home.social

#vendorrisk — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vendorrisk, aggregated by home.social.

fetched live
  1. With the new hack-back memo, the US has shot itself in the foot again. And most of the initial online discussions miss how far the damage reaches. For the US.

    Quick summary. On August 12 the President signed a memorandum letting vetted American companies break into foreign systems used by criminal groups and disrupt or destroy them. It is not vigilantism: the companies act under federal direction, and two officials approve every operation in writing.

    Americans lost more than $20 billion to this fraud last year, so the motivation is real. I am not against acting. I am against this approach, and I know the arguments because I spent years making them to governments that wanted the same thing.

    The debate so far has been about whether private firms should do this, and whether innocent foreigners get hurt. However I analyze it, the first casualty is American:

    - Why would anyone share threat intel with Americans, when it could now be used to attack infrastructure in their own country?

    - Why would a non-US CISO keep American EDR and XDR agents deep in their stack, when nobody can tell them whether that vendor also runs surveillance and offensive operations for the state?

    - Why would anyone outside the US let an American vendor build the map of their weakest cryptography, in the PQC discovery and inventory work their own regulator is forcing them to do?

    - Why would a European buyer accept "we cannot comment" as a tender answer?

    - Why would an American firm disclose the flaw it just found, when its other contract values that flaw unpatched?

    - Why would a sovereign wealth fund hold a listed US security vendor it has no way to assess?

    - Why would an allied service share access with a partner whose contractors may be on the same box?

    - How does a US prosecutor explain the next indictment of a Chinese contractor hacker?

    - What does Washington say when Beijing runs the same program and calls it law enforcement?

    Procedures are due October 11 and need not be published. Which means these questions may never get a public answer, and every one of them will get answered by assumption instead. None of those assumptions will favor the American cybersecurity industry.

    postquantum.com/cyber-kinetic-

    #Cybersecurity #CISO #CyberPolicy #ThreatIntel #NationalSecurity #InfoSec #VendorRisk #PQC

  2. With the new hack-back memo, the US has shot itself in the foot again. And most of the initial online discussions miss how far the damage reaches. For the US.

    Quick summary. On August 12 the President signed a memorandum letting vetted American companies break into foreign systems used by criminal groups and disrupt or destroy them. It is not vigilantism: the companies act under federal direction, and two officials approve every operation in writing.

    Americans lost more than $20 billion to this fraud last year, so the motivation is real. I am not against acting. I am against this approach, and I know the arguments because I spent years making them to governments that wanted the same thing.

    The debate so far has been about whether private firms should do this, and whether innocent foreigners get hurt. However I analyze it, the first casualty is American:

    - Why would anyone share threat intel with Americans, when it could now be used to attack infrastructure in their own country?

    - Why would a non-US CISO keep American EDR and XDR agents deep in their stack, when nobody can tell them whether that vendor also runs surveillance and offensive operations for the state?

    - Why would anyone outside the US let an American vendor build the map of their weakest cryptography, in the PQC discovery and inventory work their own regulator is forcing them to do?

    - Why would a European buyer accept "we cannot comment" as a tender answer?

    - Why would an American firm disclose the flaw it just found, when its other contract values that flaw unpatched?

    - Why would a sovereign wealth fund hold a listed US security vendor it has no way to assess?

    - Why would an allied service share access with a partner whose contractors may be on the same box?

    - How does a US prosecutor explain the next indictment of a Chinese contractor hacker?

    - What does Washington say when Beijing runs the same program and calls it law enforcement?

    Procedures are due October 11 and need not be published. Which means these questions may never get a public answer, and every one of them will get answered by assumption instead. None of those assumptions will favor the American cybersecurity industry.

    postquantum.com/cyber-kinetic-

    #Cybersecurity #CISO #CyberPolicy #ThreatIntel #NationalSecurity #InfoSec #VendorRisk #PQC

  3. With the new hack-back memo, the US has shot itself in the foot again. And most of the initial online discussions miss how far the damage reaches. For the US.

    Quick summary. On August 12 the President signed a memorandum letting vetted American companies break into foreign systems used by criminal groups and disrupt or destroy them. It is not vigilantism: the companies act under federal direction, and two officials approve every operation in writing.

    Americans lost more than $20 billion to this fraud last year, so the motivation is real. I am not against acting. I am against this approach, and I know the arguments because I spent years making them to governments that wanted the same thing.

    The debate so far has been about whether private firms should do this, and whether innocent foreigners get hurt. However I analyze it, the first casualty is American:

    - Why would anyone share threat intel with Americans, when it could now be used to attack infrastructure in their own country?

    - Why would a non-US CISO keep American EDR and XDR agents deep in their stack, when nobody can tell them whether that vendor also runs surveillance and offensive operations for the state?

    - Why would anyone outside the US let an American vendor build the map of their weakest cryptography, in the PQC discovery and inventory work their own regulator is forcing them to do?

    - Why would a European buyer accept "we cannot comment" as a tender answer?

    - Why would an American firm disclose the flaw it just found, when its other contract values that flaw unpatched?

    - Why would a sovereign wealth fund hold a listed US security vendor it has no way to assess?

    - Why would an allied service share access with a partner whose contractors may be on the same box?

    - How does a US prosecutor explain the next indictment of a Chinese contractor hacker?

    - What does Washington say when Beijing runs the same program and calls it law enforcement?

    Procedures are due October 11 and need not be published. Which means these questions may never get a public answer, and every one of them will get answered by assumption instead. None of those assumptions will favor the American cybersecurity industry.

    postquantum.com/cyber-kinetic-

    #Cybersecurity #CISO #CyberPolicy #ThreatIntel #NationalSecurity #InfoSec #VendorRisk #PQC

  4. With the new hack-back memo, the US has shot itself in the foot again. And most of the initial online discussions miss how far the damage reaches. For the US.

    Quick summary. On August 12 the President signed a memorandum letting vetted American companies break into foreign systems used by criminal groups and disrupt or destroy them. It is not vigilantism: the companies act under federal direction, and two officials approve every operation in writing.

    Americans lost more than $20 billion to this fraud last year, so the motivation is real. I am not against acting. I am against this approach, and I know the arguments because I spent years making them to governments that wanted the same thing.

    The debate so far has been about whether private firms should do this, and whether innocent foreigners get hurt. However I analyze it, the first casualty is American:

    - Why would anyone share threat intel with Americans, when it could now be used to attack infrastructure in their own country?

    - Why would a non-US CISO keep American EDR and XDR agents deep in their stack, when nobody can tell them whether that vendor also runs surveillance and offensive operations for the state?

    - Why would anyone outside the US let an American vendor build the map of their weakest cryptography, in the PQC discovery and inventory work their own regulator is forcing them to do?

    - Why would a European buyer accept "we cannot comment" as a tender answer?

    - Why would an American firm disclose the flaw it just found, when its other contract values that flaw unpatched?

    - Why would a sovereign wealth fund hold a listed US security vendor it has no way to assess?

    - Why would an allied service share access with a partner whose contractors may be on the same box?

    - How does a US prosecutor explain the next indictment of a Chinese contractor hacker?

    - What does Washington say when Beijing runs the same program and calls it law enforcement?

    Procedures are due October 11 and need not be published. Which means these questions may never get a public answer, and every one of them will get answered by assumption instead. None of those assumptions will favor the American cybersecurity industry.

    postquantum.com/cyber-kinetic-

    #Cybersecurity #CISO #CyberPolicy #ThreatIntel #NationalSecurity #InfoSec #VendorRisk #PQC

  5. With the new hack-back memo, the US has shot itself in the foot again. And most of the initial online discussions miss how far the damage reaches. For the US.

    Quick summary. On August 12 the President signed a memorandum letting vetted American companies break into foreign systems used by criminal groups and disrupt or destroy them. It is not vigilantism: the companies act under federal direction, and two officials approve every operation in writing.

    Americans lost more than $20 billion to this fraud last year, so the motivation is real. I am not against acting. I am against this approach, and I know the arguments because I spent years making them to governments that wanted the same thing.

    The debate so far has been about whether private firms should do this, and whether innocent foreigners get hurt. However I analyze it, the first casualty is American:

    - Why would anyone share threat intel with Americans, when it could now be used to attack infrastructure in their own country?

    - Why would a non-US CISO keep American EDR and XDR agents deep in their stack, when nobody can tell them whether that vendor also runs surveillance and offensive operations for the state?

    - Why would anyone outside the US let an American vendor build the map of their weakest cryptography, in the PQC discovery and inventory work their own regulator is forcing them to do?

    - Why would a European buyer accept "we cannot comment" as a tender answer?

    - Why would an American firm disclose the flaw it just found, when its other contract values that flaw unpatched?

    - Why would a sovereign wealth fund hold a listed US security vendor it has no way to assess?

    - Why would an allied service share access with a partner whose contractors may be on the same box?

    - How does a US prosecutor explain the next indictment of a Chinese contractor hacker?

    - What does Washington say when Beijing runs the same program and calls it law enforcement?

    Procedures are due October 11 and need not be published. Which means these questions may never get a public answer, and every one of them will get answered by assumption instead. None of those assumptions will favor the American cybersecurity industry.

    postquantum.com/cyber-kinetic-

    #Cybersecurity #CISO #CyberPolicy #ThreatIntel #NationalSecurity #InfoSec #VendorRisk #PQC

  6. Anthropic spent months carefully gatekeeping access to Mythos, their most capable AI model, while limiting access only to a small group of vetted companies for defensive cybersecurity testing. Then a private online forum got in anyway, through a third-party vendor, on the same day the controlled program was announced.

    That's the part worth sitting with. Not the model. The vendor. Third-party vendors... It's always the the 3td party vendor. 🤦🏻‍♂️ You can build the most carefully controlled AI release program in the industry, and one weak link in your supply chain burns it down. We keep having this conversation about AI safety and regulation, and we keep forgetting that the threat surface isn't just the model. It's every partner, every integration, every environment touching it. 🔗 Everything's connected. Everything.

    🤔 Ask yourself: how many third parties have access to your most sensitive systems right now? Do you actually know?
    ⚠️ Vendor risk management isn't a compliance checkbox. It's where your security posture actually lives or dies.

    yahoo.com/news/articles/anthro
    #Cybersecurity #AI #VendorRisk #InfoSec #RiskManagement #security #privacy #cloud #infosec

  7. Anthropic spent months carefully gatekeeping access to Mythos, their most capable AI model, while limiting access only to a small group of vetted companies for defensive cybersecurity testing. Then a private online forum got in anyway, through a third-party vendor, on the same day the controlled program was announced.

    That's the part worth sitting with. Not the model. The vendor. Third-party vendors... It's always the the 3td party vendor. 🤦🏻‍♂️ You can build the most carefully controlled AI release program in the industry, and one weak link in your supply chain burns it down. We keep having this conversation about AI safety and regulation, and we keep forgetting that the threat surface isn't just the model. It's every partner, every integration, every environment touching it. 🔗 Everything's connected. Everything.

    🤔 Ask yourself: how many third parties have access to your most sensitive systems right now? Do you actually know?
    ⚠️ Vendor risk management isn't a compliance checkbox. It's where your security posture actually lives or dies.

    yahoo.com/news/articles/anthro
    #Cybersecurity #AI #VendorRisk #InfoSec #RiskManagement #security #privacy #cloud #infosec

  8. Anthropic spent months carefully gatekeeping access to Mythos, their most capable AI model, while limiting access only to a small group of vetted companies for defensive cybersecurity testing. Then a private online forum got in anyway, through a third-party vendor, on the same day the controlled program was announced.

    That's the part worth sitting with. Not the model. The vendor. Third-party vendors... It's always the the 3td party vendor. 🤦🏻‍♂️ You can build the most carefully controlled AI release program in the industry, and one weak link in your supply chain burns it down. We keep having this conversation about AI safety and regulation, and we keep forgetting that the threat surface isn't just the model. It's every partner, every integration, every environment touching it. 🔗 Everything's connected. Everything.

    🤔 Ask yourself: how many third parties have access to your most sensitive systems right now? Do you actually know?
    ⚠️ Vendor risk management isn't a compliance checkbox. It's where your security posture actually lives or dies.

    yahoo.com/news/articles/anthro
    #Cybersecurity #AI #VendorRisk #InfoSec #RiskManagement #security #privacy #cloud #infosec

  9. Anthropic spent months carefully gatekeeping access to Mythos, their most capable AI model, while limiting access only to a small group of vetted companies for defensive cybersecurity testing. Then a private online forum got in anyway, through a third-party vendor, on the same day the controlled program was announced.

    That's the part worth sitting with. Not the model. The vendor. Third-party vendors... It's always the the 3td party vendor. 🤦🏻‍♂️ You can build the most carefully controlled AI release program in the industry, and one weak link in your supply chain burns it down. We keep having this conversation about AI safety and regulation, and we keep forgetting that the threat surface isn't just the model. It's every partner, every integration, every environment touching it. 🔗 Everything's connected. Everything.

    🤔 Ask yourself: how many third parties have access to your most sensitive systems right now? Do you actually know?
    ⚠️ Vendor risk management isn't a compliance checkbox. It's where your security posture actually lives or dies.

    yahoo.com/news/articles/anthro
    #Cybersecurity #AI #VendorRisk #InfoSec #RiskManagement #security #privacy #cloud #infosec

  10. Anthropic spent months carefully gatekeeping access to Mythos, their most capable AI model, while limiting access only to a small group of vetted companies for defensive cybersecurity testing. Then a private online forum got in anyway, through a third-party vendor, on the same day the controlled program was announced.

    That's the part worth sitting with. Not the model. The vendor. Third-party vendors... It's always the the 3td party vendor. 🤦🏻‍♂️ You can build the most carefully controlled AI release program in the industry, and one weak link in your supply chain burns it down. We keep having this conversation about AI safety and regulation, and we keep forgetting that the threat surface isn't just the model. It's every partner, every integration, every environment touching it. 🔗 Everything's connected. Everything.

    🤔 Ask yourself: how many third parties have access to your most sensitive systems right now? Do you actually know?
    ⚠️ Vendor risk management isn't a compliance checkbox. It's where your security posture actually lives or dies.

    yahoo.com/news/articles/anthro
    #Cybersecurity #AI #VendorRisk #InfoSec #RiskManagement #security #privacy #cloud #infosec

  11. Anthropic launches Code Review at $15-25 per pull request, completing a vertical integration play across code generation, review, and security. Their own engineers tripled output using Claude, creating demand for AI-powered oversight. Meanwhile, Pentagon supply chain designation creates new vendor risk considerations for enterprise buyers weighing the full-stack approach. #AICodeReview #EnterpriseAI #VendorRisk

    implicator.ai/anthropic-built-

  12. Anthropic launches Code Review at $15-25 per pull request, completing a vertical integration play across code generation, review, and security. Their own engineers tripled output using Claude, creating demand for AI-powered oversight. Meanwhile, Pentagon supply chain designation creates new vendor risk considerations for enterprise buyers weighing the full-stack approach. #AICodeReview #EnterpriseAI #VendorRisk

    implicator.ai/anthropic-built-

  13. A security incident involving restaurant technology provider HungerRush highlights the growing risk of compromised communication infrastructure.

    A threat actor sent extortion emails to restaurant patrons, claiming access to millions of data records associated with the HungerRush platform.

    Technical observations include:
    • Emails delivered through Twilio SendGrid infrastructure
    • Messages passed SPF, DKIM, and DMARC authentication checks
    • Access was reportedly gained via compromised third-party vendor credentials
    HungerRush states the incident was limited to an email marketing service account, and that no passwords, payment card information, or sensitive personal data were exposed.

    The event demonstrates how attackers can leverage trusted messaging infrastructure to launch extortion or phishing campaigns at scale.

    Source: bleepingcomputer.com/news/secu

    How should organizations better secure email platforms and vendor integrations within SaaS environments?

    Share your insights in the comments and follow TechNadu for more cybersecurity threat intelligence and breach coverage.

    #InfoSec #CyberSecurity #EmailSecurity #VendorRisk #ThreatIntelligence #DataSecurity #SecurityOperations #CyberThreats #SupplyChainSecurity

  14. A security incident involving restaurant technology provider HungerRush highlights the growing risk of compromised communication infrastructure.

    A threat actor sent extortion emails to restaurant patrons, claiming access to millions of data records associated with the HungerRush platform.

    Technical observations include:
    • Emails delivered through Twilio SendGrid infrastructure
    • Messages passed SPF, DKIM, and DMARC authentication checks
    • Access was reportedly gained via compromised third-party vendor credentials
    HungerRush states the incident was limited to an email marketing service account, and that no passwords, payment card information, or sensitive personal data were exposed.

    The event demonstrates how attackers can leverage trusted messaging infrastructure to launch extortion or phishing campaigns at scale.

    Source: bleepingcomputer.com/news/secu

    How should organizations better secure email platforms and vendor integrations within SaaS environments?

    Share your insights in the comments and follow TechNadu for more cybersecurity threat intelligence and breach coverage.

    #InfoSec #CyberSecurity #EmailSecurity #VendorRisk #ThreatIntelligence #DataSecurity #SecurityOperations #CyberThreats #SupplyChainSecurity

  15. A security incident involving restaurant technology provider HungerRush highlights the growing risk of compromised communication infrastructure.

    A threat actor sent extortion emails to restaurant patrons, claiming access to millions of data records associated with the HungerRush platform.

    Technical observations include:
    • Emails delivered through Twilio SendGrid infrastructure
    • Messages passed SPF, DKIM, and DMARC authentication checks
    • Access was reportedly gained via compromised third-party vendor credentials
    HungerRush states the incident was limited to an email marketing service account, and that no passwords, payment card information, or sensitive personal data were exposed.

    The event demonstrates how attackers can leverage trusted messaging infrastructure to launch extortion or phishing campaigns at scale.

    Source: bleepingcomputer.com/news/secu

    How should organizations better secure email platforms and vendor integrations within SaaS environments?

    Share your insights in the comments and follow TechNadu for more cybersecurity threat intelligence and breach coverage.

    #InfoSec #CyberSecurity #EmailSecurity #VendorRisk #ThreatIntelligence #DataSecurity #SecurityOperations #CyberThreats #SupplyChainSecurity

  16. A security incident involving restaurant technology provider HungerRush highlights the growing risk of compromised communication infrastructure.

    A threat actor sent extortion emails to restaurant patrons, claiming access to millions of data records associated with the HungerRush platform.

    Technical observations include:
    • Emails delivered through Twilio SendGrid infrastructure
    • Messages passed SPF, DKIM, and DMARC authentication checks
    • Access was reportedly gained via compromised third-party vendor credentials
    HungerRush states the incident was limited to an email marketing service account, and that no passwords, payment card information, or sensitive personal data were exposed.

    The event demonstrates how attackers can leverage trusted messaging infrastructure to launch extortion or phishing campaigns at scale.

    Source: bleepingcomputer.com/news/secu

    How should organizations better secure email platforms and vendor integrations within SaaS environments?

    Share your insights in the comments and follow TechNadu for more cybersecurity threat intelligence and breach coverage.

    #InfoSec #CyberSecurity #EmailSecurity #VendorRisk #ThreatIntelligence #DataSecurity #SecurityOperations #CyberThreats #SupplyChainSecurity

  17. ShinyHunters has listed a 1.67 GB JSON dataset allegedly containing 600K+ customer records tied to Canada Goose.
    Reported by BleepingComputer.

    Dataset reportedly includes:
    • checkout_id, cart_token schema indicators
    • Shipping lines & order values
    • IP telemetry
    • Device/browser metadata
    • Partial PAN (BIN + last four)
    • Authorization metadata
    No full card numbers observed in samples.

    Canada Goose states no evidence of breach of its own systems; attackers claim third-party processor origin.
    Security implications:
    • BIN + last four enable targeted card fraud attempts
    • Order value profiling identifies high-value targets
    • IP/device metadata aids social engineering
    • Historical datasets still carry active fraud potential
    Is vendor risk management keeping pace with SaaS-based commerce stacks?

    Source: bleepingcomputer.com/news/secu

    Engage below.
    Follow @technadu for advanced threat analysis.

    #ThreatIntel #DataLeak #VendorRisk #RetailSecurity #FraudPrevention #Infosec #CloudSecurity #DataExposure #ShinyHunters #CyberDefense #PrivacyEngineering

  18. ShinyHunters has listed a 1.67 GB JSON dataset allegedly containing 600K+ customer records tied to Canada Goose.
    Reported by BleepingComputer.

    Dataset reportedly includes:
    • checkout_id, cart_token schema indicators
    • Shipping lines & order values
    • IP telemetry
    • Device/browser metadata
    • Partial PAN (BIN + last four)
    • Authorization metadata
    No full card numbers observed in samples.

    Canada Goose states no evidence of breach of its own systems; attackers claim third-party processor origin.
    Security implications:
    • BIN + last four enable targeted card fraud attempts
    • Order value profiling identifies high-value targets
    • IP/device metadata aids social engineering
    • Historical datasets still carry active fraud potential
    Is vendor risk management keeping pace with SaaS-based commerce stacks?

    Source: bleepingcomputer.com/news/secu

    Engage below.
    Follow @technadu for advanced threat analysis.

    #ThreatIntel #DataLeak #VendorRisk #RetailSecurity #FraudPrevention #Infosec #CloudSecurity #DataExposure #ShinyHunters #CyberDefense #PrivacyEngineering

  19. ShinyHunters has listed a 1.67 GB JSON dataset allegedly containing 600K+ customer records tied to Canada Goose.
    Reported by BleepingComputer.

    Dataset reportedly includes:
    • checkout_id, cart_token schema indicators
    • Shipping lines & order values
    • IP telemetry
    • Device/browser metadata
    • Partial PAN (BIN + last four)
    • Authorization metadata
    No full card numbers observed in samples.

    Canada Goose states no evidence of breach of its own systems; attackers claim third-party processor origin.
    Security implications:
    • BIN + last four enable targeted card fraud attempts
    • Order value profiling identifies high-value targets
    • IP/device metadata aids social engineering
    • Historical datasets still carry active fraud potential
    Is vendor risk management keeping pace with SaaS-based commerce stacks?

    Source: bleepingcomputer.com/news/secu

    Engage below.
    Follow @technadu for advanced threat analysis.

    #ThreatIntel #DataLeak #VendorRisk #RetailSecurity #FraudPrevention #Infosec #CloudSecurity #DataExposure #ShinyHunters #CyberDefense #PrivacyEngineering

  20. ShinyHunters has listed a 1.67 GB JSON dataset allegedly containing 600K+ customer records tied to Canada Goose.
    Reported by BleepingComputer.

    Dataset reportedly includes:
    • checkout_id, cart_token schema indicators
    • Shipping lines & order values
    • IP telemetry
    • Device/browser metadata
    • Partial PAN (BIN + last four)
    • Authorization metadata
    No full card numbers observed in samples.

    Canada Goose states no evidence of breach of its own systems; attackers claim third-party processor origin.
    Security implications:
    • BIN + last four enable targeted card fraud attempts
    • Order value profiling identifies high-value targets
    • IP/device metadata aids social engineering
    • Historical datasets still carry active fraud potential
    Is vendor risk management keeping pace with SaaS-based commerce stacks?

    Source: bleepingcomputer.com/news/secu

    Engage below.
    Follow @technadu for advanced threat analysis.

    #ThreatIntel #DataLeak #VendorRisk #RetailSecurity #FraudPrevention #Infosec #CloudSecurity #DataExposure #ShinyHunters #CyberDefense #PrivacyEngineering

  21. At RELIANOID, we know your security is only as strong as your weakest vendor.

    That’s why we: ✅ Continuously monitor third-party risks
    ✅ Run attack simulations
    ✅ Collaborate directly with vendors

    In our book, cybersecurity isn’t optional — it’s mandatory. 🛡️


    relianoid.com/blog/how-reliano

  22. AI-driven fraud has moved from isolated scams to machine-scale impersonation — and many enterprise defenses haven’t caught up.

    In an exclusive interview with MoveTheNeedle.news, Trustpair CEO Baptiste Collot explains why manual controls like callbacks and email confirmations are failing, where fraud exploits operational change, and why continuous validation is becoming a baseline requirement.

    📖 movetheneedle.news/brands/ai-p

    #AI #fraud #technology #innovation #nacha2026 #vendorrisk

  23. AI-driven fraud has moved from isolated scams to machine-scale impersonation — and many enterprise defenses haven’t caught up.

    In an exclusive interview with MoveTheNeedle.news, Trustpair CEO Baptiste Collot explains why manual controls like callbacks and email confirmations are failing, where fraud exploits operational change, and why continuous validation is becoming a baseline requirement.

    📖 movetheneedle.news/brands/ai-p

    #AI #fraud #technology #innovation #nacha2026 #vendorrisk

  24. AI-driven fraud has moved from isolated scams to machine-scale impersonation — and many enterprise defenses haven’t caught up.

    In an exclusive interview with MoveTheNeedle.news, Trustpair CEO Baptiste Collot explains why manual controls like callbacks and email confirmations are failing, where fraud exploits operational change, and why continuous validation is becoming a baseline requirement.

    📖 movetheneedle.news/brands/ai-p

    #AI #fraud #technology #innovation #nacha2026 #vendorrisk

  25. AI-driven fraud has moved from isolated scams to machine-scale impersonation — and many enterprise defenses haven’t caught up.

    In an exclusive interview with MoveTheNeedle.news, Trustpair CEO Baptiste Collot explains why manual controls like callbacks and email confirmations are failing, where fraud exploits operational change, and why continuous validation is becoming a baseline requirement.

    📖 movetheneedle.news/brands/ai-p

    #AI #fraud #technology #innovation #nacha2026 #vendorrisk

  26. AI-driven fraud has moved from isolated scams to machine-scale impersonation — and many enterprise defenses haven’t caught up.

    In an exclusive interview with MoveTheNeedle.news, Trustpair CEO Baptiste Collot explains why manual controls like callbacks and email confirmations are failing, where fraud exploits operational change, and why continuous validation is becoming a baseline requirement.

    📖 movetheneedle.news/brands/ai-p

    #AI #fraud #technology #innovation #nacha2026 #vendorrisk

  27. Fake employees and compromised contractors are forcing organizations to rethink vendor vetting, hiring security, and identity controls.

    Our team is seeing more incidents where attackers don’t exploit vulnerabilities—they exploit trust. In the latest Cyberside Chats episode, @sherridavidoff and @MDurrin unpack Amazon’s recent incident in which a North Korean IT worker was detected through behavioral anomalies and a Russian state-sponsored campaign abusing trusted infrastructure and edge devices.

    Watch or listen to hear why hiring workflows, contractors, credentials, and edge devices are now part of your attack surface and what to do about it.

    Watch the video: youtu.be/WE8p9I3uUuA

    Listen to the podcast: chatcyberside.com/e/amazon-s-d

    #LMGSecurity #CybersideChats #IdentitySecurity #VendorRisk #InitialAccess #ZeroTrust #SecurityLeadership

  28. Fake employees and compromised contractors are forcing organizations to rethink vendor vetting, hiring security, and identity controls.

    Our team is seeing more incidents where attackers don’t exploit vulnerabilities—they exploit trust. In the latest Cyberside Chats episode, @sherridavidoff and @MDurrin unpack Amazon’s recent incident in which a North Korean IT worker was detected through behavioral anomalies and a Russian state-sponsored campaign abusing trusted infrastructure and edge devices.

    Watch or listen to hear why hiring workflows, contractors, credentials, and edge devices are now part of your attack surface and what to do about it.

    Watch the video: youtu.be/WE8p9I3uUuA

    Listen to the podcast: chatcyberside.com/e/amazon-s-d

    #LMGSecurity #CybersideChats #IdentitySecurity #VendorRisk #InitialAccess #ZeroTrust #SecurityLeadership

  29. Fake employees and compromised contractors are forcing organizations to rethink vendor vetting, hiring security, and identity controls.

    Our team is seeing more incidents where attackers don’t exploit vulnerabilities—they exploit trust. In the latest Cyberside Chats episode, @sherridavidoff and @MDurrin unpack Amazon’s recent incident in which a North Korean IT worker was detected through behavioral anomalies and a Russian state-sponsored campaign abusing trusted infrastructure and edge devices.

    Watch or listen to hear why hiring workflows, contractors, credentials, and edge devices are now part of your attack surface and what to do about it.

    Watch the video: youtu.be/WE8p9I3uUuA

    Listen to the podcast: chatcyberside.com/e/amazon-s-d

    #LMGSecurity #CybersideChats #IdentitySecurity #VendorRisk #InitialAccess #ZeroTrust #SecurityLeadership

  30. Pornhub discloses Premium user data exposure linked to third-party Mixpanel analytics.
    technadu.com/pornhub-premium-u

    • Third-party vendor exposure
    • Analytics data allegedly involved
    • No passwords or payment data confirmed
    • ShinyHunters extortion claims under investigation

    #DataBreach #CyberSecurity #VendorRisk #Infosec

  31. Pornhub discloses Premium user data exposure linked to third-party Mixpanel analytics.
    technadu.com/pornhub-premium-u

    • Third-party vendor exposure
    • Analytics data allegedly involved
    • No passwords or payment data confirmed
    • ShinyHunters extortion claims under investigation

    #DataBreach #CyberSecurity #VendorRisk #Infosec

  32. Pornhub discloses Premium user data exposure linked to third-party Mixpanel analytics.
    technadu.com/pornhub-premium-u

    • Third-party vendor exposure
    • Analytics data allegedly involved
    • No passwords or payment data confirmed
    • ShinyHunters extortion claims under investigation

    #DataBreach #CyberSecurity #VendorRisk #Infosec

  33. A new investigation highlights how contractor access allegedly played a central role in a major cyber disruption at Russia’s flagship airline.

    The attackers reportedly leveraged access from a small software vendor, escalated privileges inside the environment, and deployed multiple malware tools - ultimately causing extensive operational impact.

    The case underscores persistent challenges around vendor oversight and third-party access management.

    How can organizations better balance operational convenience with stringent access controls?

    Source: therecord.media/russia-flagshi

    Follow @technadu for ongoing threat intelligence updates.

    #CyberSecurity #ThreatIntel #IncidentResponse #SupplyChainSecurity #VendorRisk #AviationSecurity #InfoSec

  34. A new investigation highlights how contractor access allegedly played a central role in a major cyber disruption at Russia’s flagship airline.

    The attackers reportedly leveraged access from a small software vendor, escalated privileges inside the environment, and deployed multiple malware tools - ultimately causing extensive operational impact.

    The case underscores persistent challenges around vendor oversight and third-party access management.

    How can organizations better balance operational convenience with stringent access controls?

    Source: therecord.media/russia-flagshi

    Follow @technadu for ongoing threat intelligence updates.

    #CyberSecurity #ThreatIntel #IncidentResponse #SupplyChainSecurity #VendorRisk #AviationSecurity #InfoSec

  35. A new investigation highlights how contractor access allegedly played a central role in a major cyber disruption at Russia’s flagship airline.

    The attackers reportedly leveraged access from a small software vendor, escalated privileges inside the environment, and deployed multiple malware tools - ultimately causing extensive operational impact.

    The case underscores persistent challenges around vendor oversight and third-party access management.

    How can organizations better balance operational convenience with stringent access controls?

    Source: therecord.media/russia-flagshi

    Follow @technadu for ongoing threat intelligence updates.

    #CyberSecurity #ThreatIntel #IncidentResponse #SupplyChainSecurity #VendorRisk #AviationSecurity #InfoSec

  36. iQ Credit Union has disclosed that a ransomware incident at its vendor, Marquis Software Solutions, exposed personal information of over 111K Washington residents. The attacker accessed files containing names, SSNs, dates of birth, addresses, and partial financial data after exploiting a SonicWall firewall.

    Identity protection services are being provided, and individuals are advised to monitor accounts and consider credit freezes.

    How should financial institutions rethink vendor-risk strategies moving forward?

    Source: claimdepot.com/data-breach/iq-

    Share your insights and follow us for ongoing threat-intelligence updates.

    #infosec #databreach #FinancialSecurity #VendorRisk #SonicWall #ThreatIntel #IdentityProtection #Ransomware #SecurityAwareness

  37. iQ Credit Union has disclosed that a ransomware incident at its vendor, Marquis Software Solutions, exposed personal information of over 111K Washington residents. The attacker accessed files containing names, SSNs, dates of birth, addresses, and partial financial data after exploiting a SonicWall firewall.

    Identity protection services are being provided, and individuals are advised to monitor accounts and consider credit freezes.

    How should financial institutions rethink vendor-risk strategies moving forward?

    Source: claimdepot.com/data-breach/iq-

    Share your insights and follow us for ongoing threat-intelligence updates.

    #infosec #databreach #FinancialSecurity #VendorRisk #SonicWall #ThreatIntel #IdentityProtection #Ransomware #SecurityAwareness

  38. iQ Credit Union has disclosed that a ransomware incident at its vendor, Marquis Software Solutions, exposed personal information of over 111K Washington residents. The attacker accessed files containing names, SSNs, dates of birth, addresses, and partial financial data after exploiting a SonicWall firewall.

    Identity protection services are being provided, and individuals are advised to monitor accounts and consider credit freezes.

    How should financial institutions rethink vendor-risk strategies moving forward?

    Source: claimdepot.com/data-breach/iq-

    Share your insights and follow us for ongoing threat-intelligence updates.

    #infosec #databreach #FinancialSecurity #VendorRisk #SonicWall #ThreatIntel #IdentityProtection #Ransomware #SecurityAwareness

  39. FCC fines Comcast $1.5M following the FBCS vendor breach that exposed data from 237K+ customers.
    Comcast wasn't directly breached, but the settlement requires stronger third-party oversight and enhanced security controls.

    Full article:
    technadu.com/comcast-fined-1-5

    #Comcast #FCC #DataBreach #CyberSecurity #Infosec #VendorRisk #Privacy #TechNews

  40. FCC fines Comcast $1.5M following the FBCS vendor breach that exposed data from 237K+ customers.
    Comcast wasn't directly breached, but the settlement requires stronger third-party oversight and enhanced security controls.

    Full article:
    technadu.com/comcast-fined-1-5

    #Comcast #FCC #DataBreach #CyberSecurity #Infosec #VendorRisk #Privacy #TechNews

  41. FCC fines Comcast $1.5M following the FBCS vendor breach that exposed data from 237K+ customers.
    Comcast wasn't directly breached, but the settlement requires stronger third-party oversight and enhanced security controls.

    Full article:
    technadu.com/comcast-fined-1-5

    #Comcast #FCC #DataBreach #CyberSecurity #Infosec #VendorRisk #Privacy #TechNews

  42. FCC fines Comcast $1.5M following the FBCS vendor breach that exposed data from 237K+ customers.
    Comcast wasn't directly breached, but the settlement requires stronger third-party oversight and enhanced security controls.

    Full article:
    technadu.com/comcast-fined-1-5

    #Comcast #FCC #DataBreach #CyberSecurity #Infosec #VendorRisk #Privacy #TechNews

  43. FCC fines Comcast $1.5M following the FBCS vendor breach that exposed data from 237K+ customers.
    Comcast wasn't directly breached, but the settlement requires stronger third-party oversight and enhanced security controls.

    Full article:
    technadu.com/comcast-fined-1-5

    #Comcast #FCC #DataBreach #CyberSecurity #Infosec #VendorRisk #Privacy #TechNews

  44. 🚨 Discord confirms a data breach via a third-party customer support vendor.
    Attackers exfiltrated user emails, billing metadata, IPs, and chat transcripts — then attempted to extort the company.
    No core account data or DMs affected, but the supply chain weakness is evident.

    💭 Should platforms like Discord reduce vendor dependencies to limit exposure?

    🧠 Follow @technadu for real-time threat alerts, digital privacy insights, and vendor risk analyses.

    #DiscordBreach #CyberAttack #Infosec #DataSecurity #Privacy #ThreatIntelligence #CyberAwareness #DataBreach #VendorRisk

  45. 🚨 Discord confirms a data breach via a third-party customer support vendor.
    Attackers exfiltrated user emails, billing metadata, IPs, and chat transcripts — then attempted to extort the company.
    No core account data or DMs affected, but the supply chain weakness is evident.

    💭 Should platforms like Discord reduce vendor dependencies to limit exposure?

    🧠 Follow @technadu for real-time threat alerts, digital privacy insights, and vendor risk analyses.

    #DiscordBreach #CyberAttack #Infosec #DataSecurity #Privacy #ThreatIntelligence #CyberAwareness #DataBreach #VendorRisk

  46. 🚨 Discord confirms a data breach via a third-party customer support vendor.
    Attackers exfiltrated user emails, billing metadata, IPs, and chat transcripts — then attempted to extort the company.
    No core account data or DMs affected, but the supply chain weakness is evident.

    💭 Should platforms like Discord reduce vendor dependencies to limit exposure?

    🧠 Follow @technadu for real-time threat alerts, digital privacy insights, and vendor risk analyses.

    #DiscordBreach #CyberAttack #Infosec #DataSecurity #Privacy #ThreatIntelligence #CyberAwareness #DataBreach #VendorRisk

  47. 🚨 Discord confirms a data breach via a third-party customer support vendor.
    Attackers exfiltrated user emails, billing metadata, IPs, and chat transcripts — then attempted to extort the company.
    No core account data or DMs affected, but the supply chain weakness is evident.

    💭 Should platforms like Discord reduce vendor dependencies to limit exposure?

    🧠 Follow @technadu for real-time threat alerts, digital privacy insights, and vendor risk analyses.

    #DiscordBreach #CyberAttack #Infosec #DataSecurity #Privacy #ThreatIntelligence #CyberAwareness #DataBreach #VendorRisk

  48. Leaked and Loaded: DOGE’s API Key Crisis

    One leaked API key exposed 52 private LLMs and potentially sensitive systems across SpaceX, Twitter, and even the U.S. Treasury.

    In this episode of Cyberside Chats, @sherridavidoff and @MDurrin break down the DOGE/XAI API key leak. They share how it happened, why key management is a growing threat, and what you should do to protect your organization from similar risks.

    🎥 Watch the video: youtu.be/Lnn225XlIc4

    🎧 Listen to the podcast: chatcyberside.com/e/api-key-ca

    #APIsecurity #Cybersecurity #DevSecOps #PenetrationTesting #LMGSecurity #CybersideChats #IncidentResponse #VendorRisk #KeyLeak #CISO #ITsecurity #DFIR #Pentest

  49. Leaked and Loaded: DOGE’s API Key Crisis

    One leaked API key exposed 52 private LLMs and potentially sensitive systems across SpaceX, Twitter, and even the U.S. Treasury.

    In this episode of Cyberside Chats, @sherridavidoff and @MDurrin break down the DOGE/XAI API key leak. They share how it happened, why key management is a growing threat, and what you should do to protect your organization from similar risks.

    🎥 Watch the video: youtu.be/Lnn225XlIc4

    🎧 Listen to the podcast: chatcyberside.com/e/api-key-ca

    #APIsecurity #Cybersecurity #DevSecOps #PenetrationTesting #LMGSecurity #CybersideChats #IncidentResponse #VendorRisk #KeyLeak #CISO #ITsecurity #DFIR #Pentest

  50. Leaked and Loaded: DOGE’s API Key Crisis

    One leaked API key exposed 52 private LLMs and potentially sensitive systems across SpaceX, Twitter, and even the U.S. Treasury.

    In this episode of Cyberside Chats, @sherridavidoff and @MDurrin break down the DOGE/XAI API key leak. They share how it happened, why key management is a growing threat, and what you should do to protect your organization from similar risks.

    🎥 Watch the video: youtu.be/Lnn225XlIc4

    🎧 Listen to the podcast: chatcyberside.com/e/api-key-ca

    #APIsecurity #Cybersecurity #DevSecOps #PenetrationTesting #LMGSecurity #CybersideChats #IncidentResponse #VendorRisk #KeyLeak #CISO #ITsecurity #DFIR #Pentest

  51. ⚠️ Cyberattack alert: Malicious AI-art tool siphons 1.1 TB of Disney data 🎨🔓

    This breach shows how AI services can be weaponized:
    🎨 AI-art app trojanized to grant remote PC control
    🔑 Compromised credentials & Slack access
    📂 Copied from 1,400+ private channels
    💬 Exfiltrated 44 M messages, customer records, employee IDs
    🚨 Leaked when ransom demands weren’t met

    🛡️ Action steps:
    🛑 Vet and sandbox AI/third-party tools
    🔍 Monitor unusual outbound traffic
    🔐 Enforce least-privilege on endpoints
    🔒 Audit creative apps for hidden payloads

    Stay ahead of AI-driven threats—visibility and controls are non-negotiable.

    #DataBreach #AIsecurity #ThreatIntel #VendorRisk #Disney
    bankinfosecurity.com/hacker-ex