Written for risk decisions, not headlines.

Breach, ransomware, advisory and threat intelligence, classified by LiveThreat and refreshed every half hour. Free members receive the digest and set their own topics.

3Last 24 hours
195Last 7 days
2Critical, 7 days
THREAT INTELHighSep 27, 2026

Rydox Admin Faces 20 Years After Selling Stolen Data and Fraud Tools

Kosovo national Ardit Kutleshi pleaded guilty to running Rydox, a cybercrime marketplace that sold stolen identities and credentials for years. Ardit Kutleshi, 28 years old and a citizen of Kosovo, pleaded guilty last week to building and running the cybercrime marketplace Rydox. The Rydox marketplace has been active since February 2016; it facilitated over 7,600

Security AffairsLiveThreat brief →
THREAT INTELHighSep 26, 2026

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and

The Hacker NewsLiveThreat brief →
THREAT INTELHighSep 26, 2026

Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem

Exploit.in data shows how a 2005 cybercrime forum helped shape today’s ransomware ecosystem, with users and practices surviving for decades. Ransomnews researcher Dancho Danchev dug up a database dump of Exploit.in covering its first three years, from February 2005 to May 2008, and the numbers inside it tell a story about Russian cybercrime that enforcement

Security AffairsLiveThreat brief →
THREAT INTELHighSep 26, 2026

Zero Trust for AI Agents Starts With Fixing Zero Visibility

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to

The Hacker NewsLiveThreat brief →
THREAT INTELMediumSep 26, 2026

7-Year, $11.6B Anthropic Deal Drives Akamai Cloud Buildout

CPU-Based Agreement With Anthropic Will Require Major Cloud Capacity From Akamai San Francisco-based frontier AI lab Anthropic committed $11.6 billion over seven years to Akamai cloud infrastructure for CPU-based AI workloads, giving Boston-area Akamai its largest contract ever and triggering a $5.5 billion capacity buildout ahead of revenue beginning in 2027.

DataBreachTodayLiveThreat brief →
THREAT INTELHighSep 26, 2026

US Appeals Court Backs Pentagon Blacklisting of Anthropic

D.C. Circuit says Claude’s built-in restrictions can qualify as a supply chain risk A federal three judge panel gave the U.S. Department of Defense the go-ahead to continue blacklisting Anthropic, a setback in the artificial intelligence giant's bid to take on the Trump administration in court. The ruling may dissuade companies from working with Anthropic.

DataBreachTodayLiveThreat brief →
THREAT INTELHighSep 25, 2026

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below - actions-cool/issues-helper actions-cool/maintain-one-comment Visiting either of the repositories now shows the message: "Access to this

The Hacker NewsLiveThreat brief →
THREAT INTELHighSep 25, 2026

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

The Hacker NewsLiveThreat brief →
Page 1 of 18 Older →

Intelligence provided by LiveThreat, a product of a founding sponsor of the association. Each brief links to LiveThreat's analysis and the original source. RSS: Breach & Ransomware Watch Advisories & Threat Intel

Practitioner briefings

Written by the association: what the week's intelligence means for the controls you run.

Advisory · high

Reading a vendor's breach notice for what it does not say

A practitioner checklist for turning a supplier notification into an evidence request and a monitoring change.

TPR CYB
Read
Briefing · medium

Where AI inventory efforts stall, and the control that unblocks them

Findings from practitioner roundtables on AI governance programs in their first year.

AIG GRC
Read
Research

Evidence reuse across customer diligence and audit

How practitioners are organizing one evidence base to serve buyers and auditors at the same time.

GRC TRS
Read
Advisory · medium

Global Privacy Control signals and state opt-out obligations

What a site must do when it sees a GPC signal, and how to evidence it.

PRV
Read

Get the digest

No membership required. Confirm by email; unsubscribe in one click.