Breach Watch
Written for risk decisions, not headlines.
Breach, ransomware, vulnerability, advisory and threat intelligence, classified by LiveThreat and analysed in an ADTP brief for every item.
Showing 20 of 4,053
BREACH WATCH BRIEF
Critical Vulnerability in AWS Bedrock AgentCore Allows Single Prompt to Hijack Entire Fleet
A newly disclosed vulnerability in AWS Bedrock AgentCore lets an attacker use one crafted AI prompt to take over every agent in an organization’s AWS environment. The flaw underscores the need for continuous AI‑service monitoring and control‑mapping to meet audit requirements.
BREACH WATCH BRIEF
Critical Validation Flaws in Cisco Nexus Switches Enable Remote Code Execution and Denial‑of‑Service
Cisco disclosed five critical CVEs affecting Nexus 3000 and 9000 switches that allow arbitrary code execution with root privileges or forced reload when NX‑API, NGOAM, or MPLS OAM are active. The flaws underscore the need for continuous vulnerability‑management and configuration‑control evidence to satisfy audit and assurance requirements.
BREACH WATCH BRIEF
Multiple High‑Severity Auth Bypass & Credential Flaws in Red Lion N‑Tron 700 Series Switches
Seven critical vulnerabilities in Red Lion N‑Tron 700 series switches allow unauthenticated admin access, configuration tampering, and scripted reboot loops. The flaws expose gaps in authentication and change‑management controls that auditors and regulators scrutinize for trust‑worthiness.
BREACH WATCH BRIEF
Critical Deserialization, SSRF, and Hard‑Coded Credential Flaws in Grid Protection Alliance openPDC/openHistorian
CISA reports six CVEs (CVSS 9.8) in openPDC and openHistorian that enable unauthenticated attackers to execute arbitrary code or perform SSRF. The flaws test the control objective of secure software lifecycle management, a key trust signal for energy‑sector auditors.
BREACH WATCH BRIEF
Stored XSS (CVE‑2026‑105269) in Satel Netco Design Enables Arbitrary Script Execution
Satel Netco Design versions before v2.1.7 contain a stored cross‑site scripting flaw (CVE‑2026‑105269) that lets a privileged network operator inject malicious web content. Exploitation can lead to script execution, file enumeration, and possible code execution, raising compliance concerns for communications operators.
BREACH WATCH BRIEF
Critical Arbitrary File Access Flaw (CVE‑2026‑21589) in Atlassian Data Center Products Under Active Exploitation
A CVSS 9.3 path‑traversal bug (CVE‑2026‑21589) affecting multiple Atlassian Data Center applications is being actively exploited to read sensitive files. Enterprises must patch, tighten access controls, and capture evidence of remediation to meet audit and trust requirements.
BREACH WATCH BRIEF
Improper Access Control in ProFTPD (CVE‑2015‑3306) Enables Remote File Read/Write
ProFTPD versions before 1.3.5a allow unauthenticated attackers to read or overwrite arbitrary files via FTP commands. The flaw underscores the need for auditable access‑control evidence and continuous monitoring to satisfy trust‑focused compliance reviews.
BREACH WATCH BRIEF
Critical Path Traversal (CVE‑2021‑3199) in ONLYOFFICE Docs Enables Remote Code Execution
A path traversal flaw in ONLYOFFICE Docs (CVE‑2021‑3199) allows an attacker to embed a '..' sequence in an image‑upload request, bypassing JWT checks and potentially executing arbitrary code on the server. The vulnerability affects both SaaS and on‑premises deployments, raising immediate concerns for organizations that must prove secure third‑party component management.
BREACH WATCH BRIEF
Cleartext Storage of Sensitive Data in Strapi (CVE‑2023‑22894) Risks Admin‑Panel Confidentiality
Strapi’s CMS stores user details in cleartext, allowing anyone with admin‑panel access to read them. The issue also enables a chain to remote code execution, highlighting the need for encryption‑at‑rest controls and audit‑ready evidence.
BREACH WATCH BRIEF
CVE‑2016‑3081: Apache Struts Command Injection Allows Remote Code Execution
Apache Struts versions with Dynamic Method Invocation enabled are vulnerable to a command‑injection flaw (CVE‑2016‑3081) that can lead to remote code execution. The issue highlights the need for continuous vulnerability management and auditable patch evidence to satisfy trust‑focused compliance requirements.
BREACH WATCH BRIEF
ISC BIND Vulnerability (CVE‑2015‑5477) Allows Remote Denial‑of‑Service via TKEY Queries
A data‑processing error in ISC BIND can be triggered by malicious TKEY queries, causing the DNS service to crash. The issue highlights the need for continuous patch management and auditable evidence of service‑availability controls.
BREACH WATCH BRIEF
Multiple Zero-Day Vulnerabilities Disclosed in Adobe Photoshop, Apple macOS, Foxit Reader, and Microsoft Windows Drivers
Cisco Talos disclosed seven new CVEs affecting Adobe, Apple, Foxit, and Microsoft products; patches are available. The findings underscore the need for continuous vulnerability management and auditable patch‑deployment evidence.
BREACH WATCH BRIEF
Critical Pre‑Auth SSRF Flaw (CVE‑2026‑102255) in SonicWall SMA1000 Appliances Allows Unauthenticated Access
SonicWall disclosed a CVSS 10.0 pre‑authentication SSRF vulnerability (CVE‑2026‑102255) affecting SMA1000 models, enabling unauthenticated attackers to reach internal functions. The flaw underscores the need for continuous control verification and audit‑ready evidence around network perimeter protections.
BREACH WATCH BRIEF
Critical Pre‑Auth SSRF Vulnerability (CVSS 10.0) in SonicWall SMA1000 Remote‑Access Appliances
SonicWall disclosed a pre‑authentication SSRF flaw in its SMA1000 remote‑access gateways that scores 10.0 CVSS. The vulnerability allows unauthenticated attackers to reach internal services, underscoring the need for robust patch‑management and continuous evidence of remediation for audit readiness.
BREACH WATCH BRIEF
Critical Remote‑Code‑Execution Flaw in LMCache Allows Unauthenticated Attackers to Run Arbitrary Code
A newly disclosed vulnerability in the open‑source LMCache library enables unauthenticated attackers to execute code on LLM serving nodes. The issue affects AI‑focused SaaS and cloud providers and underscores the need for continuous component inventory and access‑control evidence for audit readiness.
BREACH WATCH BRIEF
Arbitrary File Access Vulnerability (CVE‑2026‑21589) Discovered in Atlassian Server Products
Atlassian disclosed CVE‑2026‑21589, an arbitrary file‑access flaw that lets unauthenticated actors read any file on the web server. The issue affects unpatched Server and Data Center editions of Confluence, Jira, Bitbucket, and related tools, raising immediate confidentiality concerns for organizations that rely on these platforms.
BREACH WATCH BRIEF
Exploitation Attempts Against Atlassian Data Center Arbitrary File Access Vulnerability (CVE‑2026‑21589)
Attackers have begun exploiting CVE‑2026‑21589, a critical arbitrary‑file‑access flaw in Atlassian’s self‑managed Data Center suite. The vulnerability can expose sensitive configuration files and credentials, underscoring the need for rapid patching and verifiable control evidence for audit readiness.
BREACH WATCH BRIEF
Critical Arbitrary File Access Flaw (CVE‑2026‑21589) in Atlassian Data Center Products Prompted Exploitation Within Two Hours
A CVE‑2026‑21589 vulnerability (CVSS 9.3) allows unauthenticated file reads on Bitbucket, Confluence, Jira Service Management and Jira Software Data Center. Threat actors began probing vulnerable installations within two hours of public disclosure. The flaw highlights the need for continuous control mapping and auditable evidence of file‑access safeguards.
BREACH WATCH BRIEF
Critical SSRF Vulnerability (CVE‑2026‑102255) in SonicWall SMA1000 Gateways
SonicWall disclosed a max‑severity server‑side request forgery (SSRF) flaw (CVE‑2026‑102255) affecting SMA1000 series appliances. The vulnerability allows unauthenticated attackers to force the device to issue internal requests, potentially leading to unauthorized operations. Organizations must patch promptly to maintain audit‑ready control assurance.
BREACH WATCH BRIEF
Google Patches Critical Use‑After‑Free Flaws in Chrome & ChromeOS (CVE‑2026‑106197, CVE‑2026‑106358, CVE‑2026‑106240)
Google released stable updates for Chrome and ChromeOS that fix 247 security issues, including four Critical use‑after‑free and type‑confusion vulnerabilities. Organizations must verify patch deployment to maintain audit‑ready evidence of vulnerability management.
Breach Watch intelligence is provided by LiveThreat, a product of a founding sponsor of the association. Every ADTP brief carries LiveThreat's analysis and links the original source.
Practitioner briefings
Written by the association: what the week's intelligence means for the controls you run.
Reading a vendor's breach notice for what it does not say
A practitioner checklist for turning a supplier notification into an evidence request and a monitoring change.
Where AI inventory efforts stall, and the control that unblocks them
Findings from practitioner roundtables on AI governance programs in their first year.
Evidence reuse across customer diligence and audit
How practitioners are organizing one evidence base to serve buyers and auditors at the same time.
Global Privacy Control signals and state opt-out obligations
What a site must do when it sees a GPC signal, and how to evidence it.
Get the digest
No membership required. Confirm by email; unsubscribe in one click.