Skip to content

Third Party Risk Management

Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 19 Aug – 25 Aug, 2025

The past week has witnessed a devastating cascade of major cybersecurity breaches affecting over 6.8 million individuals globally, with sophisticated threat actors targeting critical infrastructure, healthcare systems, and financial services. Seven significant incidents have been identified, ranging from advanced Salesforce-targeting social engineering campaigns to destructive ransomware operations encrypting healthcare data. The attacks demonstrate an alarming… Read More »Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 19 Aug – 25 Aug, 2025

Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 11 Aug – 18 Aug, 2025

The week of August 11-18, 2025, witnessed an unprecedented escalation in cybersecurity threats, marking one of the most destructive periods for data security in recent history. This period was dominated by a sophisticated Salesforce-targeting campaign orchestrated by ShinyHunters, compromising over 275 million patient records across healthcare organizations, and multiple high-profile breaches affecting financial and HR… Read More »Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 11 Aug – 18 Aug, 2025

Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 4 Aug – 11 Aug, 2025

The week of August 4-11, 2025 witnessed a significant escalation in cyber threat activity, marked by sophisticated supply chain attacks, zero-day exploitations, and critical infrastructure targeting. Key developments include massive data breaches affecting telecommunications providers, airlines, and financial institutions, alongside emergency government directives addressing critical vulnerabilities in Microsoft Exchange and SharePoint systems. Notable incidents include… Read More »Weekly Cybersecurity Intelligence Report Cyber Threats & Breaches 4 Aug – 11 Aug, 2025

Weekly Report: New Hacking Techniques and Critical CVEs 28 July – 4 Aug , 2025

From 28 July to 4 August 2025, threat actors leveraged novel AI-assisted malware, zero-day chains against on-prem SharePoint, critical command-injection in CI/CD pipelines, and advanced social-engineering playbooks. Fourteen CVEs reached Critical severity, including two actively exploited zero-days. Dark-web chatter intensified around Medusa and BlackSuit takedown fallout, with ransomware affiliates trading victim data and custom tooling… Read More »Weekly Report: New Hacking Techniques and Critical CVEs 28 July – 4 Aug , 2025

CoinDCX Cryptocurrency Exchange Breach

Overview: Indian crypto exchange CoinDCX was breached, with attackers stealing wallet credentials and transaction data, causing $1.2M in losses. Technical Details: Attack Vector: Exploited CVE-2025-20281 (Cisco ISE injection vulnerability, CVSS 10.0) in a third-party payment gateway’s API endpoint (/admin/XXX) integrated with CoinDCX. Exploitation: Attackers sent crafted POST requests (Content-Type: application/json) with malicious SQL payloads (‘… Read More »CoinDCX Cryptocurrency Exchange Breach