Data & infrastructure
-
Microsoft repos restored after GitHub removals
Microsoft-owned GitHub repositories were temporarily removed while potential malicious content was investigated, disrupting Azure Functions deployment workflows and exposing CI/CD dependency risk.
-
ServiceNow investigates customer data exposure
ServiceNow has reportedly warned affected customers after unauthenticated access through a vulnerable API endpoint allowed attackers to query customer instance data.
-
NHS flags critical Veeam flaw
NHS England has warned that a critical Veeam Backup & Replication vulnerability could allow authenticated domain users to execute remote code on affected backup servers.
-
EU cyber package moves forward
EU telecoms ministers have advanced work on the Digital Networks Act and Cybersecurity Act 2, bringing infrastructure resilience, ENISA’s role, certification, ICT supply chain risk, and NIS2 simplification into scope.
-
OpenAI expands ChatGPT Lockdown Mode
OpenAI has expanded Lockdown Mode across logged-in ChatGPT users, giving organisations a concrete control for reducing prompt-injection data-exfiltration paths.
-
SolarWinds flaw enters exploitation list
CISA has added a SolarWinds Serv-U denial-of-service vulnerability to its exploited catalogue, putting file-transfer resilience and exposed enterprise infrastructure back under scrutiny.
-
Shai-Hulud hits scientific Python packages
A new Shai-Hulud wave has compromised science-focused PyPI packages, putting developer secrets, research workflows, and bioinformatics environments back in the software supply chain spotlight.
-
Microsoft repo incident exposes agent risk
A reported Miasma supply chain compromise affecting Microsoft-linked GitHub repositories shows how AI coding tools can turn development environments into credential-exfiltration paths.
-
NHS warns on exploited VPN flaw
NHS England has issued a high-severity alert after Check Point confirmed active exploitation of a critical VPN authentication bypass affecting legacy IKEv1 remote-access configurations.
-
UK pushes device-level safety controls
The UK government has given Apple and Google three months to implement device-level nudity blocking for children, raising wider questions about endpoint controls, privacy, and platform accountability.


