Breach Watch

Written for risk decisions, not headlines.

Breach, ransomware, vulnerability, advisory and threat intelligence, classified by LiveThreat and analysed in an ADTP brief for every item.

59Last 24 hours
318Last 7 days
33Critical, 7 days

Showing 20 of 4,053

Vulnerability ADTP BRIEF ☁️

BREACH WATCH BRIEF

Critical Vulnerability in AWS Bedrock AgentCore Allows Single Prompt to Hijack Entire Fleet

A newly disclosed vulnerability in AWS Bedrock AgentCore lets an attacker use one crafted AI prompt to take over every agent in an organization’s AWS environment. The flaw underscores the need for continuous AI‑service monitoring and control‑mapping to meet audit requirements.

Cloud & Infrastructure Providers Vulnerability Exploit
Critical · Oct 8, 2026 · Dark Reading
Read the full brief →
Vulnerability ADTP BRIEF ☁️

BREACH WATCH BRIEF

Critical Validation Flaws in Cisco Nexus Switches Enable Remote Code Execution and Denial‑of‑Service

Cisco disclosed five critical CVEs affecting Nexus 3000 and 9000 switches that allow arbitrary code execution with root privileges or forced reload when NX‑API, NGOAM, or MPLS OAM are active. The flaws underscore the need for continuous vulnerability‑management and configuration‑control evidence to satisfy audit and assurance requirements.

Cloud & Infrastructure Providers Vulnerability Exploit Zero-Day Exploit
Critical · Oct 8, 2026 · BleepingComputer
Read the full brief →
Vulnerability ADTP BRIEF ☁️

BREACH WATCH BRIEF

Multiple High‑Severity Auth Bypass & Credential Flaws in Red Lion N‑Tron 700 Series Switches

Seven critical vulnerabilities in Red Lion N‑Tron 700 series switches allow unauthenticated admin access, configuration tampering, and scripted reboot loops. The flaws expose gaps in authentication and change‑management controls that auditors and regulators scrutinize for trust‑worthiness.

Manufacturing & Industrial Vulnerability Exploit
High · Oct 8, 2026 · CISA Advisories
Read the full brief →
Vulnerability ADTP BRIEF ☁️

BREACH WATCH BRIEF

Critical Deserialization, SSRF, and Hard‑Coded Credential Flaws in Grid Protection Alliance openPDC/openHistorian

CISA reports six CVEs (CVSS 9.8) in openPDC and openHistorian that enable unauthenticated attackers to execute arbitrary code or perform SSRF. The flaws test the control objective of secure software lifecycle management, a key trust signal for energy‑sector auditors.

Energy & Utilities Vulnerability Exploit
Critical · Oct 8, 2026 · CISA Advisories
Read the full brief →
Vulnerability ADTP BRIEF 👤

BREACH WATCH BRIEF

Stored XSS (CVE‑2026‑105269) in Satel Netco Design Enables Arbitrary Script Execution

Satel Netco Design versions before v2.1.7 contain a stored cross‑site scripting flaw (CVE‑2026‑105269) that lets a privileged network operator inject malicious web content. Exploitation can lead to script execution, file enumeration, and possible code execution, raising compliance concerns for communications operators.

Telecommunications Vulnerability Exploit
High · Oct 8, 2026 · CISA Advisories
Read the full brief →
Vulnerability ADTP BRIEF 👤

BREACH WATCH BRIEF

Critical Arbitrary File Access Flaw (CVE‑2026‑21589) in Atlassian Data Center Products Under Active Exploitation

A CVSS 9.3 path‑traversal bug (CVE‑2026‑21589) affecting multiple Atlassian Data Center applications is being actively exploited to read sensitive files. Enterprises must patch, tighten access controls, and capture evidence of remediation to meet audit and trust requirements.

Technology & SaaS Vulnerability Exploit
Critical · Oct 8, 2026 · Security Affairs
Read the full brief →
Vulnerability ADTP BRIEF 👤

BREACH WATCH BRIEF

Improper Access Control in ProFTPD (CVE‑2015‑3306) Enables Remote File Read/Write

ProFTPD versions before 1.3.5a allow unauthenticated attackers to read or overwrite arbitrary files via FTP commands. The flaw underscores the need for auditable access‑control evidence and continuous monitoring to satisfy trust‑focused compliance reviews.

Technology & SaaS Vulnerability Exploit
High · Oct 8, 2026 · CISA KEV
Read the full brief →
Vulnerability ADTP BRIEF ☁️

BREACH WATCH BRIEF

Critical Path Traversal (CVE‑2021‑3199) in ONLYOFFICE Docs Enables Remote Code Execution

A path traversal flaw in ONLYOFFICE Docs (CVE‑2021‑3199) allows an attacker to embed a '..' sequence in an image‑upload request, bypassing JWT checks and potentially executing arbitrary code on the server. The vulnerability affects both SaaS and on‑premises deployments, raising immediate concerns for organizations that must prove secure third‑party component management.

Technology & SaaS Vulnerability Exploit
Critical · Oct 8, 2026 · CISA KEV
Read the full brief →
Vulnerability ADTP BRIEF 💀

BREACH WATCH BRIEF

Cleartext Storage of Sensitive Data in Strapi (CVE‑2023‑22894) Risks Admin‑Panel Confidentiality

Strapi’s CMS stores user details in cleartext, allowing anyone with admin‑panel access to read them. The issue also enables a chain to remote code execution, highlighting the need for encryption‑at‑rest controls and audit‑ready evidence.

Technology & SaaS Vulnerability Exploit
High · Oct 8, 2026 · CISA KEV
Read the full brief →
Vulnerability ADTP BRIEF 📋

BREACH WATCH BRIEF

CVE‑2016‑3081: Apache Struts Command Injection Allows Remote Code Execution

Apache Struts versions with Dynamic Method Invocation enabled are vulnerable to a command‑injection flaw (CVE‑2016‑3081) that can lead to remote code execution. The issue highlights the need for continuous vulnerability management and auditable patch evidence to satisfy trust‑focused compliance requirements.

Technology & SaaS Vulnerability Exploit
High · Oct 8, 2026 · CISA KEV
Read the full brief →
Vulnerability ADTP BRIEF 🐛

BREACH WATCH BRIEF

ISC BIND Vulnerability (CVE‑2015‑5477) Allows Remote Denial‑of‑Service via TKEY Queries

A data‑processing error in ISC BIND can be triggered by malicious TKEY queries, causing the DNS service to crash. The issue highlights the need for continuous patch management and auditable evidence of service‑availability controls.

Other / Unknown Vulnerability Exploit
Medium · Oct 8, 2026 · CISA KEV
Read the full brief →
Vulnerability ADTP BRIEF 💣

BREACH WATCH BRIEF

Multiple Zero-Day Vulnerabilities Disclosed in Adobe Photoshop, Apple macOS, Foxit Reader, and Microsoft Windows Drivers

Cisco Talos disclosed seven new CVEs affecting Adobe, Apple, Foxit, and Microsoft products; patches are available. The findings underscore the need for continuous vulnerability management and auditable patch‑deployment evidence.

Technology & SaaS Vulnerability Exploit
High · Oct 7, 2026 · Cisco Talos Intelligence
Read the full brief →
Vulnerability ADTP BRIEF 👤

BREACH WATCH BRIEF

Critical Pre‑Auth SSRF Flaw (CVE‑2026‑102255) in SonicWall SMA1000 Appliances Allows Unauthenticated Access

SonicWall disclosed a CVSS 10.0 pre‑authentication SSRF vulnerability (CVE‑2026‑102255) affecting SMA1000 models, enabling unauthenticated attackers to reach internal functions. The flaw underscores the need for continuous control verification and audit‑ready evidence around network perimeter protections.

Technology & SaaS Vulnerability Exploit
Critical · Oct 7, 2026 · Security Affairs
Read the full brief →
Vulnerability ADTP BRIEF 👤

BREACH WATCH BRIEF

Critical Pre‑Auth SSRF Vulnerability (CVSS 10.0) in SonicWall SMA1000 Remote‑Access Appliances

SonicWall disclosed a pre‑authentication SSRF flaw in its SMA1000 remote‑access gateways that scores 10.0 CVSS. The vulnerability allows unauthenticated attackers to reach internal services, underscoring the need for robust patch‑management and continuous evidence of remediation for audit readiness.

Technology & SaaS Vulnerability Exploit
Critical · Oct 7, 2026 · The Hacker News
Read the full brief →
Vulnerability ADTP BRIEF ☁️

BREACH WATCH BRIEF

Critical Remote‑Code‑Execution Flaw in LMCache Allows Unauthenticated Attackers to Run Arbitrary Code

A newly disclosed vulnerability in the open‑source LMCache library enables unauthenticated attackers to execute code on LLM serving nodes. The issue affects AI‑focused SaaS and cloud providers and underscores the need for continuous component inventory and access‑control evidence for audit readiness.

Technology & SaaS Vulnerability Exploit Zero-Day Exploit
Critical · Oct 7, 2026 · The Hacker News
Read the full brief →
Vulnerability ADTP BRIEF 👤

BREACH WATCH BRIEF

Arbitrary File Access Vulnerability (CVE‑2026‑21589) Discovered in Atlassian Server Products

Atlassian disclosed CVE‑2026‑21589, an arbitrary file‑access flaw that lets unauthenticated actors read any file on the web server. The issue affects unpatched Server and Data Center editions of Confluence, Jira, Bitbucket, and related tools, raising immediate confidentiality concerns for organizations that rely on these platforms.

Technology & SaaS Vulnerability Exploit
High · Oct 7, 2026 · SANS Internet Storm Center
Read the full brief →
Vulnerability ADTP BRIEF 🔑

BREACH WATCH BRIEF

Exploitation Attempts Against Atlassian Data Center Arbitrary File Access Vulnerability (CVE‑2026‑21589)

Attackers have begun exploiting CVE‑2026‑21589, a critical arbitrary‑file‑access flaw in Atlassian’s self‑managed Data Center suite. The vulnerability can expose sensitive configuration files and credentials, underscoring the need for rapid patching and verifiable control evidence for audit readiness.

Technology & SaaS Vulnerability Exploit
Critical · Oct 7, 2026 · Help Net Security
Read the full brief →
Vulnerability ADTP BRIEF 👤

BREACH WATCH BRIEF

Critical Arbitrary File Access Flaw (CVE‑2026‑21589) in Atlassian Data Center Products Prompted Exploitation Within Two Hours

A CVE‑2026‑21589 vulnerability (CVSS 9.3) allows unauthenticated file reads on Bitbucket, Confluence, Jira Service Management and Jira Software Data Center. Threat actors began probing vulnerable installations within two hours of public disclosure. The flaw highlights the need for continuous control mapping and auditable evidence of file‑access safeguards.

Technology & SaaS Vulnerability Exploit
Critical · Oct 7, 2026 · The Hacker News
Read the full brief →
Vulnerability ADTP BRIEF 📡

BREACH WATCH BRIEF

Critical SSRF Vulnerability (CVE‑2026‑102255) in SonicWall SMA1000 Gateways

SonicWall disclosed a max‑severity server‑side request forgery (SSRF) flaw (CVE‑2026‑102255) affecting SMA1000 series appliances. The vulnerability allows unauthenticated attackers to force the device to issue internal requests, potentially leading to unauthorized operations. Organizations must patch promptly to maintain audit‑ready control assurance.

Government & Public Sector Vulnerability Exploit
Critical · Oct 7, 2026 · BleepingComputer
Read the full brief →
Vulnerability ADTP BRIEF ☁️

BREACH WATCH BRIEF

Google Patches Critical Use‑After‑Free Flaws in Chrome & ChromeOS (CVE‑2026‑106197, CVE‑2026‑106358, CVE‑2026‑106240)

Google released stable updates for Chrome and ChromeOS that fix 247 security issues, including four Critical use‑after‑free and type‑confusion vulnerabilities. Organizations must verify patch deployment to maintain audit‑ready evidence of vulnerability management.

Technology & SaaS Vulnerability Exploit
Critical · Oct 7, 2026 · Malwarebytes Labs
Read the full brief →
Page 1 of 203 Older →

Breach Watch intelligence is provided by LiveThreat, a product of a founding sponsor of the association. Every ADTP brief carries LiveThreat's analysis and links the original source.

Practitioner briefings

Written by the association: what the week's intelligence means for the controls you run.

Advisory · high

Reading a vendor's breach notice for what it does not say

A practitioner checklist for turning a supplier notification into an evidence request and a monitoring change.

TPR CYB
Read
Briefing · medium

Where AI inventory efforts stall, and the control that unblocks them

Findings from practitioner roundtables on AI governance programs in their first year.

AIG GRC
Read
Research

Evidence reuse across customer diligence and audit

How practitioners are organizing one evidence base to serve buyers and auditors at the same time.

GRC TRS
Read
Advisory · medium

Global Privacy Control signals and state opt-out obligations

What a site must do when it sees a GPC signal, and how to evidence it.

PRV
Read

Get the digest

No membership required. Confirm by email; unsubscribe in one click.