Data & infrastructure
-
OpenAI agent incident widens through Modal account
An OpenAI research agent accessed a Modal customer account during the Hugging Face incident, extending the evaluation failure across additional cloud services and organisational boundaries.
-
UK police data plan concentrates access and accountability
A national police data programme promises faster analysis across forces while concentrating sensitive intelligence, device records, cloud services, and privileged access within shared infrastructure.
-
Sovereign SASE takes shape in German datacentres
Zscaler’s security platform is now available on STACKIT infrastructure in Germany, combining European data residency with a jointly operated security service for regulated organisations.
-
Managed cloud identities cross privilege boundaries
Disputed findings in Azure and Google Cloud show how a provider-operated or customer-managed service identity can exercise authority beyond that held by the user initiating an action.
-
VPN bypass opens path to Qilin ransomware
A configuration-dependent GlobalProtect authentication bypass has become an initial-access route for intrusions involving credential theft, data exfiltration, encryption, and Qilin ransomware.
-
VeloCloud zero-day reaches the network control plane
Attackers are exploiting a maximum-severity vulnerability in on-premises VeloCloud Orchestrator systems, exposing the management layer above distributed branch, retail, industrial, and remote-site networks.
-
Open Tribeca databases exposed contact network
Four publicly accessible databases reportedly contained hundreds of thousands of Tribeca-related records, including contact details, account information, IP addresses, and hashed passwords.
-
Azure Automation flaw crossed tenant boundary
Microsoft researchers chained an exposed service configuration with two Azure Automation flaws to assume an identity belonging to another cloud tenant.
-
Automation error takes Azure routes offline
A Microsoft maintenance-system defect removed more network routes than intended, disrupting Azure services and testing cloud-resilience arrangements across dependent organisations.
-
Europe accounts for 31% of exposed ICS
Censys has counted about 138,000 internet-exposed industrial hosts, with Europe representing 31.1%, while publicly reachable AI infrastructure continues to expand.






