Supply Chain Cyber Risk in 2026: How to Assess and Continuously Monitor Third-Party Exposure
How to assess and continuously monitor third-party cyber risk in 2026. Real attack paths, not vendor questionnaires. Practical steps for security teams.
Vendor, fourth-party and software supply chain exposure.
How to assess and continuously monitor third-party cyber risk in 2026. Real attack paths, not vendor questionnaires. Practical steps for security teams.
Date of Incident: September 20, 2023 Overview: In a data breach disclosed on October 4, 2025, Discord experienced a security incident via a third-party customer service provider on September 20, 2023. The attack exposed partial payment data and personally identifiable information, including names, IDs, and email addresses of users who interacted with Discord’s support teams.… Read More »Discord Data Breach via Third-Party Customer Service Provider
Date of Incident: 2024 Overview: In 2024, Harrods experienced a data breach due to a third-party supplier vulnerability, affecting 430,000 customer records with names, contact details, and marketing information exposed. The breach, which became public in September 2025, did not compromise passwords, payment details, or order histories. Attackers used exploitation techniques like SQL Injection to… Read More »Harrods third-party supplier breach
On July 7, 2025, Ingram Micro, one of the world’s largest IT distribution companies, suffered a major ransomware attack, leading to global service disruptions. The company was forced to disconnect affected systems and halt operations temporarily to contain the breach. Services were restored by July 10, 2025, but the ripple effects impacted partners and customers across the supply chain.… Read More »Ingram Micro Ransomware Attack: Strengthening Supply Chain Risk Assessment
For the last week, Firecompass Research Team have focused on 10 brand-new vulnerabilities which are Critical in severity. They are published by the global security research community. Ransomware groups and APT target many of these vulnerabilities to get Initial Access. All the vulnerabilities have Proof of Concepts (PoC) exploit code publicly available on GitHub. That… Read More »New & Critical CVEs Exploited In Wild – 3CX Supply Chain, IBM Aspera Faspex, Forta GoAnywhere, Apache Spark UI & More