CareCloud's breach now lists 3,756,469 people affected.
The interesting TPRM issue isn't just the size of the breach. It's the concentration.
One of six EHR environments held data tied to millions of people.
If a critical supplier holds that much of your data, its environment-level concentration should be part of your risk assessment.
#TPRM #ThirdPartyRisk
An MSP can become a software supply-chain concentration point.
If the same partner chooses and operates packages, libraries, and tooling across dozens of customers, one bad dependency can become everyone's problem.
Supplier assurance should cover SBOMs, component inventories, and dependency monitoring after go-live.
#TPRM #SupplyChainSecurity
Boston Scientific’s cyber incident disrupted manufacturing, order processing, and shipping.
That creates a TPRM question worth asking: if a critical supplier went offline tomorrow, how quickly would your organization feel it?
Security risk and operational dependency aren't the same thing.
#TPRM #ThirdPartyRisk
Ransomware activity reached 894 reported cases in July, a 22% increase from June, according to NCC Group.
It was the highest monthly total recorded in 2026.
The bigger concern is where the attacks are landing.
Industrials accounted for 28% of reported attacks, while North America and Europe made up 70% combined.
Industrial organizations often sit inside complex supplier networks, with vendors, contractors, and technology providers connected to critical operations.
And attackers are becoming more automated.
More speed and scale make visibility across those third-party connections increasingly important.
894 incidents in one month is a lot of noise.
Knowing which vendors could actually affect your business helps turn that noise into something actionable.
#Ransomware #ThirdPartyRisk #CyberSecurity #IndustrialSecurity #SupplyChainSecurity #CyberAttack #CyberResilience #RiskManagement
Berlin has confirmed data was stolen in the Rhysida ransomware attack.
Investigators identified a five-day exfiltration window from August 7 to August 12.
Rhysida claims 5.79 TB was stolen, including data tied to 12,076 people and roughly 46,500 supplier and third-party contracts. Berlin has not independently verified those figures.
But the third-party angle matters.
When an organization holds data on thousands of suppliers, understanding what was exposed becomes much harder without clear visibility into those relationships.
Ransomware isn't just an access problem once data leaves the environment.
It's a visibility problem.
#Ransomware #ThirdPartyRisk #CyberSecurity #DataSecurity #SupplyChainSecurity #DataPrivacy #RiskManagement #PublicSector
Your AI agent may trust your vendors more than your security team does.
Researchers scanned 6,214 live domains and found 120 pointing AI agents toward unclaimed software packages or domains.
They registered some as a proof of concept.
Within an hour, they observed activity from a Fortune 500 company.
The bigger problem?
AI agents increasingly rely on third-party documentation, SDKs, repositories, APIs, and software packages.
If an agent trusts the source, it may also trust what that source tells it to install or execute.
The trusted vendor relationship can become the attack path.
#AIAgents #CyberSecurity #SoftwareSupplyChain #SupplyChainSecurity #AIGovernance #ThirdPartyRisk #SoftwareSecurity
A small technology supplier can create a very large critical infrastructure problem.
Micro-Comm, a Kansas manufacturer of programmable logic controllers used in critical infrastructure, was reportedly hit by the Barracuda ransomware group.
Nearly 850,000 files.
Approximately 644 GB of data.
The bigger lesson?
Critical infrastructure does not exist in isolation.
A supplier doesn't need to operate a water treatment plant to create risk for one. It may simply provide the technology that controls it.
The security perimeter doesn't end at the utility's network.
It extends into the companies and technology supporting it.
#CriticalInfrastructure #ThirdPartyRisk #CyberSecurity #SupplyChainSecurity #OTSecurity #WaterSecurity #Ransomware #CyberResilience
Preferred Parking Service (Charlotte) notified ~73k people after an unauthorized actor accessed its database on 7-8 June. The actor took names and credit/debit card data. Investigation closed 30 July. Notices went out mid-August.
Parking operators process card data for monthly parkers, event attendees, and daily customers across dozens of sites. When supplier criticality is defined mainly around core ICT systems, these providers can sit lower in the tiering model than their actual payment-card exposure justifies.
The data exposure is real even if the vendor is not a traditional technology supplier.
#TPRM #CyberSecurity #ThirdPartyRisk #carparking
73% of ransomware victims in North America and Europe were mid-market companies.
Black Kite analyzed 13,336 ransomware incidents from January 2023 to June 2026.
The mid-market share barely changed as attacks increased.
More than half of those victims generated less than $50 million annually.
That matters for third-party risk.
Mid-market companies are often suppliers to larger organizations while also depending on dozens or hundreds of vendors themselves.
They can be attractive ransomware targets and a source of downstream risk.
You don't need to be a Fortune 500 company to become a high-value target.
And you don't need to be breached directly to create risk for the organizations that depend on you.
#Ransomware #ThirdPartyRisk #CyberSecurity #SupplyChainSecurity #MidMarket #VendorRisk #CyberResilience #TPRM
3.8 million people. One healthcare vendor. One compromised cloud environment.
CareCloud is notifying nearly 3.8 million people that their personal and health information may have been stolen during a March 2026 incident.
The reported exposure includes:
Social Security numbers.
Government IDs.
Financial information.
Medical information.
Health insurance data.
The bigger issue is concentration.
Many affected people may never have heard of CareCloud. Their data was there because a healthcare provider relied on the vendor.
That is the third-party risk problem.
A vendor compromise can become a patient-data incident without ever touching the healthcare organization's own network.
Healthcare TPRM needs to understand not just whether vendors are secure, but what data they hold, how much is concentrated there, and how quickly an incident would be detected.
#HealthcareCybersecurity #ThirdPartyRisk #TPRM #HealthTech #DataBreach #CloudSecurity #HealthcareIT #CyberResilience
A supplier breach can become a customer-facing incident fast.
Pokémon Center is notifying customers in the UK and Germany after hackers reportedly compromised CEVA Logistics, the third party handling fulfillment and shipping.
The reported impact goes beyond data exposure.
8 European warehouses were disrupted, causing shipping delays and reportedly canceled orders.
The lesson?
A vendor can be responsible for the breach.
The business still owns the customer impact and response.
Third-party risk is about more than security questionnaires.
It is understanding what vendors can access, what operations depend on them, and what happens when they go down.
#ThirdPartyRisk #SupplyChainSecurity #CyberSecurity #VendorRisk #OperationalResilience #CyberResilience #DataSecurity
Nearly 50 companies. One shared software dependency.
Cl0p claims to have compromised companies including Shell and Philips through a campaign linked to a vulnerability in PTC Windchill.
The reported data:
89 GB from Shell.
13.5 GB from Philips.
The bigger lesson is the dependency.
One software platform can sit inside dozens of organizations. A single vulnerability can turn into a much larger supply-chain problem.
That means third-party risk needs to look beyond the vendor.
What software does it depend on?
How widely is that dependency used?
What happens if it is compromised?
Those connections are part of your risk profile too.
#ThirdPartyRisk #SupplyChainSecurity #CyberSecurity #SoftwareSecurity #Ransomware #VendorRisk #CyberResilience
40 minutes was enough.
Malicious LiteLLM packages were live on PyPI for roughly 40 minutes after a Trivy compromise in March.
Researchers linked the incident to potential credential exposure across 2,500+ organizations and hundreds of thousands of CI/CD pipelines.
Cloud keys. Repository tokens. Kubernetes secrets. AI provider credentials.
An annual vendor questionnaire would never catch something like this.
Neither would a spreadsheet.
Third-party risk now has to account for software components and dependencies that can move through an organization at machine speed.
The real question:
Are those dependencies part of continuous monitoring and rapid response, or do they stay outside the risk picture until the post-mortem?
#Cybersecurity #OpenSourceSecurity #SoftwareSupplyChain #DevSecOps #AISecurity #CloudSecurity #SupplyChainSecurity #ThirdPartyRiskManagement #TPSaaS
Europe’s healthcare cyber risk is increasingly a supplier problem.
Black Book Research’s 2026 Europe-30 index places Poland, the UK, France, and Germany in the critical-risk tier, with 9 more countries rated very high risk.
The bigger issue is dependency.
A compromised supplier, identity service, EHR platform, cloud provider, or MSP can affect multiple healthcare organizations at once.
One incident involving Unimed was linked to more than 135,000 affected people across connected institutions.
A vendor can pass an annual security assessment and still represent a major operational dependency.
For healthcare, TPRM needs to consider more than security controls.
It needs to account for clinical dependency, concentration risk, and recovery.
The supplier relationship is part of the attack surface.
#HealthcareCybersecurity #ThirdPartyRisk #TPRM #HealthcareIT #SupplyChainSecurity #CyberResilience #HealthTech #CyberSecurity
Retelit, an Italian telecom and cloud provider, was reportedly hit by Qilin ransomware.
The reported scale is huge:
300 GB of data.
270,000 files.
65,000 customers.
35+ data centers.
47,000 km of fiber.
But the bigger concern is who depends on Retelit.
Its customers reportedly include Leonardo, digital identity providers, and 193 public administrations.
A supplier breach can quickly become an ecosystem risk event.
That’s why TPRM needs to ask more than:
“Do they have a SOC 2?”
What does the supplier connect to?
What can they access?
How critical are they?
What happens if they’re compromised?
You can’t prevent every supplier attack.
But you can understand the dependency before it becomes a liability.
#Ransomware #ThirdPartyRisk #Telecommunications #SupplyChainSecurity #CyberSecurity #CriticalInfrastructure #CyberResilience #VendorRisk
UK manufacturers are facing sustained ransomware pressure.
SonicWall recorded 1.84 million ransomware events across 364 manufacturing sensors between January and May 2026.
But the bigger concern is how attackers are getting in.
Supply chains are becoming a major attack pathway.
Manufacturers rely on vendors for maintenance, software, logistics, and operational support.
Those connections create efficiency.
They also create exposure.
The challenge?
Many organizations understand their own environment.
Far fewer understand the suppliers connected to it.
Your security perimeter now extends beyond your own network.
#CyberSecurity #Manufacturing #Ransomware #ThirdPartyRisk #SupplyChainSecurity #OperationalResilience #VendorRisk
UK manufacturers are facing sustained ransomware pressure.
SonicWall recorded 1.84 million ransomware events across 364 manufacturing sensors between January and May 2026.
But the bigger concern is how attackers are getting in.
Supply chains are becoming a major attack pathway.
Manufacturers rely on vendors for maintenance, software, logistics, and operational support.
Those connections create efficiency.
They also create exposure.
The challenge?
Many organizations understand their own environment.
Far fewer understand the suppliers connected to it.
Your security perimeter now extends beyond your own network.
#CyberSecurity #Manufacturing #Ransomware #ThirdPartyRisk #SupplyChainSecurity #OperationalResilience #VendorRisk
A paused requirement does not mean a paused risk.
The delay of CMMC Phase 2 may change timelines.
It does not change the cybersecurity challenges facing the defence supply chain.
Contractors still rely on networks of suppliers, subcontractors, and service providers handling sensitive information and supporting critical operations.
The question remains: Do organizations have visibility into the security posture of the ecosystem they depend on?
Compliance timelines can shift.
Supply chain risk does not.
https://t.co/gnjLViqEse
#CMMC #DefenseCybersecurity #DefenseIndustry #SupplyChainSecurity #ThirdPartyRisk #NIST #CyberSecurity #OperationalResilience
The EU AI Act is changing how organizations need to manage AI vendors.
The biggest shift?
AI suppliers are becoming a third-party risk issue.
Organizations now need to think beyond AI adoption and consider:
• Vendor risk tiers
• AI-specific due diligence
• Contract obligations
• Evidence requirements
• Continuous monitoring
The challenge is that AI does not fit neatly into traditional vendor categories.
AI vendors, embedded AI features, and autonomous agents can introduce new data, security, and operational risks long after procurement.
Annual questionnaires and point-in-time reviews will not be enough.
AI suppliers require lifecycle-based TPRM:
Onboarding → Continuous oversight → Remediation → Offboarding
https://t.co/LpXXhjje9I
#EUAIAct #AICompliance #ThirdPartyRisk #TPRM #AIGovernance #VendorRisk #CyberSecurity
Third-party risk management has outgrown the security team.
Business growth now depends on suppliers, cloud platforms, technology partners, and outsourced services.
That makes third-party risk a business issue, not just a cybersecurity one.
As organizations become more connected, the resilience of the vendor ecosystem becomes just as important as protecting internal systems.
The conversation is no longer just about reducing risk.
It is about enabling the business to grow with confidence.
https://t.co/rqYYG6TFXz
#ThirdPartyRisk #BusinessResilience #OperationalResilience #CyberSecurity #EnterpriseRisk #VendorRisk #DigitalTransformation