<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vendor-Breach on CuraSec</title><link>https://curasec.metacog.co.kr/tags/vendor-breach/</link><description>Recent content in Vendor-Breach on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 25 Aug 2026 11:39:54 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/vendor-breach/index.xml" rel="self" type="application/rss+xml"/><item><title>ReliaQuest confirms failed ShinyHunters social-engineering attack</title><link>https://curasec.metacog.co.kr/insights/2026-08-25-reliaquest-confirms-failed-data-theft-attack-after-shinyhunt/</link><pubDate>Tue, 25 Aug 2026 11:39:54 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-25-reliaquest-confirms-failed-data-theft-attack-after-shinyhunt/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> ShinyHunters used internal-impersonation social engineering to target a security vendor employee; no software vulnerability involved, but worth reviewing your own internal verification procedures for sensitive access requests from apparent colleagues.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Confirms ShinyHunters is actively targeting security vendor employees via insider-impersonation lures; no IOCs or ATT&amp;amp;CK-mappable TTPs are published here, so no immediate detection work is actionable.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If ReliaQuest is in your vendor stack, formally confirm with them that no client data was at risk during this incident and request a written attestation; the failed outcome reduces urgency but does not eliminate the vendor-risk checkbox.&lt;/li>
&lt;/ul></description></item><item><title>LexisNexis takes Diligence, Metabase API, Newsdesk offline after suspicious server activity</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-lexisnexis-shuts-down-services-after-suspicious-activity-on/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-lexisnexis-shuts-down-services-after-suspicious-activity-on/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, TTPs, or detection surface published; monitor for follow-up reporting that may yield hunt queries or indicators.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> LexisNexis is a common enterprise vendor for due diligence and data enrichment — confirm this week whether your organization uses Diligence, Metabase API, or Newsdesk, and formally request a vendor incident report and data-exposure assessment.&lt;/li>
&lt;/ul></description></item><item><title>OpenAI and Hugging Face disclose model-evaluation security incident</title><link>https://curasec.metacog.co.kr/insights/2026-07-22-openai-and-hugging-face-address-security-incident-during-mod/</link><pubDate>Wed, 22 Jul 2026 12:46:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-22-openai-and-hugging-face-address-security-incident-during-mod/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your pipelines integrate with Hugging Face or consume OpenAI APIs for model evaluation, audit those integration points and review access logs covering the incident window; watch for follow-on disclosure of specific technical details before determining whether credential rotation or config changes are needed.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs or TTPs are available yet, but organizations using either platform should pull API access logs for the incident period and queue a hunt once the full disclosure provides behavioral indicators; monitor OpenAI&amp;rsquo;s and Hugging Face&amp;rsquo;s incident update pages for actionable details.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirm whether your organization uses OpenAI or Hugging Face for model evaluation, request a vendor attestation or incident report this week, and brief leadership proactively — the high public profile of this disclosure means board or customer questions are likely before a full technical picture emerges.&lt;/li>
&lt;/ul></description></item><item><title>Abbott Laboratories probes two cyber incidents amid extortion claims</title><link>https://curasec.metacog.co.kr/insights/2026-07-18-abbott-probes-two-cyber-incidents-amid-extortion-claims/</link><pubDate>Sat, 18 Jul 2026 11:51:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-18-abbott-probes-two-cyber-incidents-amid-extortion-claims/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Active investigation at a major healthcare vendor with confirmed unauthorized access and extortion claims, but no IOCs, TTPs, or ATT&amp;amp;CK-mappable behaviors have been published yet — nothing actionable to hunt or detect on today.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Abbott confirmed unauthorized access to Exact Sciences legacy systems in its Cancer Diagnostics division and is probing a separate LabCentral portal breach with data-theft claims; if your organization uses Abbott lab or diagnostics services, confirm your exposure this week and request a written attestation of incident scope from your account contact.&lt;/li>
&lt;/ul></description></item></channel></rss>