Skip to main content
Public website
Public website surface Marketing and explanation content. This is not the canonical authenticated runtime.
Canonical runtime: app.identityfirst.net
Threat Intelligence

Identity Security News

Live advisories from NCSC, CISA KEV, Microsoft, Krebs, and BleepingComputer — filtered for identity relevance.

Official Advisories

Government and federal vulnerability intelligence.

NCSC Alerts

NCSC

Content sourced from National Cyber Security Centre. IdentityFirst is not affiliated with this source.

CISA Known Exploited Vulnerabilities

CISA KEV

Content sourced from CISA Known Exploited Vulnerabilities Catalog. IdentityFirst is not affiliated with this source.

Security Research & Analysis

Vendor intelligence and investigative reporting.

Microsoft Security

Microsoft

Content sourced from Microsoft Security Blog. IdentityFirst is not affiliated with this source.

Krebs on Security

Krebs
  • Who’s Tracking You? Use This New Service to Find Out

    It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is alre…

  • Microsoft Plugs Nearly 400 Security Holes

    Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already bei…

  • Canadian Man Pleads Guilty in Snowflake Extortions

    A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort m…

  • Read This Before You Buy That TV Streaming Stick

    Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they sec…

Content sourced from Krebs on Security. IdentityFirst is not affiliated with this source.

Threat News & Breach Intelligence

Breaking incidents and publicly disclosed breaches.

BleepingComputer

BleepingComputer

Content sourced from BleepingComputer. IdentityFirst is not affiliated with this source.

Recent Breaches (HIBP)

HIBP
  • Carhartt (12,933,413 accounts)

    In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the comp

  • NIUS (6,090 accounts)

    In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly. The data included 6k unique email addresses along with names, physical add

  • Golf Canada (568,972 accounts)

    In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names

  • Oz Hair and Beauty (1,988,331 accounts)

    In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the comp

  • Fanlore (144,520 accounts)

    In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique e

Content sourced from Have I Been Pwned. IdentityFirst is not affiliated with this source.

Turn Alerts Into Action

IdentityFirstMRI™ surfaces identity-relevant findings from your own environment — not just the news.

Read-only. No changes made to your environment.