Identity Security News
Live advisories from NCSC, CISA KEV, Microsoft, Krebs, and BleepingComputer — filtered for identity relevance.
Official Advisories
Government and federal vulnerability intelligence.
NCSC Alerts
NCSC-
NCSC statement in response to recent incidents resulting from frontier AI evaluations
A statement from Ollie Whitehouse, Chief Technology Officer at the NCSC, on AI security following recent incidents.
-
UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations
GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign
-
UK and Allies urge critical sectors to improve defences against Russian intelligence targeting
New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers
-
The AI shift in cyber risk: why leaders must act now
Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk.
-
Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways
Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.
Content sourced from National Cyber Security Centre. IdentityFirst is not affiliated with this source.
CISA Known Exploited Vulnerabilities
CISA KEV-
CVE-2026-8452 — NetScaler ADC and NetScaler Gateway
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
-
CVE-2019-1068 — SQL Server
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
-
CVE-2026-33824 — Internet Key Exchange (IKE) Service Extensions
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
-
CVE-2026-55040 — SharePoint
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
-
CVE-2026-68820 — Windows Ancillary Function Driver for WinSock
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
-
CVE-2025-68686 — FortiOS
Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch develope
Content sourced from CISA Known Exploited Vulnerabilities Catalog. IdentityFirst is not affiliated with this source.
Security Research & Analysis
Vendor intelligence and investigative reporting.
Microsoft Security
Microsoft-
When AI infrastructure becomes the target: Securing gateways and control points
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The p…
-
The patch window is collapsing: Why security needs a new control plane
Organizations need protection that operates in the gap between discovery and remediation. The post The patch window is collapsing: Why security needs a new control plane appeared f…
-
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. Th…
-
Hunting MacSync Stealer infrastructure through behavioral pivots
MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots. The…
Content sourced from Microsoft Security Blog. IdentityFirst is not affiliated with this source.
Krebs on Security
Krebs-
Who’s Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is alre…
-
Microsoft Plugs Nearly 400 Security Holes
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already bei…
-
Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort m…
-
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they sec…
Content sourced from Krebs on Security. IdentityFirst is not affiliated with this source.
Threat News & Breach Intelligence
Breaking incidents and publicly disclosed breaches.
BleepingComputer
BleepingComputer-
Critical Avada WordPress theme flaw enables zero-click RCE
A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. [...]
-
New GPUThor attack defeats NVIDIA ECC protection for root access
A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escal…
-
Meta agrees to $18 billion settlement over teen social media harms
Meta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generals over allegations that Facebook and Instagram were …
-
Boston Scientific says cyberattack disrupted operations globally
Medical technology company Boston Scientific has been targeted in a cyberattack that disrupted some of its IT systems, causing operational disruptions globally. [...]
Content sourced from BleepingComputer. IdentityFirst is not affiliated with this source.
Recent Breaches (HIBP)
HIBP-
Carhartt (12,933,413 accounts)
In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data allegedly obtained from the comp
-
NIUS (6,090 accounts)
In July 2025, the German news service NIUS suffered a data breach which was subsequently leaked publicly. The data included 6k unique email addresses along with names, physical add
-
Golf Canada (568,972 accounts)
In mid-2026, hundreds of thousands of user records allegedly sourced from Golf Canada began circulating via Telegram. The data included 569k unique email addresses along with names
-
Oz Hair and Beauty (1,988,331 accounts)
In August 2026, Australian beauty retailer Oz Hair and Beauty was the target of an xpl0itrs extortion attack. The group subsequently published data allegedly obtained from the comp
-
Fanlore (144,520 accounts)
In August 2026, the Organization for Transformative Works (OTW) identified unauthorised access to the Fanlore wiki it operates. The breach resulted in the exposure of 145k unique e
Content sourced from Have I Been Pwned. IdentityFirst is not affiliated with this source.
Turn Alerts Into Action
IdentityFirstMRI™ surfaces identity-relevant findings from your own environment — not just the news.
Read-only. No changes made to your environment.