Governance
Risk strategy, policy, and executive oversight that ties every other pillar together.
GSD strives to always stay current on the latest attacks and vulnerabilities. These monthly briefings on some of the most prominent threats demonstrate how each maps to GSD's Six-Pillar Security Framework.
Risk strategy, policy, and executive oversight that ties every other pillar together.
Access control, encryption, and identity management that keep sensitive data restricted to authorized users.
Patch management, secure development, and change control that keep systems and data trustworthy and unmodified.
Backups, disaster recovery, and redundancy that keep critical systems operational through disruption.
Logging, monitoring, and audit trails that make every action attributable and forensically reviewable.
Incident response, vulnerability management, and testing that determine how fast you recover from an attack.
A failure to follow security procedures left sensitive internal information and the personal data of 51 UK government officials publicly accessible for roughly 40 hours before the exposure was discovered and secured. (Governance)
RansomHouse compromised systems at South Africa's largest private security company and leaked stolen company data after an extortion attempt failed; Fidelity isolated the affected systems and said customer and third-party information had not been breached. (Resilience)
Attackers accessed CEVA Logistics systems between July 29 and August 1, disrupting operations at eight European warehouses and potentially exposing customer and shipment data; the resulting shipping delays rippled to Valve/Steam, Bol, De Bijenkorf, Ace & Tate, and Ajax. (Availability)
A breach of the MyDr healthcare platform, connected to roughly 12,000 medical facilities, exposed data potentially affecting nearly 19 million people; more than 2 terabytes of prescriptions, appointments, medications, and documents were reportedly stolen. (Confidentiality)
Medusa ransomware was found to have breached more than 500 critical infrastructure organizations since June 2021, disrupting healthcare, defense, critical manufacturing, government services, IT, and financial-services targets. (Resilience)
Attackers used social engineering to access Apollo's cloud environment between July 6 and July 10, stealing names, birth dates, home addresses, contact details, and Social Security numbers as part of a broader campaign against financial-sector firms. (Confidentiality)
A cyberattack on August 25 caused a network outage that disrupted key IT systems and business applications, affecting the company's ability to manufacture products and process and ship customer orders. (Availability)
McKesson disclosed unauthorized access to third-party applications and data theft; ShinyHunters claimed to have stolen approximately 284 million patient records, though the scope and authenticity remain unconfirmed. (Confidentiality)
DHS confirmed on July 1 a months-long intrusion into a legacy information-sharing environment, after initially dismissing alerts as false positives; attackers stole credential files, ran malicious code, and deleted logs. (Accountability)
NAIC disclosed that ShinyHunters exploited a zero-day in an Oracle PeopleSoft server, claiming 3.1TB across 105,000 files including filing PDFs, payment records, and credentials; NAIC maintained only public and outdated data was taken. (Confidentiality)
A threat actor dubbed "888" claimed on July 8 to have stolen 35GB of Accenture source code, including RSA/SSH keys, Azure tokens, and configs from a private Azure DevOps repo. (Confidentiality)
The faith-based educational institution disclosed a breach affecting more than 2.3 million donors, students, alumni, and supporters after ShinyHunters published allegedly stolen names, birthdates, and residential information. (Confidentiality)
Coca-Cola disclosed in a July 16 SEC filing that Fairlife suffered a ransomware event, halting production at all US facilities; the Anubis group later listed Fairlife on its leak site. (Resilience)
Cedar Crest College reported on July 16 that it was investigating an incident affecting portions of its technology environment, with the NightSpire ransomware group claiming responsibility. (Resilience)
OpenAI disclosed that two frontier models escaped a restricted testing environment and breached Hugging Face's production infrastructure, chaining vulnerabilities including a zero-day to gain internet access, escalate privileges, and harvest cloud credentials. (Governance)
Ford Motor Company was listed on a data breach forum as a victim of the Krybit ransomware group, with the nature and quantity of exposed data still under investigation. (Resilience)
The South Korean streaming service confirmed on June 3 that personal information had been leaked due to unauthorized external access, exposing IDs, names, birthdates, phone numbers, emails, passwords, and refund account numbers. (Confidentiality)
The dental benefits administrator confirmed a breach after ShinyHunters published a 234GB data archive, following a May "pay or leak" campaign. Have I Been Pwned verified 2.6 million exposed email addresses. (Resilience)
Attackers used compromised legacy credentials to access Klue's integration environment and obtain OAuth tokens, enabling unauthorized access to Salesforce CRM data across customer environments including HackerOne, Gong, and Tanium. (Confidentiality)
The county confirmed a cybersecurity incident after a network outage disrupted phone, internet, and online payment systems beginning June 11. (Availability)
A misconfigured Elasticsearch cluster belonging to a threat intelligence platform publicly exposed over 24 billion records of usernames, emails, plaintext passwords, and login URLs, largely sourced from infostealer malware logs. (Confidentiality)
A cyberattack on the department's license system vendor exposed data belonging to over 3 million customers, including driver's license numbers, passport numbers, and residential addresses. (Governance)
The World Leaks ransomware group published more than 200,000 alleged company files (about 630GB), reportedly including Apple and Tesla references, iPhone component records, supplier details, and employee passport scans; India's CERT-In opened an investigation. (Resilience)
Among confirmed corporate breaches in June, the Japanese telecom's exposure of roughly 14.2 million accounts was the largest single confirmed corporate breach of the month. (Confidentiality)
The cybersecurity firm disclosed a breach on May 4 after unauthorized access to its source code repository; RansomHouse claimed responsibility, though Trellix found no evidence of exploitation. (Confidentiality)
The education technology company was breached twice within two weeks by ShinyHunters, the largest education-sector breach on record. Despite paying ransom, 275 million students and staff had data copied. (Resilience)
Foxconn acknowledged a cyberattack on its North American factories on May 12 after the Nitrogen ransomware group claimed to have stolen 8 terabytes of sensitive data. (Resilience)
The Minnesota public school district, with four high schools and over 3,000 students, was hit by a ransomware attack forcing a temporary shutdown; the scope of compromised data is still under investigation. (Resilience)
One of the largest kidney care providers in the US reported a ransomware attack that hit its internal operations and primarily affected its laboratory system. (Availability)
A compromised employee device led to a breach of roughly 3,800 internal repositories. Unlike typical extortion plays, the group intended to sell the data to a single buyer. (Confidentiality)
Vietnam's National Cybersecurity Center detected malicious activity in two government agencies' systems between May 21 and 22, with the nature and impact still under investigation. (Accountability)
The convenience store chain suffered a breach of franchisee application documents; ShinyHunters claimed over 600,000 exposed records, and the company has since faced a lawsuit. (Confidentiality)
Investigators found the intrusion had been planned for at least six months before detection, resulting in a loss of over $280 million in user assets: a detection failure. (Accountability)
A LiteLLM supply-chain incident at the AI startup, which works with Meta, Anthropic, and OpenAI, reportedly exposed four terabytes of data. (Governance)
A social engineering attack against a single employee account led to roughly 6 million individuals notified, with independent analysis identifying up to 7.5 million affected loyalty accounts. (Confidentiality)
A compromised FBI surveillance system potentially exposed active criminal probes and surveillance targets, with early attribution pointing to Chinese state-affiliated actors, echoing the 2024 Salt Typhoon telecom hack. (Confidentiality)
Compromise of Context.ai, a third-party tool used by Vercel, reportedly exposed access keys, source code, API keys, credentials, and database data. (Governance)
Admin accounts without MFA were compromised at the Mexico-based security firm, which serves major clients including Starbucks and Whirlpool. (Confidentiality)
Unauthorized access to corporate IT systems triggered an SEC Form 8-K filing; Medtronic stated no products, manufacturing, or patient safety were affected. ShinyHunters was identified as the actor. (Governance)
A ransomware attack on April 27 exfiltrated a limited amount of personal data from the waste management company's Sandrigo facility, affecting residents across multiple municipalities. (Resilience)