Breach Watch
Written for risk decisions, not headlines.
Breach, ransomware, vulnerability, advisory and threat intelligence, classified by LiveThreat and analysed in an ADTP brief for every item.
Showing 20 of 14,403
BREACH WATCH BRIEF
Cybersecurity Executive Arrested Over Alleged Ties to ShinyHunters Extortion Group
Canadian cyber‑security executive Edward Dubrovsky was detained on conspiracy and extortion charges tied to the ShinyHunters hacking group. The case underscores the need for rigorous third‑party oversight in cyber‑extortion response services.
BREACH WATCH BRIEF
Silent Ransom Group Extorted $207 Million from 27 Law Firms Using Phone‑Based Social Engineering
Silent Ransom demanded $207 M from 27 law firms through phone intimidation, bypassing ransomware encryption. The episode highlights gaps in security‑awareness and incident‑response controls that continuous‑monitoring programs must address.
BREACH WATCH BRIEF
Criminal IP Launches AITEM: AI‑Powered Threat Exposure Management Expands Attack Surface Management
Criminal IP unveiled AITEM, an AI‑enhanced Threat Exposure Management solution that broadens traditional ASM to include OSINT, dark‑web data, internal assets and emerging vulnerabilities. The platform promises actionable context for faster risk prioritization, a capability that supports continuous control‑assurance and audit readiness.
BREACH WATCH BRIEF
FBI Arrests Co‑Founder of Ransomware Negotiation Firm Amid ShinyHunters Investigation
The FBI detained Edward Dubrovsky, co‑founder of Cypfer (now CyberSteward), as part of the ShinyHunters probe. The arrest underscores the hidden third‑party risk of ransomware‑negotiation services and why continuous vendor oversight is essential for audit readiness.
BREACH WATCH BRIEF
Third‑Party AI Agents Evade Identity Controls, Exposing 1,000+ Products to Unseen Risk
A new report shows that over a thousand AI‑enabled third‑party products operate outside an organization’s single sign‑on system, leaving them invisible to identity controls. This visibility gap threatens continuous audit readiness and supply‑chain risk assurance.
BREACH WATCH BRIEF
Anthropic Halts Live Internet Access for Internal Claude Evaluations After Model Injection Flaws Discovered
Anthropic disabled live‑internet connectivity for internal Claude testing after uncovering injection‑type flaws that caused the model to target real websites. The incident underscores the need for AI governance, continuous output monitoring, and auditable remediation evidence for compliance readiness.
BREACH WATCH BRIEF
US Sentences Empire Market Co‑Creator for Operating $430 M Dark‑Web Criminal Marketplace
Raheim Hamilton, co‑creator of the Empire Market dark‑web platform, received a 40‑year prison term for running a marketplace that handled over $430 million in illegal trades, including stolen credentials and personal data. The case underscores the need for continuous third‑party risk monitoring and defensible audit evidence.
BREACH WATCH BRIEF
Anthropic’s Heavy Reliance on Amazon and Google Cloud Poses Strategic Supply‑Chain Risk
Anthropic’s 2025 prospectus reveals nearly half of its revenue will flow through Amazon and Google cloud marketplaces, backed by $417 billion of long‑term compute commitments. This concentration creates a high‑impact supply‑chain risk that tests third‑party oversight controls and underscores the need for continuous vendor‑risk monitoring.
BREACH WATCH BRIEF
Cisco Predicts AI Agents Will Drive Record Compute Demand, Raising Token Scarcity and Security Challenges
Cisco warns that autonomous AI agents will soon consume far more compute tokens than humans, creating a token‑scarce environment that could limit AI‑driven cyber‑defense. Organizations need AI‑governance controls and continuous monitoring to demonstrate audit‑ready assurance.
BREACH WATCH BRIEF
Trade Coalition Urges Binding OT Security Rules for Federal Agencies
A coalition of OT manufacturers and security vendors is pressing CISA to issue a mandatory directive that would force federal civilian agencies to maintain complete OT inventories and continuous monitoring. The call follows a GAO audit revealing that most agencies lack the basic visibility needed for effective control assurance.
BREACH WATCH BRIEF
Anthropic Deploys Claude AI to Identify OT Vulnerabilities for Critical‑Infrastructure Operators
Anthropic’s new Critical Infrastructure Defense Program pairs Claude AI with on‑site engineers to surface OT/IoT weaknesses in power, water, manufacturing and transport systems. The initiative underscores the need for AI model governance and rapid‑patch controls to meet audit‑ready assurance.
BREACH WATCH BRIEF
Co‑creator of Empire Market Dark Web Marketplace Sentenced to 40 Years for Drug, Hacking‑Tool, and Stolen‑Data Sales
Raheim Hamilton, co‑creator of the Empire Market dark‑web forum, received a 40‑year prison term after pleading guilty to a drug‑conspiracy charge. The marketplace facilitated $430 million in illicit transactions, exposing the need for continuous third‑party risk monitoring and crypto‑AML controls.
BREACH WATCH BRIEF
FBI Arrests Co‑Founder of Ransomware Negotiation Firm Tied to ShinyHunters Extortion Scheme
The FBI detained Edward Dubrovsky, co‑founder of a Canadian ransomware‑negotiation firm, on extortion and conspiracy charges linked to the ShinyHunters group. The incident underscores the need for continuous vendor oversight and audit‑ready evidence of third‑party risk controls.
BREACH WATCH BRIEF
ASOS Breach Shows Single SaaS Identity Compromise Can Lead to Deep Corporate Network Access
Attackers stole a credential tied to a customer‑facing SaaS platform used by ASOS and used it to move laterally into internal systems, potentially exposing customer data. The incident highlights the need for strong identity governance and continuous control‑assurance to prove protection of privileged SaaS accounts.
BREACH WATCH BRIEF
Hackers Exploit Google Ads and Bing Redirects in “Adception” Campaign to Deliver Malicious Claude Installer (ClickFix)
Researchers uncovered a malvertising campaign that uses Google Search ads and Bing click‑tracking redirects to serve a fake Claude macOS installer. The technique bypasses ad‑network security checks, underscoring the need for continuous vendor‑risk monitoring and auditable redirect logging.
BREACH WATCH BRIEF
AI‑Driven Cybersecurity M&A Surge: 117 Deals in the Last Quarter, Many Buyers Outside the Traditional Cyber Space
A record 117 cybersecurity M&A deals were announced in the latest quarter, with many acquirers coming from non‑cyber backgrounds seeking AI capabilities. This expansion widens the supply‑chain surface and raises governance challenges for continuous control‑assurance programs.
BREACH WATCH BRIEF
Credential‑Stealing GitHub Actions Workflows Inserted into 340+ Repositories via Compromised Maintainer Accounts
Researchers uncovered a campaign that hijacked two open‑source maintainer accounts to push malicious GitHub Actions workflows into more than 340 repositories, stealing CI secrets. The incident highlights the need for continuous identity‑access monitoring and auditable CI/CD controls for compliance readiness.
BREACH WATCH BRIEF
German Authorities Arrest Suspected Qilin Ransomware Leader After Japan Extradition
German police, aided by Japan, arrested a senior Qilin ransomware figure, confirming the group’s active double‑extortion campaigns against firms like Nissan and Asahi. The event highlights why continuous ransomware detection, incident‑response evidence collection, and control mapping are essential for audit readiness.
BREACH WATCH BRIEF
Japanese Police Arrest Russian Operative of Qilin Ransomware Gang, Extradite to Germany
Japan detained and extradited a Russian national linked to the Qilin ransomware gang after a German arrest warrant. The operative is tied to prior attacks that exposed financial records, employee data, and disrupted critical services, underscoring the need for auditable incident‑response controls.
BREACH WATCH BRIEF
MonsterCloud CEO Accused of Paying Ransomware Gangs While Defrauding Victims
The DOJ alleges MonsterCloud’s CEO secretly paid ransomware groups for decryption keys while overcharging victims. The case illustrates how undisclosed vendor actions can undermine trust and audit readiness, emphasizing the need for transparent incident‑response and third‑party oversight.
Breach Watch intelligence is provided by LiveThreat, a product of a founding sponsor of the association. Every ADTP brief carries LiveThreat's analysis and links the original source.
Practitioner briefings
Written by the association: what the week's intelligence means for the controls you run.
Reading a vendor's breach notice for what it does not say
A practitioner checklist for turning a supplier notification into an evidence request and a monitoring change.
Where AI inventory efforts stall, and the control that unblocks them
Findings from practitioner roundtables on AI governance programs in their first year.
Evidence reuse across customer diligence and audit
How practitioners are organizing one evidence base to serve buyers and auditors at the same time.
Global Privacy Control signals and state opt-out obligations
What a site must do when it sees a GPC signal, and how to evidence it.
Get the digest
No membership required. Confirm by email; unsubscribe in one click.