Supplier Shield

Supplier Shield We help organizations secure the integrity of their supply chain through in-depth assessments, backed up by our certified auditors' analysis.

A phishing attack at Xsolis, a US healthcare vendor that many hospitals and insurers use to review whether care is cover...
06/08/2026

A phishing attack at Xsolis, a US healthcare vendor that many hospitals and insurers use to review whether care is covered, exposed the data of about 1.4 million people. Patients at Mayo Clinic, UW Medicine and VHC Health were among those affected, because one vendor held records from many providers at once.

https://zurl.co/NF7nd

A phishing attack at Xsolis, a healthcare vendor used by many US hospitals, exposed about 1.4 million people's data, reaching Mayo Clinic, UW Medicine and VHC Health.

Amgen disclosed in a filing with the US Securities and Exchange Commission that attackers stole patient protected health...
05/08/2026

Amgen disclosed in a filing with the US Securities and Exchange Commission that attackers stole patient protected health information and proprietary company data from cloud systems operated by third-party service providers, not from Amgen's own network. The company detected unauthorised activity in July 2026 and concluded on 29 July 2026 that the incident was material, based on the volume of records involved and the sensitivity of the data. Amgen says it activated its incident response plan, contained the activity and engaged outside forensic investigators, and reports no disruption to its products, manufacturing, financial reporting or supply of medicines.

Several details are unconfirmed: Amgen has not named the cloud providers, explained how the systems were accessed, given a number of affected people, or attributed the attack. The third-party risk pattern is supplier cloud exposure: regulated data held in an external provider's systems can be taken without any attacker touching the company's own network, yet the breach notification, regulatory exposure and reputational cost stay with the data owner.
https://zurl.co/RaQRT

Amgen told the SEC that patient health data and proprietary information were stolen from third-party cloud systems, not its own network. What it means for supplier cloud risk.

Which companies does the software economy actually run on? We read the public GDPR Article 28 sub-processor disclosures ...
16/07/2026

Which companies does the software economy actually run on? We read the public GDPR Article 28 sub-processor disclosures of 163 widely used B2B SaaS vendors and canonicalised who each one depends on. The finding: 92% run on Amazon Web Services and close to 100% depend on at least one of just three companies (AWS, Microsoft Azure, or Google Cloud), so a single incident at one provider would reach almost every tool at once. A second finding emerged during collection: roughly four in ten vendors no longer publish a readable, open list, moving disclosures behind trust portals and NDAs even as DORA and NIS2 demand more supply-chain transparency.

https://zurl.co/6Kl9e

New research mapping 163 SaaS vendors' sub-processors: 92% run on AWS, ~100% on a top-three cloud, and disclosures are going dark. The 2026 Fourth-Party Map.

SonicWall confirmed two actively exploited SMA 1000 zero-days (CVE-2026-15409, CVE-2026-15410). Why a remote-access appl...
16/07/2026

SonicWall confirmed two actively exploited SMA 1000 zero-days (CVE-2026-15409, CVE-2026-15410). Why a remote-access appliance is a third-party concentration risk
https://zurl.co/E7Tgc

SonicWall confirmed two actively exploited SMA 1000 zero-days (CVE-2026-15409, CVE-2026-15410). Why a remote-access appliance is a third-party concentration risk.

An attacker hijacked Jscrambler's npm package with a stolen publishing credential and shipped an infostealer to develope...
15/07/2026

An attacker hijacked Jscrambler's npm package with a stolen publishing credential and shipped an infostealer to developers. Why a trusted dependency is a third-party risk. https://zurl.co/4vUC0

An attacker hijacked Jscrambler's npm package with a stolen publishing credential and shipped an infostealer to developers. Why a trusted dependency is a third-party risk.

Lidl's online shop breach started at an external IT service provider, exposing customer data across Germany, Belgium and...
15/07/2026

Lidl's online shop breach started at an external IT service provider, exposing customer data across Germany, Belgium and the Netherlands. What it means for GDPR processor risk.
https://zurl.co/ldvio

Lidl's online shop breach started at an external IT service provider, exposing customer data across Germany, Belgium and the Netherlands. What it means for GDPR processor risk.

Adresse

Rue De La Gare 39
Morges
1110

Benachrichtigungen

Lassen Sie sich von uns eine E-Mail senden und seien Sie der erste der Neuigkeiten und Aktionen von Supplier Shield erfährt. Ihre E-Mail-Adresse wird nicht für andere Zwecke verwendet und Sie können sich jederzeit abmelden.

Service Kontaktieren

Nachricht an Supplier Shield senden:

Verknüpfungen

Teilen