Vulnerabilities
33 stories[NEU] [hoch] VMware Tanzu Spring Cloud Gateway Server und Sleuth: Mehrere Schwachstellen
Spring Cloud Gateway vulnerabilities pose denial-of-service and data manipulation risks for microservices architectures commonly deployed in European enterprises.
CERT-Bund (BSI)9/10Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code
Veeam's critical RCE vulnerability exposes backup infrastructure to domain-level attacks, potentially compromising business continuity and recovery capabilities.
THN (Feedburner)9/10Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
The immediate exploitation of Ivanti Sentry's maximum-severity flaw demonstrates how threat actors now pre-position for rapid weaponization once vulnerabilities become public.
Dark Reading9/10[UPDATE] [kritisch] Ivanti Sentry: Mehrere Schwachstellen
Critical-severity Ivanti Sentry flaws enable unauthenticated remote attackers to execute arbitrary code with administrative privileges, creating immediate risk for organizations using this mobile device management platform.
CERT-Bund (BSI)9/10[UPDATE] [kritisch] Oracle PeopleSoft: Schwachstelle ermöglicht Codeausführung
Critical Oracle PeopleSoft vulnerability enables complete system takeover, posing existential threat to organizations running HR and financial systems on this platform.
CERT-Bund (BSI)9/10[UPDATE] [hoch] Check Point Remote Access VPN und Mobile Access: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen
Check Point VPN security bypasses allow unauthenticated access to corporate networks, creating direct exposure for remote workforce infrastructure.
CERT-Bund (BSI)9/10[UPDATE] [hoch] OpenSSL: Mehrere Schwachstellen
High-severity OpenSSL vulnerabilities affect the cryptographic foundation of virtually all enterprise systems, requiring urgent patching across web services, applications, and infrastructure.
CERT-Bund (BSI)9/10CVE-2025-0282 and CVE-2025-0283: Critical Ivanti 0days Exploited in the Wild
Zero-day exploitation of Ivanti Connect Secure introduces immediate enterprise VPN compromise risk, particularly threatening European organizations dependent on these appliances for remote workforce security.
Wiz BlogCVE-2025-02829.09/10Wiz Research Identifies Exploitation in the Wild of Aviatrix Controller RCE (CVE-2024-50603)
Unauthenticated remote code execution in Aviatrix Controllers enables direct escalation to AWS control plane privileges, creating a critical exposure path for cloud infrastructure managed through these platforms.
Wiz BlogCVE-2024-5060310.09/10A Record-Breaking Patch Tuesday for June 2026
Microsoft's unprecedented 200-vulnerability patch release signals a potential shift toward batch disclosure of accumulated security debt rather than standard monthly maintenance.
Krebs on Security9/10CISA orders feds to patch actively exploited Ivanti flaw by Sunday
CISA's new BOD 26-04 mandates a 72-hour patch window for an actively exploited Ivanti Sentry vulnerability — a tempo that signals growing zero-day pressure on edge-gateway appliances common in European enterprises.
BleepingComputer9/10SharePoint Vulnerabilities (CVE-2025-53770 & CVE-2025-53771): Everything You Need to Know
Active SharePoint exploitation campaigns target document repositories containing sensitive enterprise data, requiring immediate patch deployment and access audits.
Wiz BlogCVE-2025-537709.89/10[NEU] [hoch] Jenkins: Mehrere Schwachstellen
High-severity Jenkins vulnerabilities enable code execution and privilege escalation, threatening CI/CD pipeline integrity across development environments relying on this automation server.
CERT-Bund (BSI)9/10LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE
LiteLLM's addition to CISA's KEV catalog indicates active exploitation of AI infrastructure components, highlighting enterprise AI deployment risks.
THN (Feedburner)CVE-2026-422718.89/10Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
Protocol buffer implementation flaws in Node.js applications create RCE vectors in data serialization layers often overlooked during security assessments.
THN (Feedburner)9/10[UPDATE] [hoch] GitLab: Mehrere Schwachstellen
GitLab vulnerabilities threaten the software development lifecycle integrity across European enterprises increasingly reliant on DevOps automation for digital transformation initiatives.
CERT-Bund (BSI)9/10[UPDATE] [kritisch] vm2: Mehrere Schwachstellen
Critical vm2 sandbox escape vulnerabilities expose Node.js applications to remote code execution, threatening containerized environments widely used in European CI/CD pipelines.
CERT-Bund (BSI)9/10[UPDATE] [hoch] Red Hat Undertow: Mehrere Schwachstellen ermöglichen Umgehung von Sicherheitsmaßnahmen
Red Hat Undertow web server vulnerabilities enable security bypass and data manipulation, affecting enterprise applications built on this Java servlet container technology.
CERT-Bund (BSI)8/10One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public
A single-character Linux kernel flaw demonstrates how minimal code changes can create container escape vulnerabilities with publicly available exploits.
THN (Feedburner)CVE-2026-231117.88/10Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now
Chrome's V8 zero-day exploitation underscores browser security as a critical enterprise attack vector requiring immediate patch deployment across distributed workforces.
THN (Feedburner)CVE-2026-116458.88/10phpBB forum fixes auth bypass bug lurking for a decade
The decade-long persistence of this phpBB authentication bypass demonstrates how privilege escalation vulnerabilities in widely-deployed open source software can remain hidden in plain sight.
BleepingComputer8/10[UPDATE] [mittel] Red Hat Enterprise Linux (giflib): Schwachstelle ermöglicht Codeausführung oder DoS
CERT-Bund updates advisory for giflib vulnerability in Red Hat Enterprise Linux enabling memory corruption attacks that could lead to code execution or denial of service.
CERT-Bund (BSI)8/10[UPDATE] [hoch] Mozilla Firefox und Thunderbird: Mehrere Schwachstellen
Multiple browser vulnerabilities affecting Firefox and Thunderbird present enterprise-wide exposure given widespread deployment across European organizations for daily operations.
CERT-Bund (BSI)8/10[UPDATE] [hoch] AMD ARM und EPYC Prozessoren: Mehrere Schwachstellen
AMD processor vulnerabilities affecting ARM and EPYC architectures could enable security bypass attacks at the hardware level, impacting data center and cloud deployments.
CERT-Bund (BSI)8/10[UPDATE] [hoch] strongSwan: Mehrere Schwachstellen ermöglichen Denial of Service und Codeausführung
strongSwan VPN infrastructure faces remote code execution risks from anonymous attackers, threatening secure tunnel integrity across European networks.
CERT-Bund (BSI)8/10[UPDATE] [hoch] Mozilla Firefox und Mozilla Thunderbird: Mehrere Schwachstellen
High-severity Mozilla updates address code execution and security bypass flaws affecting enterprise browser deployments across German organizations.
CERT-Bund (BSI)8/10[UPDATE] [hoch] Keycloak: Mehrere Schwachstellen
High-severity Keycloak identity management vulnerabilities could compromise authentication systems protecting enterprise applications and user access controls.
CERT-Bund (BSI)8/10[NEU] [hoch] Apache OFBiz: Mehrere Schwachstellen
Apache OFBiz enterprise resource planning vulnerabilities allow authenticated attackers to escalate privileges, potentially compromising business-critical financial and operational systems.
CERT-Bund (BSI)8/10[UPDATE] [hoch] Google Chrome/Microsoft Edge: Schwachstelle ermöglicht Codeausführung
High-severity Chrome and Edge vulnerability enables arbitrary code execution, threatening enterprise browser security across widespread desktop deployments.
CERT-Bund (BSI)8/10Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address
The Ghost-Sender Exchange misconfiguration enables email spoofing attacks that could bypass enterprise email authentication controls and regulatory compliance frameworks.
Dark Reading8/10[UPDATE] [mittel] Red Hat Single Sign On: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Authentication bypass vulnerability in enterprise identity platform threatens centralized access controls used by thousands of European organizations for regulatory compliance.
CERT-Bund (BSI)7/10[UPDATE] [mittel] Keycloak: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Identity management bypass affects authentication flows across enterprise SSO deployments relying on Keycloak for access control.
CERT-Bund (BSI)7/10[UPDATE] [mittel] AMD Prozessoren: Schwachstelle ermöglicht Manipulation von Daten
AMD processor vulnerability enables local data manipulation, presenting risks for high-security environments where hardware integrity is critical.
CERT-Bund (BSI)6/10
Threat Intel
19 storiesOver 400 Arch Linux packages compromised to push rootkit, infostealer
The compromise of 400+ Arch Linux packages represents a sophisticated supply chain attack targeting developer workstations through trusted community repositories.
BleepingComputer9/10Chinese hackers hijack auth flow, spy on isolated network for a decade
This decade-long compromise of authentication infrastructure represents a masterclass in APT persistence, showing how attackers can maintain invisible access by controlling the very systems meant to secure access.
BleepingComputer9/10China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
Enterprise Linux infrastructure faces heightened APT risk as authentication bypass techniques target core system components rather than traditional endpoints.
THN (Feedburner)9/10'Hades' Campaign Against PyPI Puts New Spin on Shai-Hulud
The Hades campaign's evolution of Shai-Hulud tactics demonstrates how supply chain attackers adapt existing frameworks rather than developing entirely new attack vectors.
Dark Reading9/10The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm
The group's transition from affiliate to independent operator with worm capabilities represents a concerning evolution in ransomware ecosystem maturity.
THN (Feedburner)8/10ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
Higher education institutions face disproportionate targeting through enterprise software vulnerabilities, with Oracle ERP systems providing broad access to sensitive academic and research data.
Dark Reading8/10Pharma giant Novo Nordisk discloses breach of clinical trials data
Novo Nordisk's disclosure of a clinical-trials data breach highlights the unique GDPR and health-data-regulation exposure facing EU-headquartered pharma companies, where patient records trigger the strictest processing rules.
BleepingComputer8/10Over 73,000 French govt employees affected in Tchap messenger breach
France's government messaging platform breach affecting 73,000 employees highlights risks when secure communication tools become single points of failure for sensitive operations.
BleepingComputer8/10Belarus-linked hackers target Gmail accounts of Polish public figures and their families
State-sponsored targeting of personal accounts belonging to officials' family members represents an expansion of traditional espionage tactics beyond professional targets.
The Record8/10Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
Dark-web monitoring of GitHub credential sales and leaked API keys can surface supply-chain compromise indicators well before a downstream attack materialises — a proactive intelligence capability most Mittelstand firms still lack.
BleepingComputer8/10Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
The Miasma worm's self-propagating compromise of Microsoft repositories demonstrates how supply chain attacks can achieve lateral movement within vendor ecosystems.
Dark Reading8/10Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks
Silent Ransom's multi-vector approach combining social engineering with physical office intrusion represents an escalation beyond traditional ransomware operational models.
Dark Reading8/10When “Hi, This Is IT” Comes Through Microsoft Teams
Enterprise collaboration platforms face elevated phishing risks as attackers exploit trusted internal communication channels to bypass traditional email security controls.
Unit 42 (Palo Alto)8/10China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
The botnet's focus on SOHO devices suggests Chinese actors are building distributed reconnaissance infrastructure that could threaten European SME networks.
THN (Feedburner)8/10FBI disrupts massive AI-powered phishing service using a million URLs
The FBI's disruption of this million-URL phishing infrastructure demonstrates how AI-powered cybercrime services are scaling beyond traditional detection capabilities, requiring new defensive approaches.
BleepingComputer8/10Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History
DeepSeek database exposure reveals millions of chat logs and internal data, highlighting AI service privacy risks for European enterprise users.
Wiz Blog8/10The Invisible Battlefield: How Cyberwar Is Reshaping Everyday Life
Critical infrastructure sectors face escalating nation-state targeting that threatens business continuity beyond traditional IT systems, extending to operational technology and essential services.
Dark Reading8/10NSO Group Hacking WhatsApp Despite Court Order
Commercial spyware vendors continue operations despite legal constraints, demonstrating enforcement challenges for enterprise communication security.
Schneier on Security8/10Ukrainian national pleads guilty to role in Conti ransomware operation
Legal accountability for major ransomware groups continues advancing as another Conti operative faces US prosecution, signaling strengthened international cooperation in cybercrime enforcement.
BleepingComputer7/10
AI Security
14 storiesSEVRA-BENCH: Social Engineering of Vulnerabilities in Review Agents
New benchmark reveals social engineering vulnerabilities in LLM code reviewers, demonstrating how adversaries could manipulate automated pull request workflows to introduce malicious code.
arXiv Crypto & Security9/10Trust No Skill: Integrity Verification for AI Agent Supply Chains
Third-party AI agent extensions present supply chain risks through hidden vulnerabilities and multi-stage attack sequences that traditional security controls may miss.
Unit 42 (Palo Alto)9/10COGNITION: From Evaluation to Defense against Multimodal LLM CAPTCHA Solvers
Large language models can now bypass visual CAPTCHAs at scale, fundamentally undermining a core web security assumption relied upon by enterprise authentication flows.
arXiv Crypto & Security9/10From Shield to Target: Denial-of-Service Attacks on LLM-Based Agent Guardrails
LLM safety guardrails designed to prevent prompt injection attacks can themselves become targets for denial-of-service attacks, creating availability risks for AI-powered enterprise systems.
arXiv Crypto & Security9/10Anthropic requires 30 day data retention for Fable and Mythos
Hacker News (Security)8/10Hacking Embodied AI
Physical AI robots entering enterprise environments introduce novel attack vectors combining traditional IoT vulnerabilities with AI manipulation techniques.
Recorded Future8/10MAStrike: Shapley-Guided Collusive Red-Teaming on Multi-Agent Systems
Shapley-value-guided red-teaming of hierarchical multi-agent systems reveals that collusion among specialised AI agents can bypass distributed safety controls — a concern as agentic AI enters finance and software engineering workflows.
arXiv Crypto & Security8/10Game-Theoretic Multi-Agent Control for Robust Contextual Reasoning in LLMs
A game-theoretic multi-agent control framework addresses prompt-injection and context-poisoning in multi-turn LLM interactions — a defence pattern enterprises should watch as agentic AI moves into production pipelines.
arXiv Crypto & Security8/10Patcher: Post-Hoc Patching of Backdoored Large Language Models
This post-deployment backdoor remediation technique addresses a critical gap in AI security by enabling organizations to clean compromised models without complete retraining, reducing the operational cost of security incidents.
arXiv Crypto & Security8/10Security in a Workflow: Exploring Role-Based Agentic Architectures for Vulnerability Handling
Multi-agent AI systems are being designed to handle complete vulnerability management workflows, potentially automating the entire security remediation cycle from detection through verification.
arXiv Crypto & Security8/10I evaluated 5 LLM agents on patching real-world CVEs. Here is what I found.
r/netsec8/10From Prompts to Responses: Dual-Sided Data Leakage and Defense in Split Large Language Models
Split learning architectures for LLMs create dual-sided data leakage risks where both user prompts and model responses can expose sensitive information across distributed infrastructure.
arXiv Crypto & Security8/10[NEU] [mittel] vllm: Schwachstelle ermöglicht Codeausführung
BSI issues a new advisory for vLLM, the popular open-source LLM inference engine — remote code execution risk highlights the attack surface that AI serving infrastructure introduces.
CERT-Bund (BSI)7/10[NEU] [mittel] vllm: Schwachstelle ermöglicht Manipulation von Daten
A file-manipulation flaw in the vLLM inference engine is notable as enterprises scaling GPU workloads with this framework risk unauthorised data tampering in their AI serving layer.
CERT-Bund (BSI)6/10
DevSecOps
4 storiesNew GitHub Action supply chain attack: reviewdog/action-setup
GitHub Actions supply chain compromise affects reviewdog automation, demonstrating cascading risks in CI/CD dependency chains beyond tj-actions incident.
Wiz Blog9/10Software Dark Matter: Gazing at Uncharted Files to Navigate SBOM Integrations
Research identifies 'software dark matter' - untracked files in modern applications that escape SBOM visibility, creating blind spots in European supply chain transparency initiatives.
arXiv Crypto & Security9/10Config Files That Run Code: Supply Chain Security Blindspot
Hacker News (Security)9/10Bayesian-Calibrated Detection of Hallucinated Package Imports in AI-Assisted Code
AI coding assistants increasingly introduce phantom package dependencies that create supply chain vulnerabilities, requiring new detection methods beyond traditional dependency scanning.
arXiv Crypto & Security9/10
Research
3 storiesGPS As a Key Distribution Platform
Military-grade encryption key distribution through civilian GPS infrastructure creates unexpected security dependencies for enterprise positioning services.
Schneier on Security8/10Defending the Core: A Centrality-Based Protection Strategy for Supply Chain Security in npm Dependency Network
Research proposes centrality-based protection strategies for npm dependencies, potentially helping enterprises prioritize security investments in the most critical supply chain components.
arXiv Crypto & Security8/10Critical Zcash Vulnerability Found and Fixed
AI-assisted vulnerability research demonstrates accelerated discovery timelines for cryptographic flaws in financial technology infrastructure.
Schneier on Security7/10
Cloud
2 storiesBlinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility
Cloud logging services become attack targets themselves as adversaries manipulate audit trails to hide their activities and evade detection mechanisms.
Unit 42 (Palo Alto)9/10Gain visibility into DDoS attacks with flow logs in AWS Shield Advanced
Shield Advanced now emits per-attack flow logs during DDoS events, giving SOC teams real-time traffic metadata instead of post-hoc reconstruction — a significant uplift for incident forensics on AWS.
AWS Security Blog7/10
Regulatory
2 storiesSouth Korea hits Coupang with record $409 million fine over data breach
South Korea's record $409 million data breach penalty against Coupang signals increasingly severe regulatory enforcement that European enterprises should anticipate under GDPR and NIS2.
The Record9/10Microsoft Threatening Security Researcher
Microsoft's legal threats against BitLocker exploit researchers highlight growing tension between vulnerability disclosure and corporate liability concerns.
Schneier on Security7/10
Security
2 storiesServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances
ServiceNow's security incident demonstrates SaaS platform vulnerabilities can provide unauthorized access to multiple customer environments simultaneously.
THN (Feedburner)8/10Bug Bounty Research Triggers ServiceNow Security Alert
Legitimate bug-bounty probing of ServiceNow instances triggered false-positive breach alerts at multiple organisations, revealing how thin the line is between authorised research and perceived incident response scenarios.
Dark Reading7/10
Compliance
2 storiesHow much of your company's security info ends up on Reddit?
r/AskNetsec7/10Navigating the New Federal Logging Mandate | OMB Memorandum M-26-14
OMB M-26-14 mandates risk-based federal logging priorities — European firms supplying US agencies should expect stricter log-retention and forwarding requirements in upcoming contract clauses.
Wiz Blog6/10
Tools
1 storyBoardroom Brief
What this week's reporting means for the board, in one line per story.
- Software Dark Matter: Gazing at Uncharted Files to Navigate SBOM Integrations
Hidden software components not captured in transparency reports could expose the organization to regulatory non-compliance and supply chain risks.
- Over 400 Arch Linux packages compromised to push rootkit, infostealer
Trusted software repositories now face systematic compromise, threatening development infrastructure security.
- Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code
A critical vulnerability in backup systems could prevent disaster recovery if exploited.
- Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
Critical vulnerabilities now face immediate exploitation, eliminating traditional patch deployment timelines.
- Chinese hackers hijack auth flow, spy on isolated network for a decade
State-sponsored attackers can maintain decade-long access by compromising the authentication systems enterprises rely on for security.
- [UPDATE] [kritisch] Ivanti Sentry: Mehrere Schwachstellen
Critical vulnerabilities in enterprise mobile device management platform require immediate patching to prevent administrative compromise.
- [UPDATE] [kritisch] Oracle PeopleSoft: Schwachstelle ermöglicht Codeausführung
Critical vulnerability in HR/finance systems requires immediate emergency response to prevent potential data breach.
- [UPDATE] [hoch] Check Point Remote Access VPN und Mobile Access: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen
Critical VPN vulnerabilities require immediate patching to prevent unauthorized network access.
- [UPDATE] [hoch] OpenSSL: Mehrere Schwachstellen
Critical vulnerabilities in fundamental encryption libraries create enterprise-wide exposure requiring immediate remediation.
- Blinding the Watchmen: Abusing Cloud Logging Services for Defense Evasion and Visibility
Attackers are targeting cloud logging systems to hide their tracks and evade detection.
- China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
Nation-state actors are compromising the foundation of enterprise Linux systems, requiring immediate infrastructure security review.
- A Record-Breaking Patch Tuesday for June 2026
Microsoft released a record 200 security fixes, indicating potential shifts in their vulnerability disclosure practices.
- CISA orders feds to patch actively exploited Ivanti flaw by Sunday
An actively exploited vulnerability in a common network gateway product has triggered an emergency U.S. patching directive — European organisations using the same technology face identical risk.
- [NEU] [hoch] Jenkins: Mehrere Schwachstellen
Critical development infrastructure vulnerabilities could enable supply chain compromises across software delivery pipelines.
- LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE
AI infrastructure components are now being actively exploited by attackers in the wild.
- Bayesian-Calibrated Detection of Hallucinated Package Imports in AI-Assisted Code
AI coding assistants introduce new supply chain risks by referencing packages that don't exist, creating attack vectors for malicious actors.
- SEVRA-BENCH: Social Engineering of Vulnerabilities in Review Agents
AI code reviewers can be manipulated to approve malicious code, potentially compromising software development security controls.
- [UPDATE] [hoch] GitLab: Mehrere Schwachstellen
Development platform vulnerabilities could compromise software supply chain integrity.
- [UPDATE] [kritisch] vm2: Mehrere Schwachstellen
Critical vulnerabilities in widely-used Node.js security component could enable attackers to break out of application sandboxes.
- South Korea hits Coupang with record $409 million fine over data breach
Record-breaking data breach fines signal escalating regulatory enforcement globally.
- Trust No Skill: Integrity Verification for AI Agent Supply Chains
Enterprise AI agents face new supply chain risks from untrusted third-party extensions and skills.
- COGNITION: From Evaluation to Defense against Multimodal LLM CAPTCHA Solvers
Traditional bot protection methods are becoming obsolete as AI systems can now solve visual puzzles designed to distinguish humans from machines.
- From Shield to Target: Denial-of-Service Attacks on LLM-Based Agent Guardrails
AI safety systems intended to protect against malicious prompts can themselves be weaponized to shut down business-critical AI applications.
- One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public
A trivial Linux kernel bug enables complete container breakouts with public exploits available.
- Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now
A critical Chrome vulnerability is being actively exploited and requires immediate patching across the organization.
- The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm
Ransomware groups are developing self-spreading capabilities that could dramatically increase attack impact.
- ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
Academic sector targeting demonstrates how threat actors exploit resource gaps in institutions managing valuable data.
- Pharma giant Novo Nordisk discloses breach of clinical trials data
A major EU pharmaceutical company disclosed a clinical-data breach, underscoring that health-data incidents carry elevated regulatory and reputational consequences under GDPR.
- Over 73,000 French govt employees affected in Tchap messenger breach
Even government-grade secure communications face successful breaches, requiring redundant protection strategies.
- Belarus-linked hackers target Gmail accounts of Polish public figures and their families
State-sponsored groups are expanding attacks to target personal accounts of officials' family members.
- Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
Early indicators of software supply-chain attacks are observable on criminal forums, making dark-web monitoring a cost-effective pre-breach intelligence investment.
- GPS As a Key Distribution Platform
GPS infrastructure carries hidden military communications that may create regulatory exposure for enterprise positioning systems.
- Security in a Workflow: Exploring Role-Based Agentic Architectures for Vulnerability Handling
AI systems are approaching the capability to autonomously manage security vulnerabilities from discovery to fix implementation.
- Defending the Core: A Centrality-Based Protection Strategy for Supply Chain Security in npm Dependency Network
New research offers methods to prioritize protection of the most critical software dependencies that could cascade failures across the enterprise.
- Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks
Ransomware groups are now combining cyber attacks with physical office intrusions to steal data from law firms.
- When “Hi, This Is IT” Comes Through Microsoft Teams
Attackers are bypassing email security by targeting trusted collaboration platforms like Teams.
- [UPDATE] [mittel] Red Hat Enterprise Linux (giflib): Schwachstelle ermöglicht Codeausführung oder DoS
Critical vulnerability update for enterprise Linux systems requires immediate patching to prevent potential system compromise.
- [UPDATE] [hoch] Mozilla Firefox und Thunderbird: Mehrere Schwachstellen
Critical browser flaws require immediate patching to prevent potential compromise of business communications.
- Wiz Research Uncovers Exposed DeepSeek Database Leaking Sensitive Information, Including Chat History
AI service data breaches create direct GDPR liability and competitive intelligence risks for European enterprises.
- [UPDATE] [hoch] Keycloak: Mehrere Schwachstellen
Identity management vulnerabilities pose enterprise-wide risk by potentially compromising access controls across all connected systems.
- [UPDATE] [hoch] Google Chrome/Microsoft Edge: Schwachstelle ermöglicht Codeausführung
Critical browser vulnerability requires immediate patching across all enterprise desktops.
- From Prompts to Responses: Dual-Sided Data Leakage and Defense in Split Large Language Models
Split AI processing models create new privacy vulnerabilities where sensitive data can leak from both user inputs and system outputs.
- The Invisible Battlefield: How Cyberwar Is Reshaping Everyday Life
Cyberwarfare now directly threatens business operations and customer safety, not just data.
- Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address
A Microsoft Exchange flaw allows attackers to spoof any email address, potentially compromising trusted business communications.
- NSO Group Hacking WhatsApp Despite Court Order
Commercial spyware operations continue despite court orders, requiring enhanced technical protection for executive communications.
- ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances
A major enterprise SaaS provider suffered a security breach affecting multiple customer instances.
- Ukrainian national pleads guilty to role in Conti ransomware operation
International ransomware prosecutions are accelerating, showing law enforcement's growing capability to hold cybercriminals accountable.
- [NEU] [mittel] vllm: Schwachstelle ermöglicht Codeausführung
A critical AI serving component used in many LLM deployments has a remotely exploitable flaw — patch urgency aligns with our AI governance obligations.
- [NEU] [mittel] vllm: Schwachstelle ermöglicht Manipulation von Daten
AI infrastructure components like vLLM carry their own vulnerability surface — security teams must include ML serving stacks in patch management programmes.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.