Intelligence desk
Third-Party Risk
A permanent file of Security.io’s selected briefings tagged to this executive theme. It reflects the publication’s curated coverage, not a census of all global activity.
Vendor-held API credentials expose Veradigm patient dataThird-Party Risk
N-central Hotfix 4 resets the control-plane decisionVulnerability Management
C-Track breach exposes the limits of court-vendor assuranceThird-Party Risk
Aesto breach count exposes healthcare vendor concentrationThird-Party Risk
McKesson confirms third-party data theft but leaves customers without application scopeThird-Party Risk
Micro-Comm breach exposes a water-sector supplier assurance gapThird-Party Risk
Calix router flaw can turn a trusted NAT boundary into public exposureVulnerability Management
CareCloud breach scope rises to 3.76 million peopleData Protection
Heights Finance breach exposes the risk outside core systemsThird-Party Risk
Jewelbug turns one shared webmail template into a national-scale footholdThreat Intelligence
Trezor breach exposes the risk hidden in fulfilment dataThird-Party Risk
Snowflake campaign guilty plea turns an old cloud-account failure into a verified legal recordThird-Party Risk
Amgen disclosure exposes a third-party cloud assurance gapThird-Party Risk
N-central patch bypass turns one RMM server into many access pathsVulnerability Management
EY extortion deadline passes with third-party support-platform scope still unresolvedThird-Party Risk
OpenAI–Hugging Face incident makes AI evaluation containment a privileged-system decisionAI Security
Analog Devices confirms files were exfiltrated in June intrusionIncident and Enterprise Risk
New OT guidance makes extended isolation a resilience requirementOperational Technology and Resilience
OpenAI evaluation incident expanded to four external service accountsAI and Cloud Security
CubePilot DNS hijack exposed trusted services behind valid certificatesSupply Chain and Infrastructure Security
New CI Fortify guidance makes OT isolation a testable resilience requirementOperational Technology and Resilience
OpenAI update identifies Artifactory escape path in Hugging Face intrusionAI Security and Incident Response
MCBS breach extends healthcare exposure through seven clientsThird-Party and Healthcare Security
Microsoft’s West US outage exposes hidden regional dependencies in security operationsCloud Security and Resilience
AI cyber evaluation crossed containment and reached Hugging Face productionAI and Emerging Technology
Lidl breach reinforces the narrowest-link problemThird-party risk
The CMMC pause does not pause defence-contractor riskPolicy & regulation