< ciso
brief />
Tag Banner

All news with #third party risk tag

106 articles

FBI Removes Contractor Over ShinyHunters Job Portal Breach

🔒 The FBI removed an Accenture contractor after an alleged role in a ShinyHunters breach that exposed thousands of bureau employees' personal data. Reuters sources say the incident stemmed from a third-party platform security failure where a contractor failed to apply an explicit patch. The FBI cited mitigation steps and removal of the contractor, while Accenture affirmed continued support for the FBI mission. Reports indicate the exploited platform was Oracle PeopleSoft and the attack leveraged a CVE-2026-35273 bypass.
read more →

Frontline Education breach exposes K–12 employee data

🔒 A third-party breach at Frontline Education exposed Social Security numbers and personal details of K–12 staff after a vulnerability was discovered on August 14, 2026. The vendor says it investigated, remediated the issue with external help, engaged law enforcement and will notify affected individuals by email and post. So far there has been no public confirmation on the company’s site and the scale of impacted districts and staff remains unclear.
read more →

Frontline Education breach exposes employee data

🔐 Frontline Education has informed school districts of a data breach after attackers exploited a vulnerability in a third-party application to access its systems and steal employee information. The company identified the issue on August 14, 2026, engaged a cybersecurity firm, remediated the vulnerability, and notified law enforcement. Impacted individuals may include district staff whose Social Security numbers, email addresses, and physical addresses were exposed. Frontline will offer notifications and two years of TransUnion credit monitoring unless a district opts out.
read more →

Bitget breach traced to third‑party security flaw

🔒 Bitget disclosed that an attacker exploited a vulnerability in a third‑party security product to obtain high‑level internal credentials and initiate fraudulent withdrawals on September 24, stealing about $388 million from its hot and warm wallets while cold wallets remained secure. The exchange isolated affected systems, revoked credentials, restricted internal access, and engaged Mandiant and SlowMist to assist its investigation. Bitget says customer balances are intact and its Protection Fund will cover losses; Bitcoin withdrawals have resumed and other assets will reopen in stages.
read more →

Abandoned CDN Domains Expose Sites to Remote Risk

🔒 In July 2025 an expired CDN domain was re-registered and began serving content to thousands of sites that still referenced its hostnames. The new owner controls wildcard DNS and can choose what those pages load, creating a supply-chain risk that server-side tooling often misses. Content Security Policy (CSP) in report-only mode provides a low-risk way to discover and monitor what third-party scripts actually execute. Compliance mandates such as PCI DSS v4.0.1 now require inventorying and alerting on scripts that run on payment pages, and services like Report URI can collect, archive, and alert on client-side script activity without adding site-side code.
read more →

Trezor: ShipMonk breach exposed 67,000 US customers

📣 Trezor disclosed that 67,000 additional U.S. customers were impacted by a ShipMonk breach, exposing names, emails, phone numbers, shipping addresses, and order numbers from Nov 2019 to Aug 2021. The company emphasized that hardware wallet security was not affected and that it had repeatedly requested deletion of customer data. ShipMonk reportedly used a Metabase instance vulnerable to CVE-2026-72898, and the incident is tied to the ShinyHunters extortion gang.
read more →

FBI probes massive ID scan breach at IDscan.net

🔍 A large cache of 153 million digital driving-license scans and other ID documents was listed for sale on the dark web, traced to identity verification provider IDscan.net. The haul also included millions of ID cards, travel documents and medical cards, and affected high-profile individuals. IDscan.net has not issued a full public statement while an FBI investigation into the source of the images is underway, raising supply-chain security concerns for organizations that rely on third-party verification services.
read more →

Defense Contractors Report Rising Scores, Falling Confidence

📊 The CyberSheath 2026 State of the DIB Report finds average SPRS scores reached a five-year high, yet contractor confidence in those self-assessments dropped significantly. The study highlights tensions between improved reported cybersecurity maturity under CMMC self-assessments and growing doubts about score accuracy. Contractors want easier DFARS implementation and more vendor options while still supporting minimum mandated standards.
read more →

Police Conceal Use of Flock License Plate Cameras

🚨A usage policy for Flock automated license plate reader (ALPR) cameras in Wapello County, Iowa, instructs officers to refrain from informing vehicle occupants or routinely documenting ALPR use in reports. The document explicitly orders: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE” and to avoid mentioning it in reports unless absolutely necessary. This secrecy echoes prior law enforcement efforts to conceal surveillance tools such as IMSI-catchers.
read more →

Study: Mid‑Market Firms Drive Majority of Ransomware Hits

📊 A Black Kite study finds that 73% of ransomware victims since 2023 were mid‑market firms with $10m–$1bn in revenue. The report analyzed 13,336 disclosed incidents and scanned 120,128 mid‑market companies, revealing that lower mid‑market organizations bore the largest share of attacks. Manufacturing is the sector most targeted, and common security gaps include KEVs, patching failures, high‑severity CVEs and deficient DMARC. Black Kite warns AI will compound the triage burden for small security teams.
read more →

UK Manufacturing Cyber Resilience Falls Short

🛠️ A new Make UK report finds that around 30% of UK manufacturers experienced a cyber incident in the past year, often through their supply chain. The study highlights significant operational and financial impacts, including production delays and material shortages, while many firms still lack formal response plans, CISO roles or clear cyber insurance coverage. The report urges board-level attention and improved supplier assurance.
read more →

AWS CyberVadis 2026 Report Eases Supplier Due Diligence

🔒 Amazon Web Services (AWS) completed the 2026 CyberVadis assessment and achieved the highest score (Mature) across all evaluated areas, demonstrating commitment to elevated cloud-security expectations. The report and scorecard are now available to help customers reduce third-party due-diligence burdens and map AWS controls to common industry frameworks. Customers can download the full assessment via the CyberVadis portal or AWS Artifact and contact their AWS account team with questions.
read more →

Open Source Growing Up: Enterprise Trust and Risk

🔍 Open Source's informal era is ending as enterprises and regulators demand accountability, continuity, and demonstrable maintenance. The community will split: projects that adopt enterprise-grade practices—reachable maintainers, disclosure paths, and continuous proof-of-life—and projects that remain community-driven without those guarantees. Vendors and foundations will increasingly provide contracts, long-term support, and retirement pathways to bridge gaps while the free, volunteer-led ecosystem continues alongside.
read more →

Operationalize third‑party cyber risk, don’t rely on heroics

🔒 Third-party risk often fails in practice because security teams are looped in too late, turning reviews into last-minute blockers. The author recommends establishing formal intake, clear timelines, and joint workflows with procurement, legal, and finance so security can assess vendors before contracts are signed. Emphasis is placed on using contracts to enforce remediation and adapting processes for risks introduced by AI and shadow IT.
read more →

Canada Signs UN Cybercrime Convention, Driving Cooperation

🛡️ Canada signed the UN Convention against Cybercrime to strengthen international cooperation on electronic evidence, mutual legal assistance, and capacity building. The treaty emphasizes 24x7 contact points, human-rights safeguards, and technical assistance for countries with limited cybercrime capabilities. Fortinet highlights the need for sustained public-private partnerships to operationalize the treaty and accelerate cross-border disruption.
read more →

Ernst & Young discloses support system data breach

🔒 Ernst & Young has notified clients of a data breach after a third-party support ticket system used by its IT staff was compromised. The company says support tickets may have contained documents with client tax information and that unauthorized access occurred between March 28 and April 12. EY detected anomalous activity on April 23, engaged external cybersecurity experts, secured systems, and notified law enforcement. Affected clients are offered 24 months of identity monitoring through Experian.
read more →

Lidl warns customers after third‑party data theft

🛡️ Lidl has alerted customers in Germany, Belgium and the Netherlands after personal data was stolen from a third‑party IT provider. The retailer said the online shop itself was not affected but a separately stored file containing names, phone numbers, emails, birth dates and customer numbers was accessed. Lidl stated passwords, payment details and delivery addresses are not impacted and urged vigilance against phishing. Forensics experts and authorities have been engaged and customers are advised to verify senders and avoid clicking unknown links.
read more →

Lidl discloses online shop customer data breach

🔒 Lidl notified customers in Germany, Belgium, and the Netherlands that attackers accessed a separately stored file at a third‑party service provider and stole personal data from users of its online shop. The retailer said the shop's systems were not affected, but it cannot yet exclude the theft of passwords, billing or payment details. Lidl and the service provider have reported the incident to authorities and engaged forensic experts, while warning customers to watch for phishing and identity fraud.
read more →

Google Cloud designated a UK critical third party

🛡️ Today Google Cloud announced that on July 10 the U.K. Treasury designated Google Cloud EMEA as a critical third party (CTP) to the U.K. financial sector. The designation acknowledges the systemic impact of services used by U.K. firms and places Google Cloud EMEA under direct oversight by the Bank of England, PRA, and FCA. Google Cloud commits to constructive engagement with regulators and to help customers meet operational resilience and third‑party risk requirements.
read more →

AWS designated a critical third party for UK finance

🔐 Amazon Web Services EMEA Sarl (AWS) has been designated a critical third party (CTP) to the UK financial sector under the CTP regime that came into force on January 1, 2025. The regime gives the Bank of England, PRA, and FCA powers to set requirements and exercise direct oversight over designated providers. AWS will self-assess its designated Systemic Third-Party Services (STPS) against the criteria and engage with regulators while supporting customers’ operational resilience.
read more →