Data & infrastructure
-
EU cyber package moves forward
EU telecoms ministers have advanced work on the Digital Networks Act and Cybersecurity Act 2, bringing infrastructure resilience, ENISA’s role, certification, ICT supply chain risk, and NIS2 simplification into scope.
-
OpenAI expands ChatGPT Lockdown Mode
OpenAI has expanded Lockdown Mode across logged-in ChatGPT users, giving organisations a concrete control for reducing prompt-injection data-exfiltration paths.
-
SolarWinds flaw enters exploitation list
CISA has added a SolarWinds Serv-U denial-of-service vulnerability to its exploited catalogue, putting file-transfer resilience and exposed enterprise infrastructure back under scrutiny.
-
Shai-Hulud hits scientific Python packages
A new Shai-Hulud wave has compromised science-focused PyPI packages, putting developer secrets, research workflows, and bioinformatics environments back in the software supply chain spotlight.
-
Microsoft repo incident exposes agent risk
A reported Miasma supply chain compromise affecting Microsoft-linked GitHub repositories shows how AI coding tools can turn development environments into credential-exfiltration paths.
-
NHS warns on exploited VPN flaw
NHS England has issued a high-severity alert after Check Point confirmed active exploitation of a critical VPN authentication bypass affecting legacy IKEv1 remote-access configurations.
-
UK pushes device-level safety controls
The UK government has given Apple and Google three months to implement device-level nudity blocking for children, raising wider questions about endpoint controls, privacy, and platform accountability.
-
Spanish energy SaaS flaw exposes supplier risk
INCIBE says a critical SQL injection flaw in Nemon energy-sector ERP products has been fixed centrally, highlighting specialist SaaS dependency in critical-sector operations.
-
Flowise RCE shows AI builder risk
A critical Flowise vulnerability shows how self-hosted AI builder tools can become infrastructure exposure through connectors, credentials, workflow imports, and server-side execution.
-
Microsoft outage exposes identity dependency
Microsoft’s MFA setup and My Sign-Ins incident exposed the operational dependency now carried by cloud identity platforms, enrolment workflows, and access recovery.


