Live threat intelligence from multiple sources. Updated every 6 hours.
IDScan.net disclosed that an outside party accessed more than 153 million driver‑license records stored in its cloud platform. The breach highlights the need for continuous vendor oversight and auditable access‑control evidence to satisfy governance and risk frameworks.
A Ukrainian developer for the Conti ransomware gang was sentenced to four years after pleading guilty to wire‑fraud conspiracy. The case underscores the importance of ransomware‑focused incident‑response and security‑awareness programs for audit readiness.
Anthropic’s threat report reveals that publicly available Claude models are being weaponized by low‑skill actors to automate reconnaissance, exploitation, and data exfiltration across government, fintech, and SaaS targets. The finding highlights the need for continuous AI‑governance controls and audit‑ready evidence.
Anthropic’s Threat Intelligence report documents a surge in malicious AI use, from credential harvesting to propaganda and weapons research. The rise of AI‑enabled attack automation stresses the need for AI governance controls that can be mapped to a unified control framework for audit readiness.
CISA added five actively exploited flaws—including CVE‑2026‑42016, an 8.1‑rated authorization bypass in JFrog Artifactory—to its KEV catalog. The bug lets unauthenticated attackers gain privileged repository access, highlighting the need for robust access‑control evidence and third‑party risk monitoring.
The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN gateways (CVE‑2026‑85102, CVE‑2026‑85103) are likely to be exploited soon, allowing remote code execution. Organizations must patch immediately to maintain compliance‑ready evidence of vulnerability management.
Security operations centers are reporting a sharp rise in alerts caused by internal AI tools and agents, stretching analyst capacity. The trend underscores the need for formal AI governance controls to provide continuous assurance and audit evidence.
A coordinated campaign used OpenAI‑generated agents to publish malicious RubyGems packages that were automatically consumed by RubyDoc, resulting in remote code execution on the documentation servers. The incident underscores the importance of continuous supply‑chain monitoring and vendor‑risk evidence for audit readiness.
The White House announced Project Watershed 250, a pilot delivering free cybersecurity technology to Texas water utilities to address systemic OT hygiene gaps. The initiative underscores the need for documented governance and continuous monitoring to meet audit‑readiness expectations.
A threat actor used large‑language‑model agents to automate attacks against unpatched PaperCut NG/MF servers, compromising 395 organizations and harvesting domain‑admin credentials. The incident underscores the importance of continuous access‑control assurance and rapid patch deployment for audit readiness.
FulcrumSec used hard‑coded GitHub and Azure DevOps tokens found in client‑side JavaScript to infiltrate Novo Nordisk’s cloud environment, exfiltrating more than 1 TB of drug research and patient data. The breach underscores the need for continuous credential‑management controls and audit‑ready evidence of secret‑handling policies.
Threat groups abused Anthropic’s Claude model to mass‑download and scan Android APKs, extracting hard‑coded credentials that were then used to breach SaaS providers, an airline, an energy firm, and a card‑shop operation. The episode highlights the need for AI‑governance controls and continuous vendor‑risk monitoring to maintain audit‑ready evidence.
The Florida Department of Highway Safety and Motor Vehicles confirmed that the ShinyHunters group accessed DMV records after stealing an officer’s login credentials from a personal device. The breach exposes driver‑license data and underscores the need for strict credential‑management controls in audit‑ready environments.
A threat actor used generative AI to craft and dispatch one million tailored fraud emails within three days, blending volume with credibility. The surge threatens any organization that relies on email for business communication, underscoring the need for robust phishing defenses and continuous security‑awareness programs.
The Florida DMV confirmed that the ShinyHunters extortion group accessed the DAVID driver database using credentials from a Plant City police officer that were stored on a personal device. More than 200,000 driver records were reportedly stolen, illustrating a critical lapse in privileged‑account protection that directly impacts audit and compliance readiness.
The Cybersecurity and Infrastructure Security Agency (CISA) issued a joint advisory urging organizations to adopt clearer breach‑notification and incident‑response protocols as cyber‑related outages increase. The guidance emphasizes transparent communication and documented response steps, a core requirement for audit‑ready control assurance programs.
Microsoft researchers uncovered a BEC operation that used generative AI to craft over one million invoice‑scam emails, impersonating executives and ServiceNow. The campaign tests the effectiveness of security‑awareness programs and highlights the need for continuous control‑assurance evidence.
A scan by Mysterium VPN uncovered 36,769 publicly reachable AI model servers and vector stores, with just 2 % presenting an HTTP authentication gate. The finding highlights a systemic access‑control gap that can undermine audit readiness and continuous control assurance.
Threat actors have used passkey‑styled phishing to steal Microsoft 365 credentials, leading to confirmed data exposure across multiple enterprises. The incident highlights the need for hardened authentication controls and continuous audit evidence for access‑control assurance.
Researchers warn that threat actors can subvert AI‑based defensive tools with crafted inputs, enabling silent network compromise. The scenario underscores the need for AI‑governance controls that provide continuous validation and audit evidence across frameworks.
GitLab disclosed CVE‑2026‑85706, a CVSS 10.0 path‑traversal flaw in the Repository Commits API that lets unauthenticated actors read arbitrary server files. The issue underscores the need for robust file‑access controls and auditable evidence of enforcement for compliance readiness.
LiveThreat monitors this intelligence against your vendor portfolio and alerts you automatically.
Get critical and high-severity threats delivered to your inbox every morning. Unsubscribe anytime.
Assess your first vendors free — no credit card, no contract, no gym membership required.
Score 10 Vendors on Free Tier →