Tag

#third-party risk

19 stories taggedthird-party risk.

Illustration: a dimly lit industrial control room at a water treatment plant
Policy & Regulation

FBI and CISA warn critical infrastructure operators to rein in third-party ICS integrators

A new joint fact sheet asks water, power and manufacturing operators to lock down the outside engineers who quietly run their control systems.

4 min read
A Google Workspace administration console showing connected third-party applications with persistent access permissions, highlighting outdated integrations that
Cloud Security

The Google Workspace apps you forgot about are still reading your email

Third-party integrations left connected to Workspace tenants keep their access for years, and attackers are quietly walking through the door they left open.

3 min read
A Chicago downtown skyline framed through office glass with a laptop in foreground showing healthcare data columns, overlaid with digital lock symbols breaking
Breaches

Veradigm Confirms Patient Data Theft After Vendor Credentials Stolen; Ransomware Crew Claims 3.5 Million Records

The Chicago health-tech firm told the SEC that attackers used a vendor's login to a customer-service API. The Gentlemen ransomware group says it grabbed millions of patient records.

4 min read
A corporate security operations center with a CISO or security leader reviewing AI risk assessment reports on a large dashboard, team members in background, con
AI Security

Most CISOs Are Not Confident About AI Security. Here Is What Separates the Ones Who Are.

A new survey finds only 41% of chief information security officers feel optimistic about managing AI risks over the next two years. The gap between the hopeful and the worried comes down less to technology and more to whether the boss actually listens.

3 min read
A sprawling pharmaceutical warehouse or distribution center at night, with security lights illuminating rows of shelving units and inventory, a single door or a
Breaches

McKesson Confirms Break-In After Hackers Claim 284 Million Patient Records Stolen

The US pharmaceutical distribution giant says intruders reached third-party apps holding limited data. The ShinyHunters gang claims a haul far larger than McKesson admits.

4 min read
A hotel front desk area with a computer system showing a data breach alert, with guest information forms and identity documents visible on the counter
Breaches

Quest Apartment Hotels Investigating Customer Data Breach Tied to Third-Party Provider

Personal details of Quest guests, including names, email addresses and some dates of birth, were exposed after criminals broke into a database through a flaw in an outside supplier's system.

3 min read
A hospital building exterior with a data breach notification banner, showing HR and personnel records locked behind security barriers while patient files remain
Breaches

SickKids Says Third-Party Software Flaw Exposed Employee and Applicant Data

Toronto's largest paediatric hospital confirms a breach affecting HR records. Patient files were not touched.

3 min read
Government office building in Edinburgh with survey equipment cases and hard drives stacked near an unsecured loading area, clipboard with employee rosters visi
Breaches

A Survey Company May Have Leaked Scottish Government Workers' Personal Details

A contractor hired to run a government training exercise lost staff data from Scotland's public prosecution service. The real worry: dozens of other agencies probably handed over the same information.

4 min read
A data center with servers being physically disconnected from network cables by technicians in gloves, server racks powered down in sequence, documentation and
Breaches

LexisNexis Pulls Three Services Offline After Vendor Server Break-In

The data analytics giant disconnected Nexis Diligence, Metabase API and Newsdesk after spotting suspicious activity on a third party's servers, and is rebuilding the systems from scratch.

4 min read
A conference or seminar setting with an experienced speaker at a podium, with compliance checkboxes and regulatory documents visible on large displays behind th
Policy & Regulation

Compliance Alone Won't Protect Your Organisation: Edna Conway on the Real Future of Cyber Risk

A cybersecurity veteran with four decades in the field says ticking regulatory boxes is not the same as being secure. Here is what she means and why it matters.

3 min read
A business meeting room where software vendors present to executives while security personnel stand unheard in the background, with a timeline showing security
Policy & Regulation

Your Company's Vendor Problem Starts Before Anyone Calls Security

When businesses pick software first and ask security questions second, they hand criminals a head start. Here is why fixing that order matters, and what a grown-up process actually looks like.

4 min read
A network architecture diagram showing a cloud platform with a forgotten service account highlighted, then a second breach arrow showing stolen data being stole
Cloud Security

The Hackers Got Hacked: Inside the Klue Breach and What It Means for Every Business Using Cloud Software

A forgotten service account let criminals walk into a competitive-intelligence platform. Then a second criminal group stole the stolen data. The whole chain shows exactly how cloud software trust goes wrong.

4 min read
A banking website interface displayed on a monitor with tracking pixels and data transmission flows visualized as glowing lines sending information toward adver
Policy & Regulation

Your Bank May Be Sending Your Loan Details to TikTok Without Knowing It

New research finds that tracking tools baked into banking websites are quietly forwarding customers' personal and financial data to advertising platforms, sometimes before anyone clicks 'accept cookies'.

4 min read
A corporate office environment with multiple computer workstations, server room visible in the background, and visual indicators of data being extracted or tran
Breaches

Ernst & Young Client Data Stolen in Third-Party Platform Breach

Names, Social Security numbers, and card details belonging to Ernst & Young clients were taken after criminals broke into a third-party software platform the firm used to manage data.

3 min read
Illustration: A modern glass office tower at dusk with warm interior lights on upper floors
Breaches

Ernst & Young Tells Clients Their Tax Data Was Taken From a Support Ticket System

The Big Four firm says an outside party pulled documents from a third-party helpdesk platform between late March and mid-April. Affected clients get 24 months of identity monitoring through Experian.

3 min read
© 2026 Threat Vectr