Breach Watch
Written for risk decisions, not headlines.
Breach, ransomware, vulnerability, advisory and threat intelligence, classified by LiveThreat and analysed in an ADTP brief for every item.
Showing 20 of 2,381
BREACH WATCH BRIEF
Chinese‑Linked Hackers Ran Public Portal Giving Third Parties Access to Stolen Emails from Government, Health, and Religious Entities
State‑linked actors stole email archives from multiple Southeast Asian sectors and exposed them via an open portal. The breach highlights the need for continuous third‑party risk monitoring and audit‑ready evidence of vendor oversight.
BREACH WATCH BRIEF
Convicted Consultant Exploits Smart‑Contract Flaws to Steal $54 M from Uranium Finance Exchange
A cybersecurity consultant was convicted after abusing vulnerabilities in Uranium Finance’s smart contracts to siphon $54 million, forcing the exchange to shut down. The incident underscores the need for auditable secure‑development controls to satisfy trust and control‑assurance requirements.
BREACH WATCH BRIEF
Hackers Compromised an ASOS Employee Account to Send a Rogue Push Notification, Exposing Limited Customer Data
ASOS disclosed that attackers impersonated a trusted contact to gain an employee’s credentials, allowing them to push a fraudulent notification to customers and view limited personal information. The incident highlights the need for robust identity controls and security‑awareness programs to meet audit and trust requirements.
BREACH WATCH BRIEF
Hackers Breach Two South Korean Megachurches, Exposing Data of Up to 850,000 Members
Two of South Korea's largest Protestant churches suffered cyberattacks that led to the theft of personal, financial, and internal records for hundreds of thousands of congregants. The breach highlights gaps in access control and privileged account management, underscoring the need for continuous control assurance.
BREACH WATCH BRIEF
ASOS Data Breach Linked to Social Engineering Credential Theft Exposes Customer Personal Info
ASOS confirmed that a social‑engineering attack stole an employee’s login credentials, allowing attackers to access third‑party platforms and expose names and contact details. The incident underscores the need for continuous identity‑access monitoring and third‑party oversight for audit readiness.
BREACH WATCH BRIEF
MonsterCloud Owner Charged with $19 M Fraud After Secretly Paying Ransomware Decryptors
The DOJ has indicted MonsterCloud’s owner for billing ransomware victims while covertly paying attackers to obtain decryption keys, exposing a critical gap in third‑party oversight. Organizations must tighten vendor risk controls to maintain audit‑ready evidence of due diligence.
BREACH WATCH BRIEF
Oracle Health’s Cerner EHR Breach Affects 20 Million Patients After Stolen‑Credential Attack on Legacy Servers
An unknown actor used stolen credentials to breach legacy Cerner EHR servers, exposing the health data of about 20 million patients. The breach underscores the need for continuous third‑party risk monitoring and documented migration controls to satisfy audit and compliance expectations.
BREACH WATCH BRIEF
Compromised “tensorlake” npm Package Delivers Credential‑Stealing Worm via Supply‑Chain Attack
The npm package tensorlake version 0.5.144 was published with malicious code that harvests credentials and runs remote code. The incident underscores the importance of continuous third‑party risk monitoring and audit‑ready evidence for supply‑chain security.
BREACH WATCH BRIEF
CyrusOne Data Centre Operator Breach Exposes 373 K Corporate Contacts
CyrusOne suffered a data‑centre breach in August 2026 that resulted in the public release of 373 000 corporate email addresses, names, job titles and support‑ticket details. The incident underscores the need for continuous third‑party risk monitoring and audit‑ready evidence of vendor oversight.
BREACH WATCH BRIEF
FBI Warns FortiBleed Credential Leak Enables Lockout of FortiGate VPN Administrators
The FBI disclosed that threat actors are using the FortiBleed leak of plaintext FortiGate credentials to gain unauthorized VPN access, create rogue admin accounts, and lock out legitimate administrators. This underscores the need for robust access‑control policies, MFA, and continuous monitoring to satisfy audit‑readiness requirements.
BREACH WATCH BRIEF
Hackers Hijack Google and Global Domains via Compromised ccTLD Registries
Attackers breached the operators of .GH, .SL and .AS ccTLD registries, altered DNS records and obtained valid HTTPS certificates for Google and other brands. The incident highlights the need for continuous third‑party risk monitoring and certificate‑transparency visibility to maintain audit‑ready control assurance.
BREACH WATCH BRIEF
Attackers Hijack .gh, .sl, and .as Registries to Obtain Fraudulent Certificates for Google Domains
Attackers breached the Ghana, Sierra Leone and American Samoa ccTLD registries and issued unauthorized HTTPS certificates for Google domains. The incident highlights the need for continuous third‑party risk monitoring and PKI oversight to protect brand integrity.
BREACH WATCH BRIEF
Hackers Access and Copy Backup Files of Arizona Court System, Exposing 1.3 Million Records
Criminal hackers used a phishing email to breach Arizona’s court backup files, stealing personal and child‑care data for over 1.3 million people. The event underscores the need for robust access controls and continuous security‑awareness programs to satisfy audit and compliance expectations.
BREACH WATCH BRIEF
Dread Dark Web Forum Hijacked; Operators Claim Control of Domain Keys
The Dread dark‑web forum was seized by unknown actors who now control its domain‑name keys, though they say they will not leak user data. This highlights the need for continuous monitoring of cryptographic assets to maintain audit‑ready evidence of control.
BREACH WATCH BRIEF
Attackers Hijack ASOS Mobile App to Display Fake ‘Store Hacked’ Notification
Attackers injected a fraudulent pop‑up into the ASOS shopping app, claiming the retailer’s Snowflake data warehouse was compromised and warning customers of a breach. The incident highlights gaps in oversight of third‑party communication services and the need for continuous control‑assurance evidence around vendor access.
BREACH WATCH BRIEF
AI‑Powered Penetration Testing Tool ‘Artex’ Linked to Theft of 66,000 South Korean Bank Customers’ Data
South Korean authorities say the open‑source AI tool Artex was used to automate vulnerability discovery and exfiltrate personal data from seven banks, affecting 66 000 individuals. The case highlights the need for documented governance of AI‑enabled security tools to satisfy audit and control‑assurance requirements.
BREACH WATCH BRIEF
FortiBleed Credential‑Harvesting Campaign Compromises 86,644 Fortinet FortiGate Firewalls Worldwide
A coordinated FortiBleed campaign used leaked and weakly‑hashed Fortinet admin credentials to take control of 86,644 firewalls across 194 countries. The breach underscores the need for strong privileged‑access controls and continuous audit evidence for compliance readiness.
BREACH WATCH BRIEF
Senate Passes Health Care Cybersecurity & Resiliency Act After Change Healthcare Ransomware Breach Exposes 190 Million Records
A ransomware attack on Change Healthcare compromised the health data of 190 million people. In response, the Senate enacted a new cybersecurity law that mandates minimum security standards and vendor oversight for all private health‑care entities. This underscores the need for continuous vendor risk monitoring and audit‑ready evidence.
BREACH WATCH BRIEF
ShinyHunters Extorted Boeing‑Spun‑Off Unit After Exploiting Oracle PeopleSoft Zero‑Day
ShinyHunters leveraged CVE‑2026‑35273 in Oracle PeopleSoft to steal data from a Boeing‑divested business unit and demand ransom. The incident illustrates why continuous third‑party risk monitoring and patch‑validation are essential for audit readiness.
BREACH WATCH BRIEF
Hackers Hijack Three ccTLD Registries to Issue Unauthorized HTTPS Certificates for Google Domains
Attackers seized control of the .gh, .sl and .as country‑code domain registries and used that access to obtain fraudulent HTTPS certificates for Google and other large brands. The incident underscores the importance of continuous third‑party risk monitoring and certificate‑transparency checks for audit‑ready control assurance.
Breach Watch intelligence is provided by LiveThreat, a product of a founding sponsor of the association. Every ADTP brief carries LiveThreat's analysis and links the original source.
Practitioner briefings
Written by the association: what the week's intelligence means for the controls you run.
Reading a vendor's breach notice for what it does not say
A practitioner checklist for turning a supplier notification into an evidence request and a monitoring change.
Where AI inventory efforts stall, and the control that unblocks them
Findings from practitioner roundtables on AI governance programs in their first year.
Evidence reuse across customer diligence and audit
How practitioners are organizing one evidence base to serve buyers and auditors at the same time.
Global Privacy Control signals and state opt-out obligations
What a site must do when it sees a GPC signal, and how to evidence it.
Get the digest
No membership required. Confirm by email; unsubscribe in one click.