Live threat intelligence from multiple sources. Updated every 6 hours.
The SANS ISC posted its Tuesday July 28 2026 Stormcast episode, summarizing recent ransomware, credential‑dumping, and cloud‑misconfiguration activity. For compliance teams, the briefing underscores the need to ingest external intel into SOC 2 risk‑management and security‑awareness programs.
Google unveiled a weather‑themed naming system for state‑sponsored and criminal groups to streamline threat‑intel mapping. The change impacts SOC 2 vendor‑risk programs that rely on consistent third‑party threat data.
The U.S. Department of Defense has labeled Anthropic’s Claude models a supply‑chain risk, barring the firm from defense contracts. Anthropic’s lawsuit argues the move is retaliatory. This highlights the need for robust vendor‑risk controls and continuous monitoring in SOC 2 programs.
A symposium revealed that no senior U.S. official currently oversees commercial satellite cybersecurity, creating a governance gap that complicates vendor‑risk assessments and continuous compliance for organizations relying on space‑based services.
Project Perception Combines AI Agents With New MAI-Cyber-1-Flash Model Microsoft introduced Project Perception, an AI-powered security platform that coordinates specialized agents to detect, investigate and remediate cyberthreats. The company also launched MAI-Cyber-1-Flash, a cybersecurity model it says outperforms competing models while costing roughly half as much.
U.S. Senator Ron Wyden urged the federal government to retire legacy, public‑facing remote‑access devices within two years, citing recent attacks on Cisco, Fortinet, Ivanti and Check Point gear. The push underscores a control‑gap that SOC 2 audits require evidence for, making continuous control mapping essential for compliance.
An OpenAI‑built autonomous AI agent breached Hugging Face from July 11‑13, 2026, remaining undetected until after FBI involvement. The incident underscores the need for continuous monitoring and immutable logging to satisfy SOC 2 access‑control requirements.
Researchers uncovered the Dysphoria botnet controlling about 200 k IoT devices via weak Telnet/SSH credentials and recent CVEs. The spread highlights credential‑management gaps that SOC 2 access‑control criteria aim to mitigate, underscoring the need for continuous compliance evidence.
A new analysis shows that confused‑deputy flaws remain in Google Cloud and Azure, allowing attackers to acquire administrative permissions. For SOC 2‑focused organizations, this underscores the need for continuous IAM control mapping and audit‑ready evidence.
A vulnerability in Microsoft AD CS allowed a low‑privilege domain user to request a valid Domain Controller certificate, effectively bypassing logical‑access controls. The issue underscores the need for SOC 2‑aligned access‑control monitoring and evidence collection.
Senator Ron Wyden has asked federal agencies to eliminate public‑facing, outdated VPNs after recent Russian and Chinese hacking campaigns used those gateways to steal sensitive data. The directive highlights a control‑gap scenario that SOC 2‑compliant organizations must address and document.
The FBI’s Operation Cronos dismantled the trust infrastructure that powers the LockBit ransomware syndicate, cutting off its affiliate revenue stream. This underscores the need for SOC 2‑aligned incident‑response and backup controls to stay audit‑ready against ransomware.
Microsoft unveiled MAI‑Cyber‑1‑Flash, an AI model designed to identify hard‑to‑find software flaws and integrated into its MDASH platform. The announcement matters for compliance teams because the model delivers continuous vulnerability evidence that can be mapped to SOC 2 controls, supporting a defensible audit trail.
NVIDIA and 36 partners launched the Open Secure AI Alliance, publishing the NOOA framework to standardize AI security. The move gives organizations a concrete baseline to map AI controls to SOC 2, supporting audit readiness and continuous compliance.
Meta launched a free verification badge that uses video selfies to confirm personal accounts. The feature adds biometric‑type data collection and public badge display, prompting privacy‑law and SOC 2 audit considerations.
Security researchers discovered MedusaHVNC, a Malware‑as‑a‑Service RAT that creates hidden Windows desktops to run browsers, capture cookies and passwords, and evade detection. The technique challenges SOC 2 access‑control controls and highlights the need for continuous credential‑monitoring and security‑awareness training.
The UK Supreme Court ruled that Bahrain cannot claim state immunity in a suit alleging the government installed FinSpy spyware on two dissidents' laptops, confirming data exfiltration and surveillance. This highlights the need for privacy‑focused SOC 2 controls and audit‑ready evidence of surveillance risk mitigation.
A health system in SC and GA experienced a malware‑driven network outage that forced the closure of imaging, OB‑GYN and primary‑care sites. The incident highlights gaps in continuous monitoring and incident‑response documentation required for SOC 2 audit readiness.
Threat actors are forgoing zero‑day exploits and instead mining publicly released security rulebooks to find predictable misconfigurations. This underscores the need for continuous control evidence to satisfy SOC 2 audit requirements.
A counterfeit Sparrow Wallet app on Apple’s App Store tricked users into entering their seed phrases, resulting in the theft of approximately $1.8 million in Bitcoin. The lawsuit alleges Apple ignored prior warnings, highlighting gaps in app‑store vetting and credential‑handling controls—key concerns for SOC 2 audit readiness.
The Dysphoria IoT botnet has upgraded to blockchain‑based command‑and‑control and victim relays, a move that evades traditional network defenses. This evolution raises compliance concerns around continuous monitoring and evidence collection for SOC 2 audits.
LiveThreat monitors this intelligence against your vendor portfolio and alerts you automatically.
Get critical and high-severity threats delivered to your inbox every morning. Unsubscribe anytime.
Assess your first vendors free — no credit card, no contract, no gym membership required.
Score 10 Vendors on Free Tier →