Skip to content

Cyber Risk Assessment

Weekly Cybersecurity Intelligence Report: Cyber Threats and Breaches 17 Aug to 23 Aug 2026

The week of 17 to 23 August 2026 was defined by stolen and sprayed credentials doing the work that malware used to do. France’s tax authority DGFiP confirmed that attackers used compromised access points to extract data on 678,000 individuals. A threat actor calling themselves TheHatman put 3.64 million employee records from Fortune 500 Azure… Read More »Weekly Cybersecurity Intelligence Report: Cyber Threats and Breaches 17 Aug to 23 Aug 2026

Weekly Cybersecurity Intelligence Report: Cyber Threats and Breaches 10 Aug to 16 Aug 2026

The week of 10 to 16 August 2026 was defined by third-party access: every major incident reached its victims through a system the victims did not own. A cyberattack on Ceva Logistics exposed customer data across at least six downstream brands including Bol and Valve’s Steam hardware business. Trezor warned nearly 14,000 customers after its… Read More »Weekly Cybersecurity Intelligence Report: Cyber Threats and Breaches 10 Aug to 16 Aug 2026

Weekly Cybersecurity Intelligence Report: Cyber Threats and Breaches – 13 Jul to 19 Jul 2026

The week of 13 to 19 July 2026 was defined by operational disruption. A ransomware attack shut down all US production at Coca-Cola’s Fairlife dairy subsidiary, attackers stole client tax documents from EY through a third-party support platform, and a previously undocumented threat actor exploited SonicWall VPN zero-days for weeks before public disclosure. One incident… Read More »Weekly Cybersecurity Intelligence Report: Cyber Threats and Breaches – 13 Jul to 19 Jul 2026

UNC3886 breach of Singapore’s four largest telcos

Date of Incident: 2024 Overview: In 2024, the APT group UNC3886 breached Singapore’s four major telecom companies—Singtel, StarHub, M1 Limited, and TPG Telecom. The attackers accessed some critical systems but failed to cause service disruptions or access sensitive customer data. Techniques used included exploiting public-facing applications and leveraging valid accounts, with attempts at lateral movement… Read More »UNC3886 breach of Singapore’s four largest telcos

Autonomous Penetration Testing Is Growing Up

For the last few years, autonomous penetration testing has been defined by proof of possibility that machines can plan and execute attacks without human operators. That question has been answered. The real question today is far more important: Can autonomous penetration testing operate credibly inside real enterprise environments continuously, safely, and at scale? At FireCompass,… Read More »Autonomous Penetration Testing Is Growing Up