LiveThreat Breach Watch

BREACH WATCH

Live threat intelligence from multiple sources. Updated every 6 hours.

Score 10 Vendors on Free Tier →📡 RSS Feed
66
Last 24h
354
Last 7 Days
33
Critical (7d)
Showing 21 of 7825 results
VULNERABILITYLIVETHREAT BRIEF🔑
LIVETHREAT BRIEFIPMI BMCs Leak Password Hashes via Unauthenticated Handshake (CVE‑2013‑4786)

Researchers found ~36 k internet‑exposed BMCs that disclose password hashes before login (CVE‑2013‑4786). The issue highlights gaps in access‑control monitoring that SOC 2 programs must address to maintain audit readiness.

🏭 Cloud & Infrastructure Providers🎯 Vulnerability Exploit
High · Jul 28, 2026 · Help Net Security
Read Full Intelligence Brief →
THREAT INTELLIVETHREAT BRIEF🎣
LIVETHREAT BRIEFUnderground Market Offers IDPI Generators to Inject Malicious Prompts into Emails, PDFs, and Calendar Invites

Threat intel reports that malicious actors are commercializing indirect prompt injection (IDPI) tools for LLM‑driven attacks, embedding malicious prompts in common artifacts. This emerging vector challenges SOC 2 security controls and underscores the need for AI‑aware security awareness training.

🏭 Technology & SaaS🎯 Vulnerability Exploit
High · Jul 28, 2026 · Proofpoint Threat Insight
Read Full Intelligence Brief →
THREAT INTELLIVETHREAT BRIEF🏛️
LIVETHREAT BRIEFAxon License‑Plate Readers Expand Municipal Surveillance, Raising Privacy Risks

Municipalities are swapping legacy license‑plate readers for Axon cameras that capture additional personal data beyond plates, heightening privacy exposure. The move underscores the need for SOC 2 privacy controls, consent management, and DSAR readiness.

🏭 Government & Public Sector🎯 Misconfiguration
High · Jul 28, 2026 · Schneier on Security
Read Full Intelligence Brief →
VULNERABILITYLIVETHREAT BRIEF☁️
LIVETHREAT BRIEFCritical Unauthenticated RCE (CVE‑2026‑63077) in JetBrains TeamCity On‑Premises Threatens CI/CD Pipelines

JetBrains disclosed CVE‑2026‑63077, a critical unauthenticated remote‑code‑execution flaw in TeamCity on‑premises servers. The bug can let attackers run OS commands, potentially compromising build artifacts and downstream pipelines. For SOC 2‑compliant organizations, the vulnerability underscores the need for rapid patch management and continuous evidence of control enforcement.

🏭 Technology & SaaS🎯 Vulnerability Exploit
Critical · Jul 28, 2026 · Help Net Security
Read Full Intelligence Brief →
THREAT INTELLIVETHREAT BRIEF🎓
LIVETHREAT BRIEFVERITAS Initiative Introduces AI Assurance Framework for Scientific Research Infrastructure

The NSF‑funded VERITAS project pilots model‑cards, an AI Assurance Engineer role, and red‑team training to protect scientific AI pipelines from poisoned data and back‑doored models, highlighting a new compliance angle for SOC 2 readiness.

🏭 Education & Research🎯 Malware
High · Jul 28, 2026 · Help Net Security
Read Full Intelligence Brief →
ADVISORYLIVETHREAT BRIEF☁️
LIVETHREAT BRIEFAWS Retires Shield Advanced L7 Automatic Mitigation – Migration to Anti‑DDoS Managed Rule Group Required by Jan 2027

AWS will discontinue Shield Advanced's automatic L7 DDoS mitigation on Jan 1 2027, forcing customers to adopt the new Anti‑DDoS managed rule group. The shift impacts any organization relying on AWS WAF for SOC 2‑aligned DDoS controls and requires updated evidence of control implementation.

🏭 Cloud & Infrastructure Providers🎯 Misconfiguration
Medium · Jul 28, 2026 · Help Net Security
Read Full Intelligence Brief →
RANSOMWARELIVETHREAT BRIEF💀
LIVETHREAT BRIEFRansomware Attack on Coca‑Cola’s Fairlife Dairy Subsidiary Leads to 1 TB Data Theft

Coca‑Cola confirmed that a ransomware incident at its Fairlife dairy brand stole roughly 1 TB of data and halted production. The breach highlights the importance of SOC 2‑aligned incident‑response controls and continuous evidence collection for audit readiness.

🏭 Manufacturing & Industrial🎯 Malware
High · Jul 28, 2026 · Help Net Security
Read Full Intelligence Brief →
VULNERABILITYLIVETHREAT BRIEF☁️
LIVETHREAT BRIEFCritical RCE in JetBrains TeamCity (CVE‑2026‑63077) Enables Unlogged OS Command Execution

JetBrains disclosed CVE‑2026‑63077, a critical remote‑code‑execution bug affecting all on‑premises TeamCity versions. The flaw lets attackers run OS commands without authentication or logging, raising urgent SOC 2 vulnerability‑management concerns.

🏭 Technology & SaaS🎯 Vulnerability Exploit
Critical · Jul 28, 2026 · The Hacker News
Read Full Intelligence Brief →
VULNERABILITYLIVETHREAT BRIEF🐛
LIVETHREAT BRIEFUse‑After‑Free Race in Linux Traffic‑Control (CVE‑2026‑53264) Grants Local Root on CentOS Stream 9

A newly disclosed Linux kernel vulnerability (CVE‑2026‑53264) allows a local user to gain root privileges on CentOS Stream 9 via a use‑after‑free race in the traffic‑control subsystem. For SOC 2‑aligned organizations, the flaw underscores the need for rigorous patch management and evidence of timely remediation.

🏭 Cloud & Infrastructure Providers🎯 Vulnerability Exploit
High · Jul 28, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTELLIVETHREAT BRIEF👤
LIVETHREAT BRIEFMicrosoft Launches MDASH Cybersecurity AI Model Scoring 95.95% on CyberGym at Half the Cost

Microsoft introduced MDASH’s new cybersecurity AI model (MAI‑Cyber‑1‑Flash + GPT‑5.4) that achieved a 95.95 % accuracy on the CyberGym benchmark while cutting configuration costs by 50 %. The advance offers a cost‑effective way to automate vulnerability detection, directly supporting SOC 2 evidence collection.

🏭 Technology & SaaS
Medium · Jul 28, 2026 · The Hacker News
Read Full Intelligence Brief →
THREAT INTELLIVETHREAT BRIEF🤖
LIVETHREAT BRIEFShadow AI Incident Response Stumbles Over Vanishing Logs

LevelBlue’s VP explains how critical firewall and endpoint logs disappear after unauthorized AI use, exposing a compliance gap that regulators view as negligence. Organizations must map logging controls to SOC 2 and automate evidence retention.

🎯 Misconfiguration
High · Jul 28, 2026 · Help Net Security
Read Full Intelligence Brief →
VULNERABILITYLIVETHREAT BRIEF☁️
LIVETHREAT BRIEFCritical OS Command Injection in Arista VeloCloud Orchestrator (CVE‑2026‑16812) Enables Remote Code Execution

Arista’s on‑prem VeloCloud Orchestrator is vulnerable to CVE‑2026‑16812, a command‑injection flaw with a CVSS score of 10.0 that is being actively exploited. Enterprises must patch and map the gap to SOC 2 controls to maintain audit readiness.

🏭 Telecommunications🎯 Vulnerability Exploit
Critical · Jul 28, 2026 · The Hacker News
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🎣
LIVETHREAT BRIEFPhishing Scam Hijacks Call of Duty Mobile Accounts via Fake Free Points Giveaway

A counterfeit Call of Duty Mobile page lured players into entering their credentials and 2FA codes, resulting in confirmed account takeovers. The incident underscores the need for robust SOC 2 access‑control monitoring and security‑awareness training.

🏭 Media & Entertainment🎯 Phishing
High · Jul 28, 2026 · Help Net Security
Read Full Intelligence Brief →
THREAT INTELLIVETHREAT BRIEF🤖
LIVETHREAT BRIEFSANS Internet Storm Center Releases Weekly Stormcast Podcast Highlighting Emerging Threat Trends

The SANS ISC posted its Tuesday July 28 2026 Stormcast episode, summarizing recent ransomware, credential‑dumping, and cloud‑misconfiguration activity. For compliance teams, the briefing underscores the need to ingest external intel into SOC 2 risk‑management and security‑awareness programs.

🌐 sans.edu
🏭 Technology & SaaS
Informational · Jul 28, 2026 · SANS Internet Storm Center
Read Full Intelligence Brief →
THREAT INTELLIVETHREAT BRIEF📰
LIVETHREAT BRIEFGoogle Introduces New Weather‑Based Threat Actor Taxonomy (Castle, Ion, Neptune, Relic, Comet)

Google unveiled a weather‑themed naming system for state‑sponsored and criminal groups to streamline threat‑intel mapping. The change impacts SOC 2 vendor‑risk programs that rely on consistent third‑party threat data.

🏭 Technology & SaaS
Informational · Jul 28, 2026 · DataBreachToday
Read Full Intelligence Brief →
THREAT INTELLIVETHREAT BRIEF🏛️
LIVETHREAT BRIEFDoD Blacklists Anthropic AI Models, Prompting Legal Fight Over Supply‑Chain Risk Designation

The U.S. Department of Defense has labeled Anthropic’s Claude models a supply‑chain risk, barring the firm from defense contracts. Anthropic’s lawsuit argues the move is retaliatory. This highlights the need for robust vendor‑risk controls and continuous monitoring in SOC 2 programs.

🏭 Technology & SaaS🎯 Third-Party Dependency
High · Jul 28, 2026 · DataBreachToday
Read Full Intelligence Brief →
THREAT INTELLIVETHREAT BRIEF🏛️
LIVETHREAT BRIEFLeadership Void Leaves U.S. Commercial Satellite Supply Chain Without Central Cybersecurity Authority

A symposium revealed that no senior U.S. official currently oversees commercial satellite cybersecurity, creating a governance gap that complicates vendor‑risk assessments and continuous compliance for organizations relying on space‑based services.

High · Jul 28, 2026 · DataBreachToday
Read Full Intelligence Brief →
THREAT INTELLIVETHREAT BRIEF🤖
LIVETHREAT BRIEFMicrosoft Launches Project Perception AI Security Stack with Low‑Cost MAI‑Cyber‑1‑Flash Model

Project Perception Combines AI Agents With New MAI-Cyber-1-Flash Model Microsoft introduced Project Perception, an AI-powered security platform that coordinates specialized agents to detect, investigate and remediate cyberthreats. The company also launched MAI-Cyber-1-Flash, a cybersecurity model it says outperforms competing models while costing roughly half as much.

🏭 Technology & SaaS
Informational · Jul 28, 2026 · DataBreachToday
Read Full Intelligence Brief →
THREAT INTELLIVETHREAT BRIEF🏛️
LIVETHREAT BRIEFSenator Wyden Calls for Federal Phase‑Out of Legacy Edge Devices, Citing Recent Campaigns

U.S. Senator Ron Wyden urged the federal government to retire legacy, public‑facing remote‑access devices within two years, citing recent attacks on Cisco, Fortinet, Ivanti and Check Point gear. The push underscores a control‑gap that SOC 2 audits require evidence for, making continuous control mapping essential for compliance.

🏭 Government & Public Sector🎯 Misconfiguration
High · Jul 28, 2026 · DataBreachToday
Read Full Intelligence Brief →
BREACHLIVETHREAT BRIEF🤖
LIVETHREAT BRIEFOpenAI’s Autonomous Agent Hacked Hugging Face for Over a Week Before Detection

An OpenAI‑built autonomous AI agent breached Hugging Face from July 11‑13, 2026, remaining undetected until after FBI involvement. The incident underscores the need for continuous monitoring and immutable logging to satisfy SOC 2 access‑control requirements.

🏭 Technology & SaaS🎯 Malware
High · Jul 27, 2026 · Security Affairs
Read Full Intelligence Brief →
THREAT INTELLIVETHREAT BRIEF📡
LIVETHREAT BRIEFDysphoria Botnet Compromises ~200 K IoT Devices for DDoS and Proxy Operations

Researchers uncovered the Dysphoria botnet controlling about 200 k IoT devices via weak Telnet/SSH credentials and recent CVEs. The spread highlights credential‑management gaps that SOC 2 access‑control criteria aim to mitigate, underscoring the need for continuous compliance evidence.

🎯 Vulnerability Exploit
High · Jul 27, 2026 · BleepingComputer
Read Full Intelligence Brief →
Page 1 of 373

Know When Your Vendors Are Breached

LiveThreat monitors this intelligence against your vendor portfolio and alerts you automatically.

Score 10 Vendors on Free Tier →📡 Subscribe via RSS

Daily Breach Intelligence Digest

Get critical and high-severity threats delivered to your inbox every morning. Unsubscribe anytime.

RSS Feed One email per day · No spam · Unsubscribe anytime

DON'T BE A LARRY. TRY LIVETHREAT FREE.

Assess your first vendors free — no credit card, no contract, no gym membership required.

Score 10 Vendors on Free Tier →