Skip to main content
Public website
Public website surface Marketing and explanation content. This is not the canonical authenticated runtime.
Canonical runtime: app.identityfirst.net
Threat Intelligence

Identity Security News

Live advisories from NCSC, CISA KEV, Microsoft, Krebs, and BleepingComputer — filtered for identity relevance.

Official Advisories

Government and federal vulnerability intelligence.

NCSC Alerts

NCSC

Content sourced from National Cyber Security Centre. IdentityFirst is not affiliated with this source.

CISA Known Exploited Vulnerabilities

CISA KEV
  • CVE-2008-4250 — Windows

    Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that trigg

  • CVE-2009-1537 — DirectX

    Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitr

  • CVE-2010-0249 — Internet Explorer

    Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted ob

  • CVE-2010-0806 — Internet Explorer

    Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer

  • CVE-2026-41091 — Defender

    Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.

  • CVE-2026-45498 — Defender

    Microsoft Defender contains an unspecified vulnerability that allows for denial of service.

Content sourced from CISA Known Exploited Vulnerabilities Catalog. IdentityFirst is not affiliated with this source.

Security Research & Analysis

Vendor intelligence and investigative reporting.

Microsoft Security

Microsoft

Content sourced from Microsoft Security Blog. IdentityFirst is not affiliated with this source.

Krebs on Security

Krebs

Content sourced from Krebs on Security. IdentityFirst is not affiliated with this source.

Threat News & Breach Intelligence

Breaking incidents and publicly disclosed breaches.

BleepingComputer

BleepingComputer

Content sourced from BleepingComputer. IdentityFirst is not affiliated with this source.

Recent Breaches (HIBP)

HIBP
  • Kemper (269,299 accounts)

    In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign. The attackers alleged

  • Mytheresa (84,108 accounts)

    In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters "pay or leak" extortion group. After the ransom deadline passed, the grou

  • Ameriprise (502,597 accounts)

    In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group claimed possession of more than

  • 7-Eleven (185,256 accounts)

    In April 2026, 7-Eleven was the victim of a "pay or leak" extortion campaign by ShinyHunters, with the data later published that month. The incident exposed 185k unique email addre

  • Dragonica Lunaris (126,293 accounts)

    In December 2025, the European Dragonica private server Dragonica Lunaris suffered a data breach. The incident exposed 126k email addresses, usernames, dates of birth and bcrypt pa

Content sourced from Have I Been Pwned. IdentityFirst is not affiliated with this source.

Turn Alerts Into Action

IdentityFirstMRI™ surfaces identity-relevant findings from your own environment — not just the news.

Read-only. No changes made to your environment.