
We’ve expanded the security profile template library to include templates for cloud service providers and core infrastructure providers. These map to the Cloud Security Alliance Cloud Controls Matrix (CCM), UK Cyber Essentials, the Center for Internet Security Critical Security Controls (CIS), and NIST Special Publication 800-53 Revision 5. Vendor Risk users can run AI assessments and gap analysis in Security Profile against these standards when reviewing SaaS, PaaS, IaaS, MSP, and data center vendors. For more information see Control Templates.
Vendor Risk users can now request remediation for evidence risks in Security Profile directly from document citations, without sending a questionnaire. Vendors can share supporting evidence as part of the remediation process, and Vendor Risk users can manually mark risks as remediated based on their evidence and responses.
To help Vendor Risk users more easily surface and manage risk from unknown vendors, we now surface Breach Risk detected products in the Detected tab on the Vendors page. The Detected tab on the Vendors list now shows vendors detected by Breach Risk alongside those detected by User Risk (for Breach Risk and User Risk users respectively), and vendors can be monitored directly from the list.
Breach Risk Threat Monitoring can automatically suppress exposed credential detections for inactive or known-benign accounts, cutting down noise from reposted ULP and combolist data. Organizations can import, as well as manually curate, a list of known inactive accounts so future detections are triaged without manual dismissal.
Breach Risk and Vendor Risk now detect WordPress installations affected by CVE-2026-60137, a SQL injection vulnerability and CVE-2026-63030, a REST API batch-route confusion vulnerability. Chained together they enable unauthenticated remote code execution, and both are listed in CISA’s Known Exploited Vulnerabilities catalog. Fixes are available in WordPress 7.0.2, 6.9.5, and 6.8.6.