Identity Security News
Live advisories from NCSC, CISA KEV, Microsoft, Krebs, and BleepingComputer — filtered for identity relevance.
Official Advisories
Government and federal vulnerability intelligence.
NCSC Alerts
NCSC-
China-linked malicious actors called out by UK and international partners for targeting sensitive data globally
Joint advisory with international partners highlights malicious targeting of organisations from a range of sectors across the globe.
-
Incident affecting ASOS customers
ASOS has said it is investigating a cyber incident and that some customer personal information may have been accessed.
-
Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
-
Iranian cyber targeting of dissidents, activists and journalists
Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.
-
UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists
UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.
Content sourced from National Cyber Security Centre. IdentityFirst is not affiliated with this source.
CISA Known Exploited Vulnerabilities
CISA KEV-
CVE-2026-88779 — NetScaler
Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer
-
CVE-2026-104286 — FortiMail
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitra
-
CVE-2026-88772 — NetScaler
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code executi
-
CVE-2026-88771 — NetScaler
Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.
-
CVE-2026-65660 — SharePoint
Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.
-
CVE-2026-58704 — Pixel
Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges.
Content sourced from CISA Known Exploited Vulnerabilities Catalog. IdentityFirst is not affiliated with this source.
Security Research & Analysis
Vendor intelligence and investigative reporting.
Microsoft Security
Microsoft-
Post-quantum authentication: Why organizations should start testing certificate ecosystems now
Prepare for post-quantum authentication by testing certificate ecosystems now. Learn how Microsoft’s PQC TLS Pilot Program helps advance future readiness. The post Post-quantum aut…
-
3 lessons from frontier AI vulnerability research
Read how How Microsoft Security's FORGE Lab is scaling vulnerability research from Windows to the Linux kernel. The post 3 lessons from frontier AI vulnerability research appeared …
-
CISO perspectives on managing vulnerability risks in the age of AI
Learn how CISOs can mitigate cybersecurity risks and increase resilience in the age of AI-powered vulnerability management. The post CISO perspectives on managing vulnerability ris…
-
Preparing governments for an era of interconnected cyber risk
According to this year’s Microsoft Digital Defense Report, government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observed a…
Content sourced from Microsoft Security Blog. IdentityFirst is not affiliated with this source.
Krebs on Security
Krebs-
FBI Arrests Executive at Ransomware Negotiation Firm
Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters…
-
ShinyHunters Extorted Boeing Spin-off Prior to Arrests
A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify…
-
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. I…
-
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in …
Content sourced from Krebs on Security. IdentityFirst is not affiliated with this source.
Threat News & Breach Intelligence
Breaking incidents and publicly disclosed breaches.
BleepingComputer
BleepingComputer-
Cyber exec arrested in case allegedly tied to ShinyHunters hackers
Canadian cybersecurity executive Edward Dubrovsky has been arrested in Pennsylvania in connection with alleged extortion activity that multiple reports have linked to the FBI's ong…
-
ARTEX AI, Claude agents used in cyberattacks on South Korean banks
The cyberattacks that shook the South Korean financial sector earlier this month were launched by a Chinese hacker using the ARTEX AI penetration testing suite and Claude agents. […
-
Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management
Traditional attack surface management helps organizations discover exposed assets, but visibility alone is not enough to address threats. Criminal IP introduces AITEM, an AI-powere…
-
Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks. [...]
Content sourced from BleepingComputer. IdentityFirst is not affiliated with this source.
Recent Breaches (HIBP)
HIBP-
Neogen (435,963 accounts)
In August 2026, the food and animal safety organisation Neogen was the target of a ShinyHunters "pay or leak" extortion attempt. The group later published data it claimed had been
-
CyrusOne (373,460 accounts)
In August 2026, data centre operator CyrusOne was the target of a ShinyHunters "pay or leak" extortion attempt. The group subsequently published data allegedly obtained from the co
-
Double Counter (274,922 accounts)
In October 2026, the Discord server protection service Double Counter suffered a data breach attributed to a vulnerability in the Metabase analytics tool. In its disclosure notice,
-
Angel One (6,765,054 accounts)
In July 2024, the Indian stock brokerage firm Angel One confirmed that data leaked online related to a breach that occurred in April 2023. The leaked data included 7.9M user record
-
Medela (423,947 accounts)
In September 2026, Swiss medical device company Medela was the target of a ShinyHunters "pay or leak" extortion campaign. The data allegedly obtained in the breach was later publis
Content sourced from Have I Been Pwned. IdentityFirst is not affiliated with this source.
Turn Alerts Into Action
IdentityFirstMRI™ surfaces identity-relevant findings from your own environment — not just the news.
Read-only. No changes made to your environment.