CuraSec

tag: Vendor-Breach · 4 items

  • Engineer — Learn: ShinyHunters used internal-impersonation social engineering to target a security vendor employee; no software vulnerability involved, but worth reviewing your own internal verification procedures for sensitive access requests from apparent colleagues.
  • SOC/IR — Learn: Confirms ShinyHunters is actively targeting security vendor employees via insider-impersonation lures; no IOCs or ATT&CK-mappable TTPs are published here, so no immediate detection work is actionable.
  • Leader — Plan: If ReliaQuest is in your vendor stack, formally confirm with them that no client data was at risk during this incident and request a written attestation; the failed outcome reduces urgency but does not eliminate the vendor-risk checkbox.
  • Engineer — Skip
  • SOC/IR — Learn: No IOCs, TTPs, or detection surface published; monitor for follow-up reporting that may yield hunt queries or indicators.
  • Leader — Act: LexisNexis is a common enterprise vendor for due diligence and data enrichment — confirm this week whether your organization uses Diligence, Metabase API, or Newsdesk, and formally request a vendor incident report and data-exposure assessment.
  • Engineer — Plan: If your pipelines integrate with Hugging Face or consume OpenAI APIs for model evaluation, audit those integration points and review access logs covering the incident window; watch for follow-on disclosure of specific technical details before determining whether credential rotation or config changes are needed.
  • SOC/IR — Plan: No IOCs or TTPs are available yet, but organizations using either platform should pull API access logs for the incident period and queue a hunt once the full disclosure provides behavioral indicators; monitor OpenAI’s and Hugging Face’s incident update pages for actionable details.
  • Leader — Act: Confirm whether your organization uses OpenAI or Hugging Face for model evaluation, request a vendor attestation or incident report this week, and brief leadership proactively — the high public profile of this disclosure means board or customer questions are likely before a full technical picture emerges.
2026-07-18 · BleepingComputer · source ↗ #vendor-breach#healthcare#extortion
  • Engineer — Skip
  • SOC/IR — Learn: Active investigation at a major healthcare vendor with confirmed unauthorized access and extortion claims, but no IOCs, TTPs, or ATT&CK-mappable behaviors have been published yet — nothing actionable to hunt or detect on today.
  • Leader — Act: Abbott confirmed unauthorized access to Exact Sciences legacy systems in its Cancer Diagnostics division and is probing a separate LabCentral portal breach with data-theft claims; if your organization uses Abbott lab or diagnostics services, confirm your exposure this week and request a written attestation of incident scope from your account contact.