Threat Intel
20 storiesHide Your RDP: Password Spray Leads to RansomHub Deployment
DFIR Report traces a full RansomHub kill-chain from initial RDP password-spray to domain-wide encryption, offering defenders detection timestamps and IOCs at every ATT&CK stage.
The DFIR Report9/10Version 1.1: Cisco Firewalls mit persistenter Malware infiziert
BSI updated its advisory on Cisco firewalls compromised with persistent malware, indicating the campaign scope or remediation guidance has expanded since the initial release.
BSI-IT-Sicherheitsmitteilungen (BITS)9/10FortiBleed campaign used custom FortiGate sniffer to steal credentials
The FortiBleed campaign deployed custom packet sniffers on compromised FortiGate firewalls to harvest authentication credentials in transit — elevating the urgency for any organisation still running unpatched Fortinet edge devices.
BleepingComputer9/10Cat’s Got Your Files: Lynx Ransomware
DFIR Report details a Lynx ransomware intrusion originating from a single exposed RDP session—no brute-force needed—underscoring the danger of any internet-facing remote-access without MFA.
The DFIR Report9/10vSphere and BRICKSTORM Malware: A Defender's Guide
Google's defender guide for BRICKSTORM malware targeting VMware vSphere environments provides actionable detection and hardening advice — critical for enterprises relying on vCenter as their virtualisation backbone.
Google Threat Intel9/10Version 1.1: SonicWall Gen 7 Firewalls - Ransomware-Angriffe beobachtet
BSI confirms ransomware attacks targeting SonicWall Gen 7 firewalls, reinforcing the trend of threat actors systematically compromising perimeter appliances as their preferred initial-access method.
BSI-IT-Sicherheitsmitteilungen (BITS)9/10Investigating an adversary-in-the-middle phishing campaign targeting Microsoft 365 and Okta users
Datadog details an adversary-in-the-middle phishing campaign stealing M365 and Okta session tokens — a direct threat to enterprises relying on federated identity without phishing-resistant MFA.
Datadog Security Labs9/10Web Traffic Hijacking: When Your Nginx Configuration Turns Malicious
Datadog documents an active campaign hijacking web traffic via tampered NGINX configs and compromised Baota management panels — with IOCs to check against your own reverse-proxy infrastructure.
Datadog Security Labs9/10Risky Business #830 -- LiteLLM and security scanner supply chains compromised
Supply-chain compromises of LiteLLM and security-scanning toolchains show attackers increasingly targeting developer infrastructure, with one campaign bundling an anti-Iran wiper alongside the backdoor.
Risky Business9/10Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects
A cascading GitHub Actions supply-chain attack exfiltrated secrets from 23,000 repositories, demonstrating how a single compromised CI/CD component can propagate at ecosystem scale.
Risky Business9/10Microsoft links Mastra AI supply chain attack to North Korean hackers
Microsoft attributes the Mastra AI npm supply-chain compromise—140+ malicious packages—to North Korea's Sapphire Sleet, signalling that state-sponsored actors are now systematically targeting the AI-tooling ecosystem.
BleepingComputer9/10Risky Business #788 -- Trump targets Chris Krebs, SentinelOne
The Trump administration's political targeting of former CISA director Krebs and SentinelOne raises concerns about the independence of US cybersecurity institutions that European partners rely on for threat intelligence.
Risky Business8/10Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
Two Russian APT campaigns are exploiting CVE-2025-8088 in WinRAR — patched a year ago — against Ukrainian military and government targets, underscoring the long tail of unpatched archive-handler vulnerabilities in conflict zones.
Dark ReadingCVE-2025-80888.88/10Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
A Chinese espionage group abused Google Workspace mail-routing rules to silently exfiltrate defence and medical research emails for over a year after backdooring REDCap servers.
THN (Feedburner)8/10[UPDATE] [mittel] MISP: Mehrere Schwachstellen
MISP threat intelligence platform vulnerabilities could compromise security teams' ability to share and analyze threat indicators effectively.
CERT-Bund (BSI)8/10Iran Signed a Ceasefire — Its Hackers Didn't
Iranian state-linked cyber operations persisted despite a formal ceasefire, spotlighting the gap in international law where cyber-hostilities are not explicitly covered by ceasefire obligations.
Dark Reading7/10Phishing Attack Volume Down 20%, But Risk Still Rising
Phishing volumes dropped 20%, yet per-campaign success rates are climbing as attackers leverage AI to craft more convincing lures — a quality-over-quantity shift that defeats volume-based detection heuristics.
Dark Reading7/10Stopping Sobolan Malware with Aqua Runtime Protection
A multi-stage campaign dubbed Sobolan targets Jupyter Notebook environments with compressed payloads from remote C2 servers, underscoring the growing risk to data-science infrastructure.
Aqua Security7/10Tomcat in the Crosshairs: New Research Reveals Ongoing Attacks
Active exploitation campaigns against Apache Tomcat are accelerating, with attackers weaponising new vulnerabilities within hours—organisations should verify Tomcat exposure and patch status now.
Aqua Security7/10Pass the Cookie and Pivot to the Clouds
Stolen browser session cookies let attackers bypass MFA and pivot from compromised endpoints into cloud services — a technique enterprises must detect at the session layer, not just the perimeter.
Embrace The Red (AI Security)7/10
AI Security
15 storiesAgentjacking Attack Tricks AI Coding Agents Into Running Malicious Code
Social engineering attacks against AI coding assistants could compromise developer workstations by exploiting the trust relationship between humans and AI tools.
THN (Feedburner)9/10Copilot 'SearchLeak' Attack Allows 1-Click Data Theft
A now-patched three-stage prompt-injection chain in Microsoft Copilot used hidden URLs to exfiltrate user data with a single click—illustrating systemic risks in enterprise AI assistant deployments.
Dark Reading9/10What we learned about TEE security from auditing WhatsApp's Private Inference
Trail of Bits' audit of Meta's TEE-based AI inference reveals hard lessons for enterprises seeking to combine end-to-end encryption with cloud-hosted LLM processing.
Trail of Bits9/10US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
The US government's emergency intervention against Anthropic's AI models marks the first known instance of regulatory authorities forcing immediate AI capability restrictions based on national security concerns.
BleepingComputer8/10Google Antigravity exfiltrates data via indirect prompt injection attack
Hacker News (AI Security)8/10Autonomous cars, drones cheerfully obey prompt injection by road sign
Hacker News (AI Security)8/10SkillMutator: Benchmarking and Defending Language-and-Code Cross-modal Attacks on LLM Agent Skills
New research demonstrates cross-modal attacks where adversaries manipulate both documentation and code to compromise LLM agent skills, creating enterprise risks for AI-powered automation workflows.
arXiv Crypto & Security8/10One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Varonis chained three bugs in Microsoft 365 Copilot Enterprise Search into a one-click exfiltration path — emails, files, and MFA codes were reachable via a trusted Microsoft URL.
THN (Feedburner)8/10Entra Agent ID: Inside a cross-tenant agent compromise
A cross-tenant agent compromise via Entra Agent ID blueprints mirrors the Midnight Blizzard attack pattern — an attacker controlling a third-party blueprint can impersonate any downstream agent, threatening multi-tenant SaaS environments.
Datadog Security Labs8/10Promoting Advanced Artificial Intelligence Innovation and Security
Hacker News (DevSecOps)7/10US holds off blacklisting DeepSeek, more than 100 firms deemed security risks
Hacker News (DevSecOps)7/10Microsoft 365 Copilot Generated Images Accessible Without Authentication -- Fixed!
Microsoft 365 Copilot-generated images were publicly accessible without authentication until a fix was applied, underscoring that AI features bolted onto SaaS suites can quietly erode access controls.
Embrace The Red (AI Security)7/10The Normalization of Deviance in AI
Drawing parallels to the Challenger disaster's cultural failures, this essay argues the AI industry is normalising known security defects—a governance-level warning for boards green-lighting large-scale AI rollouts.
Embrace The Red (AI Security)7/10Show HN: Claw Patrol, a security firewall for agents
Hacker News (Security)7/10Dynamic Free-Rider Detection in Federated Learning via Simulated Attack Patterns
A new method uses simulated attack patterns to detect free-rider clients in federated learning, addressing a model-integrity gap relevant to enterprises deploying privacy-preserving ML under EU AI Act obligations.
arXiv Crypto & Security7/10
Vulnerabilities
13 storiesCISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
CISA added a max-severity Joomla JCE flaw enabling unauthenticated PHP execution to its KEV catalogue, signalling active exploitation that affects the many EU SMBs still running Joomla-based sites.
THN (Feedburner)9/10Version 1.0: Ivanti Connect Secure - Zero-Day Angriffe beobachtet
BSI confirms active zero-day exploitation of Ivanti Connect Secure appliances, continuing a pattern of edge-device targeting that has plagued European organisations since late 2023.
BSI-IT-Sicherheitsmitteilungen (BITS)9/10Version 1.0: Kubernetes - Kritische Schwachstelle im Ingress NGINX Controller ermöglicht Clusterübernahme
BSI flags a critical Kubernetes Ingress NGINX Controller vulnerability that allows full cluster takeover — a severe risk for any enterprise running containerised workloads with exposed ingress endpoints.
BSI-IT-Sicherheitsmitteilungen (BITS)9/10Twenty One Zero-Days in FFmpeg
Hacker News (Security)9/10Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP
Wiz discloses 'Fragnesia,' a new Linux kernel page-cache corruption bug in the ESP-in-TCP path enabling unprivileged local-to-root escalation — part of the growing Dirty Frag exploit family.
Wiz Blog9/10Persistent XSS/RCE using WebSockets in Storybook’s dev server
A WebSocket hijacking vulnerability in Storybook's development server (CVE-2026-27148) can be chained to achieve persistent XSS and RCE, creating a credible path to supply-chain compromise for any team running Storybook locally.
AikidoCVE-2026-271489.69/10Version 1.1: Citrix NetScaler ADC & NetScaler Gateway - Kritische Sicherheitslücken geschlossen und teils aktiv ausgenutzt
BSI reports critical Citrix NetScaler ADC and Gateway vulnerabilities are patched but some are already being actively exploited — urgency is high for organisations that delayed remediation.
BSI-IT-Sicherheitsmitteilungen (BITS)9/10[UPDATE] [hoch] git: Mehrere Schwachstellen
Git vulnerabilities present supply chain risk through compromised version control, potentially affecting software integrity across development teams and CI/CD pipelines enterprise-wide.
CERT-Bund (BSI)8/10[UPDATE] [hoch] Bouncy Castle BC-JAVA: Mehrere Schwachstellen
Cryptographic library vulnerabilities in Bouncy Castle threaten the security foundation of countless Java applications across enterprise environments, potentially undermining encryption assumptions.
CERT-Bund (BSI)8/10ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
University targeting suggests the group prioritizes high-value research data and academic credentials over traditional financial targets.
THN (Feedburner)CVE-2026-352739.88/10[NEU] [hoch] IBM i: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
IBM i administrative privilege escalation vulnerability threatens mainframe environments still prevalent in German manufacturing and financial sectors.
CERT-Bund (BSI)8/10[UPDATE] [hoch] Google Chrome / Microsoft Edge: Mehrere Schwachstellen
Chrome and Edge browser vulnerabilities require immediate patching across enterprise endpoints to prevent code execution through web-based attacks.
CERT-Bund (BSI)8/10[UPDATE] [hoch] Ubiquiti UniFi OS: Mehrere Schwachstellen
Ubiquiti UniFi network management flaws enable privilege escalation and data manipulation across enterprise wireless infrastructure deployments.
CERT-Bund (BSI)8/10
Compliance
11 storiesTikTok, AliExpress and WeChat ignore your GDPR rights
Hacker News (EU Regulatory)9/10Delve – Fake Compliance as a Service – Part II
Hacker News (EU Regulatory)9/10SBOMs in 2026: Everyone's generating them, no one's using them
ENISA's 2026 study of 334 organisations reveals that SBOM generation has become routine but operational consumption — vulnerability correlation, procurement gating — lags far behind, weakening CRA readiness.
Aikido8/10Data sharing and GDPR compliance: Bounty UK shows what not to do
The UK ICO's enforcement against Bounty for illegal bulk data sharing offers a concrete precedent for EU-operating firms to benchmark their own third-party data-sharing practices against GDPR Article 6 expectations.
GDPR.eu8/10Italy fines Eni Gas e Luce €11.5 million for multiple GDPR violations
Italy's €11.5M double fine against Eni Gas e Luce for consent and telemarketing violations remains one of the largest early GDPR penalties — a reference point for enterprises auditing consent management workflows.
GDPR.eu8/10I Read NIST 800-218 So You Don’t Have To: Here’s What To Watch Out For
Practical breakdown of NIST SP 800-218 requirements, highlighting the areas most likely to create compliance friction for organisations not yet following attestation-based development practices.
Chainguard7/10How to explain the CISA software attestation requirements to your board
CISA's draft self-attestation form translates OMB M-22-18 into concrete minimum requirements—a useful benchmark even for EU firms selling software to US federal buyers.
Chainguard7/10Building digital products for the Cyber Resilience Act
Chainguard positions its zero-CVE container approach as a shortcut to meeting the EU CRA's secure-by-design mandate — useful vendor framing, but teams should map actual CRA obligations independently.
Chainguard7/10Data anonymization and GDPR compliance: the case of Taxa 4×35
Danish taxi firm Taxa 4×35's enforcement case illustrates how DPAs scrutinise anonymisation techniques — a useful benchmark for organisations processing high-volume personal data under GDPR Art. 89.
GDPR.eu7/10What the first Italian GDPR fine reveals about data security liabilities for processors
Italy's €50k fine against the Rousseau platform underscores that data processors — not only controllers — bear direct GDPR liability when security controls are inadequate.
GDPR.eu7/10Spring 2026 SOC 1 and 2 reports are now available in OSCAL format
AWS now publishes SOC 1 and SOC 2 reports in machine-readable OSCAL format, enabling automated ingestion into GRC platforms and reducing the manual effort of continuous cloud-provider assurance reviews.
AWS Security Blog7/10
DevSecOps
10 storiesSupply Chain Security Risk: GitHub Action tj-actions/changed-files Compromised
CVE-2025-30066 in the popular tj-actions/changed-files GitHub Action leaked CI/CD secrets through build logs, echoing earlier supply-chain compromises and reinforcing the need for pinned action references.
Aqua SecurityCVE-2025-300668.69/10Living Off the Pipeline: Defending Against CI/CD Subversion
Deep-dive into 'living-off-the-pipeline' techniques where attackers abuse legitimate CI/CD features—build triggers, artefact caches, runner tokens—rather than injecting malicious code directly.
SentinelOne Blog9/10[tl;dr sec] #321 - Sandboxing AI Agents, Trivy Compromised, Pentesting AWS' AI Pentester
The compromise of Trivy, a widely-deployed container scanner, underscores that even security tooling in CI/CD pipelines is a viable supply-chain target, while AWS's own AI-based pentesting agent showed exploitable weaknesses.
tl;dr sec9/10Novo Nordisk Breach Highlights Software Development Pipeline Risk
A leaked GitHub token at Novo Nordisk exposed development pipelines, underscoring that secrets management must be treated as an identity-governance discipline—not just a vault configuration task.
Dark Reading9/10We hardened zizmor's GitHub Actions static analyzer
After the Trivy-action supply-chain attack on PyPI, Trail of Bits hardened zizmor to detect pull_request_target misconfigurations that enable secret exfiltration from GitHub Actions.
Trail of Bits9/10Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised
The Mini Shai-Hulud campaign has compromised TanStack and other high-value npm packages, injecting malicious code into widely used developer tooling—a direct supply-chain threat to any JavaScript-heavy enterprise stack.
Wiz Blog9/10GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
GitHub's breaking change reflects growing industry recognition that convenience features in package managers have become major supply chain attack vectors.
THN (Feedburner)9/10Dealing with multiple SBOMs
Practical strategies for merging and correlating multiple SBOMs across a product's lifecycle — a growing pain as CRA and US EO mandates push SBOM adoption into real workflows.
Chainguard8/10The security costs of base image version loitering
Stale base images silently accumulate known CVEs; the article quantifies how version-pinning without regular refresh inflates container attack surface over time.
Chainguard8/10Curl will not accept vulnerability reports during July 2026
Hacker News (Security)8/10
Research
6 storiesWe beat Google’s zero-knowledge proof of quantum cryptanalysis
Trail of Bits claims a more efficient zero-knowledge proof challenging Google's timeline for quantum ECC key-breaking, intensifying the post-quantum migration urgency.
Trail of Bits10/10V8 Heap Archaeology: Finding Exploitation Artifacts in Chrome’s Memory
SpecterOps details memory-level artifacts left by V8 JavaScript exploitation primitives, offering forensic analysts and exploit researchers a detection methodology for Chrome full-chain attacks.
SpecterOps9/10npx Confusion: Packages That Forgot to Claim Their Own Name
Researchers registered 128 unclaimed npm names referenced in official docs and logged 121k downloads in seven months — demonstrating that namespace confusion in package managers remains a systemic supply-chain risk.
Aikido9/10Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
GTIG's disclosure of the Coruna iOS exploit kit — covering five exploits against iOS 13 through 17.2.1 — underscores the commercial exploit market's ability to stockpile and chain zero-days across multiple iOS generations.
Google Threat Intel9/10The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
GTIG documents DarkSword, a full-chain iOS exploit leveraging multiple zero-days and now adopted by several threat actors since late 2025 — demonstrating how exploit proliferation accelerates once a chain enters the commercial market.
Google Threat Intel9/10Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025
SQL Server 2025's new AI features—vector search and external model calls—open practical channels for data exfiltration and C2 transport entirely within the database engine, with published PoC code.
SpecterOps9/10
Tools
2 storiesScripting the disassembler: Local agentic reverse engineering through vbdec’s live COM object model
Cisco Talos demonstrates a local agentic reverse-engineering workflow where AI agents interact with vbdec's live COM interface—a practical pattern for augmenting malware analysis without cloud-dependent LLMs.
Cisco Talos9/10Accelerate security investigations with Kiro CLI
AWS's Kiro CLI leverages AI to streamline security investigations by auto-generating complex CLI queries across multiple services — reducing analyst friction during time-critical incident response in cloud environments.
AWS Security Blog7/10
Security
2 storiesMost CISOs Report Pressure to Bury Bad Security News
Surveys show most CISOs face implicit pressure to delay or downplay security disclosures—a governance gap that NIS2's 24-hour notification mandate will make legally untenable.
Dark Reading9/10Maine breach portal abused to publish fake data breach disclosures
Fraudulent breach disclosures were posted on Maine's official breach portal before verification, forcing named companies into public denials — an emerging misinformation tactic that weaponises regulatory transparency processes.
BleepingComputer7/10
Regulatory
2 storiesMaine disables data breach notification portal after fake disclosures
Maine's breach notification system compromise exposes how public disclosure portals themselves become attack vectors for spreading disinformation and undermining regulatory transparency.
BleepingComputer8/10Reliable CVE sources in the age of NIST NVD cutbacks
With NIST stepping back from CVE enrichment, enterprises must diversify vulnerability intelligence sources or risk blind spots in patch-prioritisation workflows.
Aikido7/10
Cloud
1 storyBoardroom Brief
What this week's reporting means for the board, in one line per story.
- We beat Google’s zero-knowledge proof of quantum cryptanalysis
Quantum threats to current encryption may materialise sooner than expected; cryptographic modernisation timelines should be reviewed.
- CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
A critical Joomla vulnerability is being actively exploited in the wild; unpatched public-facing sites are at immediate risk of full compromise.
- Hide Your RDP: Password Spray Leads to RansomHub Deployment
A documented ransomware case starting from an exposed remote-desktop service underlines the risk of legacy remote-access configurations.
- Supply Chain Security Risk: GitHub Action tj-actions/changed-files Compromised
A widely-used CI/CD component was compromised, potentially exposing pipeline credentials—review your software supply-chain controls.
- Version 1.0: Ivanti Connect Secure - Zero-Day Angriffe beobachtet
Ivanti VPN zero-days are being actively exploited again — consider whether continued reliance on this product is acceptable risk.
- Version 1.1: Cisco Firewalls mit persistenter Malware infiziert
Cisco firewall malware persists across reboots; affected organisations face potential regulatory reporting obligations under NIS2.
- Most CISOs Report Pressure to Bury Bad Security News
Pressure on CISOs to suppress breach disclosures creates legal liability under NIS2's mandatory 24-hour notification window.
- FortiBleed campaign used custom FortiGate sniffer to steal credentials
Attackers installed credential-harvesting sniffers on Fortinet firewalls — assume compromise if devices were unpatched and rotate all network credentials.
- Cat’s Got Your Files: Lynx Ransomware
One exposed remote-desktop session without MFA led to a full ransomware compromise—access controls must be verified.
- vSphere and BRICKSTORM Malware: A Defender's Guide
Malware specifically targeting VMware virtualisation infrastructure poses risk to core data-centre operations.
- Version 1.1: SonicWall Gen 7 Firewalls - Ransomware-Angriffe beobachtet
Ransomware gangs are actively targeting SonicWall firewalls — verify patching and monitor for compromise indicators.
- Investigating an adversary-in-the-middle phishing campaign targeting Microsoft 365 and Okta users
Session-hijacking phishing campaigns can bypass standard MFA — upgrading to hardware-based authentication significantly reduces this board-level identity risk.
- Web Traffic Hijacking: When Your Nginx Configuration Turns Malicious
Attackers are silently hijacking web traffic by modifying server configurations — a risk that standard endpoint security may not detect.
- Living Off the Pipeline: Defending Against CI/CD Subversion
Attackers are weaponising build pipelines themselves, not just the code flowing through them—pipeline security needs dedicated investment.
- [tl;dr sec] #321 - Sandboxing AI Agents, Trivy Compromised, Pentesting AWS' AI Pentester
A compromise of a popular security scanning tool demonstrates that even defensive infrastructure is a high-value supply-chain target.
- Risky Business #830 -- LiteLLM and security scanner supply chains compromised
Attackers compromised widely used AI and security-scanning tools, threatening any organisation whose build pipelines depend on them.
- Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects
A single compromised open-source CI/CD component leaked secrets from 23,000 projects — illustrating the cascading risk of software supply-chain attacks.
- Novo Nordisk Breach Highlights Software Development Pipeline Risk
A leaked developer token at a major pharma firm illustrates that software pipeline security is a board-level supply-chain risk.
- Microsoft links Mastra AI supply chain attack to North Korean hackers
North Korean hackers compromised 140+ AI-framework packages, demonstrating that open-source AI supply chains are now a nation-state attack surface requiring board-level risk governance.
- Version 1.0: Kubernetes - Kritische Schwachstelle im Ingress NGINX Controller ermöglicht Clusterübernahme
A critical Kubernetes ingress flaw could let attackers seize entire container clusters — patch immediately.
- npx Confusion: Packages That Forgot to Claim Their Own Name
Official npm documentation inadvertently directed developers to run unclaimed packages, exposing a systemic software supply-chain weakness.
- We hardened zizmor's GitHub Actions static analyzer
CI/CD pipeline misconfigurations are actively exploited to steal credentials and poison software supply chains.
- Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised
A supply-chain attack hit widely used JavaScript libraries—development teams should verify their dependencies immediately.
- Fragnesia: Linux Kernel Local Privilege Escalation via ESP-in-TCP
A new Linux kernel privilege-escalation vulnerability could enable container escapes across cloud infrastructure — rapid patching advised.
- Coruna: The Mysterious Journey of a Powerful iOS Exploit Kit
Commercial exploit kits covering four years of iPhone models highlight the importance of aggressive mobile patching and device lifecycle management.
- The Proliferation of DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors
A powerful iOS exploit chain is now in the hands of multiple threat groups, increasing mobile attack risk across the enterprise.
- Copilot 'SearchLeak' Attack Allows 1-Click Data Theft
A patched but instructive Copilot exploit demonstrates that enterprise AI assistants introduce a new, testable attack surface requiring dedicated governance.
- Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025
New AI features in SQL Server 2025 create insider-threat and exfiltration risks that require proactive network controls before deployment.
- What we learned about TEE security from auditing WhatsApp's Private Inference
Trusted execution environments for AI are not inherently secure; independent audits are essential before deploying AI on sensitive data.
- Persistent XSS/RCE using WebSockets in Storybook’s dev server
A widely-used frontend development tool has a vulnerability that could let attackers inject code into your software supply chain.
- Version 1.1: Citrix NetScaler ADC & NetScaler Gateway - Kritische Sicherheitslücken geschlossen und teils aktiv ausgenutzt
Citrix NetScaler vulnerabilities are being actively exploited — confirm your appliances are patched and check for signs of compromise.
- [UPDATE] [hoch] git: Mehrere Schwachstellen
Version control vulnerabilities threaten software supply chain integrity across development operations.
- US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
Government intervention in AI services is now a demonstrated reality that could impact business operations and AI strategy.
- Risky Business #788 -- Trump targets Chris Krebs, SentinelOne
Political pressure on US cybersecurity leadership may weaken the intelligence-sharing partnerships that underpin European enterprise defences.
- Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
Russian groups are weaponising a year-old WinRAR flaw — a stark reminder that delayed patching translates directly into espionage risk.
- Chinese Hackers Abused Google Workspace Rules to Steal Research and Defense Emails
State-sponsored attackers hid inside research networks for a year by manipulating routine cloud email settings.
- SkillMutator: Benchmarking and Defending Language-and-Code Cross-modal Attacks on LLM Agent Skills
AI agent vulnerabilities could enable attackers to manipulate automated business processes through compromised agent capabilities.
- Dealing with multiple SBOMs
Regulatory SBOM mandates are creating operational complexity; consolidation strategy prevents compliance gaps.
- [UPDATE] [hoch] Bouncy Castle BC-JAVA: Mehrere Schwachstellen
Core cryptographic library vulnerabilities could undermine encryption across multiple business applications.
- One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
A vulnerability chain in Microsoft's AI search assistant could have exposed corporate emails and MFA codes through a single trusted link.
- Entra Agent ID: Inside a cross-tenant agent compromise
Third-party AI agent blueprints in Microsoft Entra can be weaponised for cross-tenant compromise — a supply-chain identity risk requiring board-level governance.
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities
Cybercriminals are increasingly targeting universities and research institutions for intellectual property theft.
- [NEU] [hoch] IBM i: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit Administratorrechten
Critical vulnerability in IBM mainframe systems requires immediate attention to prevent administrative compromise.
- [UPDATE] [hoch] Google Chrome / Microsoft Edge: Mehrere Schwachstellen
Critical browser vulnerabilities require immediate patching to prevent widespread endpoint compromise.
- SBOMs in 2026: Everyone's generating them, no one's using them
Generating software bills of materials is no longer enough — regulators and auditors will increasingly expect evidence that SBOMs drive actual risk decisions.
- Data sharing and GDPR compliance: Bounty UK shows what not to do
A UK enforcement action against illegal data sharing serves as a warning for any European business relying on weak consent mechanisms for third-party data flows.
- Italy fines Eni Gas e Luce €11.5 million for multiple GDPR violations
An €11.5M fine for consent violations demonstrates that flawed marketing data practices carry material financial risk.
- How to explain the CISA software attestation requirements to your board
US federal software attestation mandates may affect European suppliers; proactive gap analysis prevents deal-blocking compliance surprises.
- Building digital products for the Cyber Resilience Act
Vendor marketing around the EU Cyber Resilience Act is intensifying — ensure your CRA readiness programme is driven by legal analysis, not vendor narratives.
- Data anonymization and GDPR compliance: the case of Taxa 4×35
Regulators are actively testing whether corporate anonymisation methods truly meet GDPR standards — gaps create fine exposure.
- What the first Italian GDPR fine reveals about data security liabilities for processors
Processor liability is real — the Italian DPA's fine signals that outsourcing data processing does not outsource regulatory risk.
- Reliable CVE sources in the age of NIST NVD cutbacks
The US government's pullback from CVE data enrichment may slow vulnerability response unless alternative intelligence sources are integrated.
- Holding blobs for ransom: Four methods for Azure Storage ransomware
Cloud storage ransomware is now a demonstrated threat — Azure Blob customers need immutable backup controls to prevent data extortion.
- Microsoft 365 Copilot Generated Images Accessible Without Authentication -- Fixed!
AI add-ons in enterprise SaaS can silently weaken data-access controls, warranting periodic configuration audits.
- The Normalization of Deviance in AI
The AI sector is culturally normalising known security defects—boards should demand explicit risk-acceptance documentation.
- Iran Signed a Ceasefire — Its Hackers Didn't
A ceasefire did not stop state-backed hacking — boards should treat geopolitical risk and cyber risk as only loosely coupled.
- Phishing Attack Volume Down 20%, But Risk Still Rising
Phishing is getting smarter, not bigger — traditional volume-based defences are becoming insufficient.
- Maine breach portal abused to publish fake data breach disclosures
Official breach portals can be weaponised with fake disclosures — enterprises need a reputational-defence playbook.
- Stopping Sobolan Malware with Aqua Runtime Protection
Data-science platforms are increasingly targeted; ensure they fall under your standard security controls.
- Tomcat in the Crosshairs: New Research Reveals Ongoing Attacks
Apache Tomcat servers are under active attack with near-zero exploitation lag—ensure patching is current.
- Pass the Cookie and Pivot to the Clouds
Attackers can bypass multi-factor authentication by stealing browser cookies, turning a single compromised laptop into full cloud access.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.