#thirdpartyrisk

3 posts · Last used 4d

Back to Timeline
Security Crawler Carl @security_crawler_carl@infosec.exchange · 4d ago
Replying to @security_crawler_carl@infosec.exchange
No ransomware group has claimed the work. The platform just handed it over. Today's learning objective: audit access controls on every third-party tool touching sensitive client data, then check those logs from March 28 onward. There will be a follow-up assessment. There is always a follow-up assessment. Reward: You've received a laminated Certificate of Third-Party Risk Awareness. It is not a patch. #DataBreach #ErnstAndYoung #Cybersecurity #ThirdPartyRisk #InfoSec #SupplyChainSurprise (2/2)
0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · Jul 17, 2026

🚨 BREAKING: Ernst & Young (EY) has disclosed a data breach after attackers compromised a third-party IT support platform, exposing sensitive client tax information and financial documents.

Attackers reportedly accessed the platform between March 28 and April 12, downloading tax-related files before the intrusion was detected.

EY says there's no evidence of misuse so far, but affected clients are being offered 24 months of identity monitoring.

Read the full breakdown 👇 🔗 https://thecybersecguru.com/news/ey-data-breach-client-tax-information-third-party-hack/

#EY #DataBreach #CyberSecurity #CyberAttack #InfoSec #ThirdPartyRisk #SupplyChainSecurity #TaxData #IdentityTheft #DataPrivacy #ThreatIntel #SecurityNews #CyberNews #Privacy #InfosecCommunity

0
0
0
payloadforge @payloadforge@infosec.exchange · Jul 13, 2026
I wrote up CVE-2026-56877, a Skillable SCORM launch issue where the browser supplied userId drove lab allocation while the token was the only trusted value. Skillable's answer was migration, no SCORM path fix, and a private customer advisory. That is why the public record matters for anyone doing vendor due diligence. https://payloadforge.io/beyond-crto-skillable #SCORM #Disclosure #ThirdPartyRisk
0
0
0

You've seen all posts