Governance
Risk strategy, policy, and executive oversight that ties every other pillar together.
GSD strives to always stay current on the latest attacks and vulnerabilities. These monthly briefings on some of the most prominent threats demonstrate how each maps to GSD's Six-Pillar Security Framework.
Risk strategy, policy, and executive oversight that ties every other pillar together.
Access control, encryption, and identity management that keep sensitive data restricted to authorized users.
Patch management, secure development, and change control that keep systems and data trustworthy and unmodified.
Backups, disaster recovery, and redundancy that keep critical systems operational through disruption.
Logging, monitoring, and audit trails that make every action attributable and forensically reviewable.
Incident response, vulnerability management, and testing that determine how fast you recover from an attack.
The South Korean streaming service confirmed on June 3 that personal information had been leaked due to unauthorized external access, exposing IDs, names, birthdates, phone numbers, emails, passwords, and refund account numbers. (Confidentiality)
The dental benefits administrator confirmed a breach after ShinyHunters published a 234GB data archive, following a May "pay or leak" campaign. Have I Been Pwned verified 2.6 million exposed email addresses. (Resilience)
Attackers used compromised legacy credentials to access Klue's integration environment and obtain OAuth tokens, enabling unauthorized access to Salesforce CRM data across customer environments including HackerOne, Gong, and Tanium. (Confidentiality)
The county confirmed a cybersecurity incident after a network outage disrupted phone, internet, and online payment systems beginning June 11. (Availability)
A misconfigured Elasticsearch cluster belonging to a threat intelligence platform publicly exposed over 24 billion records of usernames, emails, plaintext passwords, and login URLs, largely sourced from infostealer malware logs. (Confidentiality)
A cyberattack on the department's license system vendor exposed data belonging to over 3 million customers, including driver's license numbers, passport numbers, and residential addresses. (Governance)
The World Leaks ransomware group published more than 200,000 alleged company files (about 630GB), reportedly including Apple and Tesla references, iPhone component records, supplier details, and employee passport scans; India's CERT-In opened an investigation. (Resilience)
Among confirmed corporate breaches in June, the Japanese telecom's exposure of roughly 14.2 million accounts was the largest single confirmed corporate breach of the month. (Confidentiality)
The cybersecurity firm disclosed a breach on May 4 after unauthorized access to its source code repository; RansomHouse claimed responsibility, though Trellix found no evidence of exploitation. (Confidentiality)
The education technology company was breached twice within two weeks by ShinyHunters, the largest education-sector breach on record. Despite paying ransom, 275 million students and staff had data copied. (Resilience)
Foxconn acknowledged a cyberattack on its North American factories on May 12 after the Nitrogen ransomware group claimed to have stolen 8 terabytes of sensitive data. (Resilience)
The Minnesota public school district, with four high schools and over 3,000 students, was hit by a ransomware attack forcing a temporary shutdown; the scope of compromised data is still under investigation. (Resilience)
One of the largest kidney care providers in the US reported a ransomware attack that hit its internal operations and primarily affected its laboratory system. (Availability)
A compromised employee device led to a breach of roughly 3,800 internal repositories. Unlike typical extortion plays, the group intended to sell the data to a single buyer. (Confidentiality)
Vietnam's National Cybersecurity Center detected malicious activity in two government agencies' systems between May 21 and 22, with the nature and impact still under investigation. (Accountability)
The convenience store chain suffered a breach of franchisee application documents; ShinyHunters claimed over 600,000 exposed records, and the company has since faced a lawsuit. (Confidentiality)
Investigators found the intrusion had been planned for at least six months before detection, resulting in a loss of over $280 million in user assets: a detection failure. (Accountability)
A LiteLLM supply-chain incident at the AI startup, which works with Meta, Anthropic, and OpenAI, reportedly exposed four terabytes of data. (Governance)
A social engineering attack against a single employee account led to roughly 6 million individuals notified, with independent analysis identifying up to 7.5 million affected loyalty accounts. (Confidentiality)
A compromised FBI surveillance system potentially exposed active criminal probes and surveillance targets, with early attribution pointing to Chinese state-affiliated actors, echoing the 2024 Salt Typhoon telecom hack. (Confidentiality)
Compromise of Context.ai, a third-party tool used by Vercel, reportedly exposed access keys, source code, API keys, credentials, and database data. (Governance)
Admin accounts without MFA were compromised at the Mexico-based security firm, which serves major clients including Starbucks and Whirlpool. (Confidentiality)
Unauthorized access to corporate IT systems triggered an SEC Form 8-K filing; Medtronic stated no products, manufacturing, or patient safety were affected. ShinyHunters was identified as the actor. (Governance)
A ransomware attack on April 27 exfiltrated a limited amount of personal data from the waste management company's Sandrigo facility, affecting residents across multiple municipalities. (Resilience)