Record
Read Full Intelligence Brief →
THREAT INTELLT BRIEF🦠
LIVETHREAT BRIEFFake OpenAI Codex Download Lures macOS Users into Executing Malware via Terminal

A sponsored ad redirects macOS users to a counterfeit OpenAI Codex page that instructs them to paste a malicious command into Terminal, installing a universal Mach‑O binary. The technique highlights the need for robust SOC 2 access‑control policies and security‑awareness training.

High · Aug 25, 2026 · Help Net Security
Read Full Intelligence Brief →
ADVISORYLT BRIEF📋
LIVETHREAT BRIEFCISA Red Team Advisory Shows Full Domain Compromise When Detection Gaps Exist

CISA’s red‑team assessments revealed that one organization failed to detect a full domain compromise while another contained it, underscoring the importance of SOC 2 detection and response controls for audit readiness.

High · Aug 25, 2026 · CISA Advisories
Read Full Intelligence Brief →
Page 1 of 294