Data & infrastructure
-
Critical VMware fixes put vCenter under scrutiny
Broadcom has issued critical VMware updates for vCenter and ESX, including two CVSS 9.8 vCenter vulnerabilities with no workaround.
-
Exploited Cisco flaw exposes firewall management
Cisco says attackers are exploiting a static credential flaw in Secure Firewall Management Center and has urged customers to patch and rotate credentials, keys, and certificates.
-
Cloud providers enter UK finance resilience regime
UK financial regulators are now directly overseeing the first critical third parties, bringing major cloud providers inside a system-wide operational resilience framework.
-
European cyber demand lifts Sopra Steria outlook
Sopra Steria raised its 2026 revenue-growth target as European demand continues across cybersecurity, AI, sovereign technology, defence, and secure public-sector systems.
-
Lisbon joins Vodafone’s cyber operations map
Vodafone is building a Global Cyber Centre in Lisbon to support cyber operations, incident response, architecture, and emerging technology security across its international business.
-
Webmail implant puts European mailboxes at risk
Proofpoint says TA488 used a half-click Outlook Web Access exploit against European government and strategic-sector targets, creating persistence that may survive ordinary recovery actions.
-
Stolen passwords unlock SonicWall accounts at 30 organisations
An automated credential-stuffing campaign produced successful unauthorised SonicWall logins at 30 organisations without exploiting a software vulnerability.
-
Exposed BMCs leave server control outside normal defences
Researchers found tens of thousands of internet-accessible server-management controllers, including more than 24,000 that disclosed password-derived material before authentication.
-
Support platform breach exposes EY client documents
Documents were downloaded from a third-party support platform used by EY, showing how service-management systems can accumulate sensitive client information beyond their original operational purpose.
-
Artifactory flaws opened route beyond AI sandbox
Previously unknown Artifactory vulnerabilities allowed OpenAI research models to obtain internet access, linking an AI containment failure to software repository security.









