"True security begins when you stop assuming you're protected and start proving you're not exposed."
- Zero Tolerance Principle
Coordinated disclosure of five vulnerability classes in Deloitte AI Assist for Customer, affecting six tenants. Three CVEs assigned — CVE-2026-57474 / -57475 / -57476, MEDIUM under the coordinator record — and published in CISA CSAF VA-26-191-01. Coordinated with CERT/CC under VU#487875.
VU#487875 · Published May 18, 2026 · Updated Aug 3, 2026 · PGP-signed, SHA-256 verifiable
READ THE COORDINATED DISCLOSURE
Independent OSINT research and published threat analyses across critical infrastructure, healthcare, cloud, and software supply chains. These are recent breach analyses.
An intrusion into Medtronic corporate IT systems between April 13 and April 19, 2026 exposed the names, dates of birth, Social Security numbers and health information of 3,834,294 device patients. No Medtronic medical device, and no manufacturing or distribution system, was affected.
Itron told the SEC on April 24, 2026 that no unauthorized activity was observed in its customer hosted systems. Seven days later it filed an amendment identifying limited unauthorized access to certain customer-hosted systems.
OCR announced four HIPAA Security Rule settlements on a single day, all turning on the same failure: no accurate and thorough risk analysis. The four actions bring OCR's completed ransomware investigations to 19.
The French agency issuing every passport, ID card and driving licence detected unauthorised access to its portal on April 15, 2026. The Interior Ministry confirmed 11.7 million accounts; an actor using the handle breach3d claimed 19 million.
An employee's OAuth grant to a third-party AI tool gave an attacker the employee's Google Workspace account and, from there, a path into Vercel. Non-sensitive environment variables belonging to a limited subset of customers were enumerated and decrypted.
An attacker impersonated an authorised staff account and exploited a flaw in the ÉduConnect pupil account management service, taking names, identifiers, schools, classes and activation codes for unactivated accounts. The ministry has published no victim count.
Security research operating under zero-trust principles. Never trust, always verify.
Passive external reconnaissance to identify exposed assets, leaked credentials, and misconfigured services before adversaries do.
External attack surface analysis from an adversary's perspective.
Vendor inventory mapping, third-party risk scoring, and supply chain exposure analysis for organizations relying on external data and infrastructure access.
Coordinated vulnerability disclosure with verified remediation. We document, we notify, we follow through.
Post-breach forensic analysis and timeline reconstruction. Understanding the kill chain to prevent recurrence.
Independent open-source intelligence research on cyber threats. We investigate, analyze, and publish breach reports on our Cyber Threats page.
One breach exposes every client. We assess the attack surface your partners create.
A subsidiary's exposure is yours. We map risk across your portfolio.
Critical infrastructure under persistent threat. We verify what internal programs miss.
The costliest breach sector for 14 consecutive years. We quantify the exposure.
Banks, insurers, and payment platforms across three continents. We find what compliance audits miss.
Millions of records, hundreds of vendors. We test the boundaries.
Zero Tolerance is a security research firm built on one principle: Breaches are inevitable, but negligence isn't.
We conduct passive external reconnaissance - no intrusion, no exploitation. We observe what's already exposed and document what organizations fail to protect.
Every disclosure is responsible. Every remediation is confirmed. Every analysis is published to raise the standard of accountability in cybersecurity.
Responsible disclosure, advisory engagement, or media inquiries.
We do not use web forms. Your message is sent directly from your own email client - no data passes through or is stored on our servers. For sensitive disclosures, encrypt with our PGP key.
RESPONSE WITHIN 48 HOURS
KARIM EL LABBAN · FOUNDER & PRINCIPAL · ZERO TOLERANCE LLC