HireACISO

LexisNexis pulled products offline over a third-party vendor incident

August 11, 2026. From issue 1 of The Compliance Brief, 2 stories for founders and executives who own security.

Last reviewed 2026-08-11Written by Jacob Masse, TrazTech Inc.

Issue 1 of The Compliance Brief went to subscribers on August 11, 2026. 2 of its 5 stories bear on breaches, incidents and security leadership, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: BleepingComputer

LexisNexis took several services offline, including Diligence and the Metabase API, in response to unusual activity on servers hosted and managed by a third-party vendor it has not named. The company treated the shutdown as part of its incident response.

Our take, in short

Taking the service down was the right call, and it is also the version of vendor risk that most SaaS companies have never modelled. Your subprocessor list probably names the screening or data provider, and almost certainly says nothing about who runs their infrastructure, so an outage two layers out becomes your degraded onboarding flow and your customer notification.

Read the full take on traztech.ca

Gunra ransomware is getting in through firewalls, per a joint advisory

Source: The Hacker News

US and South Korean agencies issued a joint advisory on Gunra, a ransomware-as-a-service operation that has been breaching organizations by exploiting vulnerabilities in Fortinet and Schneider Electric products. Named targets span critical infrastructure, healthcare, financial services and government.

Our take, in short

Nothing in this advisory is novel, which is the uncomfortable part. Internet-facing appliances remain the cheapest way in, and most companies I test have a documented patch SLA for servers and an informal one for the firewall and the VPN concentrator.

Read the full take on traztech.ca

Also in issue 1

Outside breaches, incidents and security leadership, but in the same email:

All issues on HireACISO Newer: issue 3