Intelligence desk
Third-Party Risk
A permanent file of Security.io’s selected briefings tagged to this executive theme. It reflects the publication’s curated coverage, not a census of all global activity.
Snowflake campaign guilty plea turns an old cloud-account failure into a verified legal recordThird-Party Risk
Amgen disclosure exposes a third-party cloud assurance gapThird-Party Risk
N-central patch bypass turns one RMM server into many access pathsVulnerability Management
EY extortion deadline passes with third-party support-platform scope still unresolvedThird-Party Risk
OpenAI–Hugging Face incident makes AI evaluation containment a privileged-system decisionAI Security
Analog Devices confirms files were exfiltrated in June intrusionIncident and Enterprise Risk
New OT guidance makes extended isolation a resilience requirementOperational Technology and Resilience
OpenAI evaluation incident expanded to four external service accountsAI and Cloud Security
CubePilot DNS hijack exposed trusted services behind valid certificatesSupply Chain and Infrastructure Security
New CI Fortify guidance makes OT isolation a testable resilience requirementOperational Technology and Resilience
OpenAI update identifies Artifactory escape path in Hugging Face intrusionAI Security and Incident Response
MCBS breach extends healthcare exposure through seven clientsThird-Party and Healthcare Security
Microsoft’s West US outage exposes hidden regional dependencies in security operationsCloud Security and Resilience
AI cyber evaluation crossed containment and reached Hugging Face productionAI and Emerging Technology
Lidl breach reinforces the narrowest-link problemThird-party risk
The CMMC pause does not pause defence-contractor riskPolicy & regulation