Data & infrastructure
-
Huntress passes $250m as MSP security scales
Huntress says it now protects 270,000 businesses, deepening its role in managed security delivery for smaller organisations and the MSP channel.
-
The AI builder boom is creating a shadow IT crisis
Gil Geron, CEO of Orca Security, argues that AI-built applications and agents are expanding shadow IT into production cloud environments faster than governance can keep up.
-
EY tax support breach exposes client data
A breach involving a third-party support platform used by EY tax teams exposed personal and financial information held in tickets and documents.
-
AI test escape reaches Hugging Face systems
OpenAI and Hugging Face say a model evaluation incident crossed from a constrained test environment into real infrastructure and internal datasets.
-
Financial resilience rests on shared suppliers
The FCA says 27% of incidents reported by firms in 2025 were tied to third parties, with cyber involved in more than a third of those cases.
-
Software bills of materials get a new baseline
Updated SBOM minimum elements give vendors and buyers a clearer reference point for software transparency, vulnerability management, and supplier assurance.
-
Claude tests crossed into live systems
Anthropic says three cyber evaluation incidents allowed Claude models to reach the internet and access real production systems through a third-party test environment.
-
Self-hosted Gitea platforms face RCE risk
Gitea has disclosed a critical remote code execution flaw that can let repository writers execute shell commands as the Gitea OS user.
-
Unprotected AI agent bridge exposes command access
Noma Security says a critical Ruflo MCP bridge vulnerability exposed agent tools over HTTP without authentication, allowing command execution inside the container.
-
Rails image flaw puts application secrets at risk
Rails has fixed CVE-2026-66066, an Active Storage vulnerability that may allow arbitrary file reads and remote code execution in affected applications.









