Skip to main content
Public website
Public website surface Marketing and explanation content. This is not the canonical authenticated runtime.
Canonical runtime: app.identityfirst.net
Threat Intelligence

Identity Security News

Live advisories from NCSC, CISA KEV, Microsoft, Krebs, and BleepingComputer — filtered for identity relevance.

Official Advisories

Government and federal vulnerability intelligence.

NCSC Alerts

NCSC

Content sourced from National Cyber Security Centre. IdentityFirst is not affiliated with this source.

CISA Known Exploited Vulnerabilities

CISA KEV
  • CVE-2026-88779 — NetScaler

    Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer

  • CVE-2026-104286 — FortiMail

    Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitra

  • CVE-2026-88772 — NetScaler

    Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code executi

  • CVE-2026-88771 — NetScaler

    Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.

  • CVE-2026-65660 — SharePoint

    Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.

  • CVE-2026-58704 — Pixel

    Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.

Content sourced from CISA Known Exploited Vulnerabilities Catalog. IdentityFirst is not affiliated with this source.

Security Research & Analysis

Vendor intelligence and investigative reporting.

Microsoft Security

Microsoft

Content sourced from Microsoft Security Blog. IdentityFirst is not affiliated with this source.

Krebs on Security

Krebs

Content sourced from Krebs on Security. IdentityFirst is not affiliated with this source.

Threat News & Breach Intelligence

Breaking incidents and publicly disclosed breaches.

BleepingComputer

BleepingComputer

Content sourced from BleepingComputer. IdentityFirst is not affiliated with this source.

Recent Breaches (HIBP)

HIBP
  • Neogen (435,963 accounts)

    In August 2026, the food and animal safety organisation Neogen was the target of a ShinyHunters "pay or leak" extortion attempt. The group later published data it claimed had been

  • CyrusOne (373,460 accounts)

    In August 2026, data centre operator CyrusOne was the target of a ShinyHunters "pay or leak" extortion attempt. The group subsequently published data allegedly obtained from the co

  • Double Counter (274,922 accounts)

    In October 2026, the Discord server protection service Double Counter suffered a data breach attributed to a vulnerability in the Metabase analytics tool. In its disclosure notice,

  • Angel One (6,765,054 accounts)

    In July 2024, the Indian stock brokerage firm Angel One confirmed that data leaked online related to a breach that occurred in April 2023. The leaked data included 7.9M user record

  • Medela (423,947 accounts)

    In September 2026, Swiss medical device company Medela was the target of a ShinyHunters "pay or leak" extortion campaign. The data allegedly obtained in the breach was later publis

Content sourced from Have I Been Pwned. IdentityFirst is not affiliated with this source.

Turn Alerts Into Action

IdentityFirstMRI™ surfaces identity-relevant findings from your own environment — not just the news.

Read-only. No changes made to your environment.