From the Desk
CISO & Security Leaders
Strategic threat landscape, regulatory changes, board-level risk intelligence.
20
Stories filed
4
Desks covered
≥ 7/10
Editorial floor
Coverage:RegulatoryThreat IntelComplianceSecurity
§
On the CISO & Security Leaders Desk
The latest stories filtered for your beat, organised by sub-section.
Security4 stories
- CISOs Feel the Heat Over AI RiskWith 26% of CISOs considering leaving due to AI-related job pressure, boards face a talent-retention crisis precisely when AI governance demands are escalating — losing experienced security leaders compounds organisational risk.20 Jul
- Security incident disclosure – July 202619 Jul
- Abbott probes two cyber incidents amid extortion claimsA healthcare/diagnostics conglomerate facing dual breaches with extortion illustrates the compounding risk when legacy systems coexist with modern portals in large enterprises.17 Jul
- Ernst & Young discloses data breach after support system hackA Big Four consultancy losing client data through a compromised third-party ticketing system underscores persistent supply-chain risk for any enterprise relying on outsourced IT support.17 Jul
Threat Intel13 stories
- Attackers Combo Up Evasion Tactics for BEC Phishing20 Jul
- New HollowGraph malware uses Microsoft Graph for stealthy C2 commsAbusing trusted Microsoft 365 infrastructure for C2 makes detection significantly harder and could bypass traditional perimeter controls across enterprise tenants.20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 Jul
- Romania races to restore land registry after cyberattack disrupts property marketAn EU member state's land registry — critical to its property market — was crippled by what officials called their worst-ever cyber incident, illustrating how attacks on government digital infrastructure can cascade into real-economy disruption.20 Jul
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050HollowGraph abuses legitimate Microsoft 365 calendar infrastructure for C2, making detection extremely difficult for organisations that rely heavily on M365 — which includes the vast majority of European enterprises.20 Jul
- Software provider to more than 2,000 US hospitals says hackers stole employee and customer dataEdinburgh-based, AIM-listed Craneware serving 2,000+ US hospitals suffered a breach — a reminder that healthcare supply-chain vendors with EU headquarters face dual regulatory exposure under GDPR and potential NIS2 essential-entity rules.20 Jul
- Autonomous AI Intrusions Are Here: Lessons from the Hugging Face CompromiseThe Hugging Face incident reportedly represents the first publicly confirmed intrusion driven end-to-end by an autonomous AI agent, marking a qualitative shift in threat actor capability that demands revised risk models.20 Jul
- Hackers abuse ViPNet software to target Russian govt agencies19 Jul
- UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih MalwareRussian state-sponsored actors deploying social-engineering tactics against Ukrainian targets signals escalation in cyber operations that could spill over to EU-aligned organisations and supply chains.19 Jul
- Microsoft warns of surge in ACR Stealer attacks on customersMicrosoft's warning about surging ACR Stealer activity signals a credential-theft campaign at scale, putting browser-stored enterprise credentials and auth tokens at direct risk.18 Jul
- The Good, the Bad and the Ugly in Cybersecurity – Week 2917 Jul
- GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate TheftCompromise of a certificate authority's code-signing infrastructure undermines software-supply-chain trust globally — any organisation relying on DigiCert-signed code must assess exposure.17 Jul
- Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag ImagesNorth Korean campaigns using fake developer hiring tests are actively targeting tech teams — a direct HR and supply-chain risk for European firms recruiting remotely.17 Jul
Regulatory2 stories
- AI Watermark Evidence Fails Forensic Readiness: An Empirical EvaluationThe research directly challenges the reliability of AI watermarking mandated by the EU AI Act and California's SB 942 — CISOs must understand these limitations when building AI governance programmes.20 Jul
- E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants17 Jul