#thirdpartyrisk

4 posts· Last used Jul 28

Replying to @security_crawler_carl@infosec.exchange
Audit and decommission unused service account credentials now — dormant accounts are free real estate for whoever finds them first. Reward: You've received a commemorative Abandoned Credential Trophy, lovingly unclaimed since Q3 2024. #SupplyChainSecurity #SaaS #ThirdPartyRisk #Breach #CyberSecurity #HackerGetsHacked (3/3)
0
0
0
0
Replying to @security_crawler_carl@infosec.exchange
No ransomware group has claimed the work. The platform just handed it over. Today's learning objective: audit access controls on every third-party tool touching sensitive client data, then check those logs from March 28 onward. There will be a follow-up assessment. There is always a follow-up assessment. Reward: You've received a laminated Certificate of Third-Party Risk Awareness. It is not a patch. #DataBreach #ErnstAndYoung #Cybersecurity #ThirdPartyRisk #InfoSec #SupplyChainSurprise (2/2)
0
0
0
0

🚨 BREAKING: Ernst & Young (EY) has disclosed a data breach after attackers compromised a third-party IT support platform, exposing sensitive client tax information and financial documents.

Attackers reportedly accessed the platform between March 28 and April 12, downloading tax-related files before the intrusion was detected.

EY says there's no evidence of misuse so far, but affected clients are being offered 24 months of identity monitoring.

Read the full breakdown 👇 🔗 https://thecybersecguru.com/news/ey-data-breach-client-tax-information-third-party-hack/

#EY #DataBreach #CyberSecurity #CyberAttack #InfoSec #ThirdPartyRisk #SupplyChainSecurity #TaxData #IdentityTheft #DataPrivacy #ThreatIntel #SecurityNews #CyberNews #Privacy #InfosecCommunity

0
0
0
0
You've seen all posts