Written for risk decisions, not headlines.

Breach, ransomware, advisory and threat intelligence, classified by LiveThreat and refreshed every half hour. Free members receive the digest and set their own topics.

3Last 24 hours
195Last 7 days
2Critical, 7 days
BREACHHighSep 27, 2026

Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Know what was tested before your SAP ECC migration goes live In this Help Net Security interview, Guilherme Joventino, COO of MIGNOW, explains why some large companies plan to stay on ECC past the 2027 deadline and pay SAP for extended support until 2030. The interview covers what that choice may cost, why fear of disruption stalls projects more often …

Help Net SecurityLiveThreat brief →
BREACHCriticalSep 25, 2026

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," BitGet said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain

The Hacker NewsLiveThreat brief →
BREACHHighSep 24, 2026

OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files

An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said. The portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not public, but no personal

The Hacker NewsLiveThreat brief →
BREACHHighSep 24, 2026

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts –

The Hacker NewsLiveThreat brief →
BREACHHighSep 24, 2026

Nightmare Eclipse Reveals Name, Story Behind MS Zero-Days

Abdelhamid Naceri Says His Microsoft Dispute Preceded 12 Zero-Day Reports Former Microsoft employee Abdelhamid Naceri identified himself as the researcher behind a string of Windows and Defender zero-day disclosures, including BigDiskBuster, saying the releases followed a bitter employment and vulnerability-reporting dispute with the company.

DataBreachTodayLiveThreat brief →
BREACHHighSep 23, 2026

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project." Mail sent to it opens an issue in that project, authored

The Hacker NewsLiveThreat brief →
BREACHHighSep 23, 2026

ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack

ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead

Security AffairsLiveThreat brief →
BREACHHighSep 23, 2026

ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack

ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead

Security AffairsLiveThreat brief →
BREACHHighSep 22, 2026

Ambry Genetics Pays $700K HIPAA Fine in Phishing Breach

Settlement Comes After Firm Paid Nearly $12.3M to Settle Civil Claim for Same Hack A genetics testing lab has agreed to pay a $700,000 HIPAA settlement and improve its security practices in the wake of a 2020 phishing hack that affected 225,370 patients. The firm paid a $12.25 million civil class action settlement in 2023 for the same breach. But the firm faces other legal woes.

DataBreachTodayLiveThreat brief →
Page 1 of 9 Older →

Intelligence provided by LiveThreat, a product of a founding sponsor of the association. Each brief links to LiveThreat's analysis and the original source. RSS: Breach & Ransomware Watch Advisories & Threat Intel

Practitioner briefings

Written by the association: what the week's intelligence means for the controls you run.

Advisory · high

Reading a vendor's breach notice for what it does not say

A practitioner checklist for turning a supplier notification into an evidence request and a monitoring change.

TPR CYB
Read
Briefing · medium

Where AI inventory efforts stall, and the control that unblocks them

Findings from practitioner roundtables on AI governance programs in their first year.

AIG GRC
Read
Research

Evidence reuse across customer diligence and audit

How practitioners are organizing one evidence base to serve buyers and auditors at the same time.

GRC TRS
Read
Advisory · medium

Global Privacy Control signals and state opt-out obligations

What a site must do when it sees a GPC signal, and how to evidence it.

PRV
Read

Get the digest

No membership required. Confirm by email; unsubscribe in one click.