Breach Watch

Written for risk decisions, not headlines.

Breach, ransomware, vulnerability, advisory and threat intelligence, classified by LiveThreat and analysed in an ADTP brief for every item.

13Last 24 hours
344Last 7 days
36Critical, 7 days

Showing 20 of 4,065

Vulnerability ADTP BRIEF 🐛

BREACH WATCH BRIEF

Critical Remote Code Execution Vulnerability (CVE‑2026‑107406) in Citrix NetScaler ADC & Gateway Appliances

Citrix disclosed CVE‑2026‑107406, a critical memory‑overflow flaw in NetScaler ADC and Gateway that can enable remote code execution when the appliance acts as a SAML IdP/SP. The vulnerability underscores the importance of continuous configuration monitoring and rapid patching for audit readiness.

Cloud & Infrastructure Providers Vulnerability Exploit
Critical · Oct 9, 2026 · DataBreachToday
Read the full brief →
Vulnerability ADTP BRIEF ☁️

BREACH WATCH BRIEF

Remote Code Execution Vulnerability Discovered in Citrix NetScaler ADC and Gateway

Citrix NetScaler ADC and Gateway appliances configured as SAML IdP/SP contain critical RCE flaws (CVE‑2026‑19490, CVE‑2026‑88771, CVE‑2026‑88779, CVE‑2026‑88772). The issue underscores the need for continuous vulnerability‑management and configuration‑hardening controls to maintain audit‑ready evidence.

Cloud & Infrastructure Providers Vulnerability Exploit
High · Oct 9, 2026 · CIS Advisories
Read the full brief →
Vulnerability ADTP BRIEF 👤

BREACH WATCH BRIEF

Researchers Release Working Exploit for Pre‑Auth AnyDesk Linux RCE Granting Root Access

Researchers have published a functional exploit for a pre‑authentication remote code execution flaw in AnyDesk's Linux client that provides root access. The vulnerability highlights the need for robust vulnerability‑management and patch‑verification controls to maintain audit‑ready evidence across frameworks.

Technology & SaaS Vulnerability Exploit
Critical · Oct 9, 2026 · The Hacker News
Read the full brief →
Vulnerability ADTP BRIEF 🐛

BREACH WATCH BRIEF

Improper Authentication in AhsayCBS Backup Utility (CVE‑2026‑105133) Enables Crypto‑Miner Deployment

AhsayCBS backup software contains an authentication bypass (CVE‑2026‑105133) that attackers are exploiting to install XMRig miners disguised as Microsoft Edge. The flaw underscores the importance of robust authentication controls and timely patching for audit readiness.

Technology & SaaS Vulnerability Exploit
Medium · Oct 9, 2026 · The Hacker News
Read the full brief →
Vulnerability ADTP BRIEF 👤

BREACH WATCH BRIEF

Critical Remote‑Code‑Execution Vulnerability in SonicWall SMA1000 Appliances (CVE‑2026‑102255) Exploited in the Wild

SonicWall’s SMA1000 series (models 6210, 7210, 8200v) contain a maximum‑severity SSRF/RCE flaw (CVE‑2026‑102255) that attackers are already probing. The issue underscores the need for robust access‑control, rapid patching, and audit‑ready evidence for compliance frameworks.

Technology & SaaS Vulnerability Exploit
Critical · Oct 9, 2026 · BleepingComputer
Read the full brief →
Vulnerability ADTP BRIEF 🐛

BREACH WATCH BRIEF

Unauthenticated Attackers Can Crash NVIDIA DCGM Exporter (CVE-2026-47483), Threatening AI GPU Monitoring

A high‑severity flaw (CVE‑2026‑47483) in NVIDIA’s DCGM Exporter lets anyone on the Internet send crafted requests that crash the metrics service, exposing GPU inventory and potentially halting AI workloads. The issue underscores the importance of authenticated observability controls for audit‑ready environments.

Cloud & Infrastructure Providers Misconfiguration
High · Oct 9, 2026 · Help Net Security
Read the full brief →
Vulnerability ADTP BRIEF 👤

BREACH WATCH BRIEF

Critical Improper Access Control in ProFTPD (CVE‑2015‑3306) Exploited by Flax Typhoon

Flax Typhoon is weaponising CVE‑2015‑3306, a critical improper‑access‑control bug in ProFTPD that grants unauthenticated file‑system access. Organizations must patch and prove control‑area compliance to satisfy audit expectations.

Other / Unknown Vulnerability Exploit
Critical · Oct 9, 2026 · The Hacker News
Read the full brief →
Vulnerability ADTP BRIEF 🐛

BREACH WATCH BRIEF

FBI Warns FortiBleed Campaign Still Active, Compromising Over 86,000 FortiGate Firewalls

The FBI alerts that the FortiBleed (CVE‑2022‑42475) vulnerability continues to be weaponized, with more than 86,000 FortiGate firewalls reported compromised. The episode underscores the need for continuous vulnerability‑management evidence to satisfy audit and control‑assurance requirements.

Telecommunications Vulnerability Exploit
Critical · Oct 9, 2026 · HackRead
Read the full brief →
Vulnerability ADTP BRIEF 📡

BREACH WATCH BRIEF

Critical Remote Code Execution Vulnerability in Citrix NetScaler ADC and Gateway (CVE‑2026‑107406)

Citrix disclosed CVE‑2026‑107406, a memory‑overflow flaw in NetScaler ADC/Gateway that can enable RCE or DoS when the device is configured as a SAML SP/IdP. The high CVSS score underscores the need for rapid patching and configuration review to maintain audit‑ready control assurance.

Technology & SaaS Vulnerability Exploit
Critical · Oct 9, 2026 · Security Affairs
Read the full brief →
Vulnerability ADTP BRIEF 🐛

BREACH WATCH BRIEF

GoBalance Vulnerability Enables Hijacking of .onion Addresses via Secret Key Recovery

A cryptographic flaw in the GoBalance tool allows attackers to recover the private key that defines a hidden‑service .onion address, enabling full site takeover. This highlights the need for robust key‑management and continuous evidence of third‑party tool controls for audit readiness.

Other / Unknown Vulnerability Exploit
Critical · Oct 9, 2026 · The Hacker News
Read the full brief →
Vulnerability ADTP BRIEF 🐛

BREACH WATCH BRIEF

Critical Remote Code Execution Vulnerability (CVE‑2026‑107406) in Citrix NetScaler ADC & Gateway

Citrix disclosed CVE‑2026‑107406, a memory‑overflow RCE flaw affecting NetScaler ADC and Gateway when used as SAML IdP/SP. The vulnerability underscores the need for continuous patch management and audit‑ready evidence of remediation.

Cloud & Infrastructure Providers Vulnerability Exploit
Critical · Oct 9, 2026 · BleepingComputer
Read the full brief →
Vulnerability ADTP BRIEF 📋

BREACH WATCH BRIEF

Critical RCE Vulnerability in Citrix NetScaler ADC/Gateway (CVE‑2026‑107406)

Citrix disclosed CVE‑2026‑107406, a memory‑overflow bug in NetScaler ADC and Gateway that can enable remote code execution or denial‑of‑service under certain configurations. The flaw underscores the importance of continuous vulnerability management and auditable patch evidence for compliance readiness.

Cloud & Infrastructure Providers Vulnerability Exploit
Critical · Oct 9, 2026 · The Hacker News
Read the full brief →
Vulnerability ADTP BRIEF ☁️

BREACH WATCH BRIEF

Critical Vulnerability in AWS Bedrock AgentCore Allows Single Prompt to Hijack Entire Fleet

A newly disclosed vulnerability in AWS Bedrock AgentCore lets an attacker use one crafted AI prompt to take over every agent in an organization’s AWS environment. The flaw underscores the need for continuous AI‑service monitoring and control‑mapping to meet audit requirements.

Cloud & Infrastructure Providers Vulnerability Exploit
Critical · Oct 8, 2026 · Dark Reading
Read the full brief →
Vulnerability ADTP BRIEF ☁️

BREACH WATCH BRIEF

Critical Validation Flaws in Cisco Nexus Switches Enable Remote Code Execution and Denial‑of‑Service

Cisco disclosed five critical CVEs affecting Nexus 3000 and 9000 switches that allow arbitrary code execution with root privileges or forced reload when NX‑API, NGOAM, or MPLS OAM are active. The flaws underscore the need for continuous vulnerability‑management and configuration‑control evidence to satisfy audit and assurance requirements.

Cloud & Infrastructure Providers Vulnerability Exploit Zero-Day Exploit
Critical · Oct 8, 2026 · BleepingComputer
Read the full brief →
Vulnerability ADTP BRIEF ☁️

BREACH WATCH BRIEF

Multiple High‑Severity Auth Bypass & Credential Flaws in Red Lion N‑Tron 700 Series Switches

Seven critical vulnerabilities in Red Lion N‑Tron 700 series switches allow unauthenticated admin access, configuration tampering, and scripted reboot loops. The flaws expose gaps in authentication and change‑management controls that auditors and regulators scrutinize for trust‑worthiness.

Manufacturing & Industrial Vulnerability Exploit
High · Oct 8, 2026 · CISA Advisories
Read the full brief →
Vulnerability ADTP BRIEF ☁️

BREACH WATCH BRIEF

Critical Deserialization, SSRF, and Hard‑Coded Credential Flaws in Grid Protection Alliance openPDC/openHistorian

CISA reports six CVEs (CVSS 9.8) in openPDC and openHistorian that enable unauthenticated attackers to execute arbitrary code or perform SSRF. The flaws test the control objective of secure software lifecycle management, a key trust signal for energy‑sector auditors.

Energy & Utilities Vulnerability Exploit
Critical · Oct 8, 2026 · CISA Advisories
Read the full brief →
Vulnerability ADTP BRIEF 👤

BREACH WATCH BRIEF

Stored XSS (CVE‑2026‑105269) in Satel Netco Design Enables Arbitrary Script Execution

Satel Netco Design versions before v2.1.7 contain a stored cross‑site scripting flaw (CVE‑2026‑105269) that lets a privileged network operator inject malicious web content. Exploitation can lead to script execution, file enumeration, and possible code execution, raising compliance concerns for communications operators.

Telecommunications Vulnerability Exploit
High · Oct 8, 2026 · CISA Advisories
Read the full brief →
Vulnerability ADTP BRIEF 👤

BREACH WATCH BRIEF

Critical Arbitrary File Access Flaw (CVE‑2026‑21589) in Atlassian Data Center Products Under Active Exploitation

A CVSS 9.3 path‑traversal bug (CVE‑2026‑21589) affecting multiple Atlassian Data Center applications is being actively exploited to read sensitive files. Enterprises must patch, tighten access controls, and capture evidence of remediation to meet audit and trust requirements.

Technology & SaaS Vulnerability Exploit
Critical · Oct 8, 2026 · Security Affairs
Read the full brief →
Vulnerability ADTP BRIEF 👤

BREACH WATCH BRIEF

Improper Access Control in ProFTPD (CVE‑2015‑3306) Enables Remote File Read/Write

ProFTPD versions before 1.3.5a allow unauthenticated attackers to read or overwrite arbitrary files via FTP commands. The flaw underscores the need for auditable access‑control evidence and continuous monitoring to satisfy trust‑focused compliance reviews.

Technology & SaaS Vulnerability Exploit
High · Oct 8, 2026 · CISA KEV
Read the full brief →
Vulnerability ADTP BRIEF ☁️

BREACH WATCH BRIEF

Critical Path Traversal (CVE‑2021‑3199) in ONLYOFFICE Docs Enables Remote Code Execution

A path traversal flaw in ONLYOFFICE Docs (CVE‑2021‑3199) allows an attacker to embed a '..' sequence in an image‑upload request, bypassing JWT checks and potentially executing arbitrary code on the server. The vulnerability affects both SaaS and on‑premises deployments, raising immediate concerns for organizations that must prove secure third‑party component management.

Technology & SaaS Vulnerability Exploit
Critical · Oct 8, 2026 · CISA KEV
Read the full brief →
Page 1 of 204 Older →

Breach Watch intelligence is provided by LiveThreat, a product of a founding sponsor of the association. Every ADTP brief carries LiveThreat's analysis and links the original source.

Practitioner briefings

Written by the association: what the week's intelligence means for the controls you run.

Advisory · high

Reading a vendor's breach notice for what it does not say

A practitioner checklist for turning a supplier notification into an evidence request and a monitoring change.

TPR CYB
Read
Briefing · medium

Where AI inventory efforts stall, and the control that unblocks them

Findings from practitioner roundtables on AI governance programs in their first year.

AIG GRC
Read
Research

Evidence reuse across customer diligence and audit

How practitioners are organizing one evidence base to serve buyers and auditors at the same time.

GRC TRS
Read
Advisory · medium

Global Privacy Control signals and state opt-out obligations

What a site must do when it sees a GPC signal, and how to evidence it.

PRV
Read

Get the digest

No membership required. Confirm by email; unsubscribe in one click.