Data & infrastructure
-
Red Hat packages hit npm supply chain
A reported Red Hat npm package compromise puts trusted namespaces, CI/CD publishing, cloud credentials, and developer secrets under fresh software supply-chain scrutiny.
-
AUKUS moves undersea resilience into capability
AUKUS partners plan uncrewed undersea systems from 2027, placing cable, pipeline, telecoms, energy, and cloud dependency inside the UK’s cyber-physical resilience agenda.
-
France keeps Exchange alert active
France has kept its Exchange Server warning active, keeping exposed mail infrastructure, emergency mitigations, and compromise detection inside the current European risk cycle.
-
France flags enterprise patch pressure
France’s cyber agency has flagged another heavy enterprise patch week, with infrastructure, identity, cloud, application, and security platforms all competing for risk-based remediation.
-
Belgium warns Netlogon flaw is exploited
Belgium says a critical Netlogon flaw is now being exploited, putting domain-controller patching, compromise detection, and Active Directory recovery at the centre of enterprise identity risk.
-
MPs press FCA over Palantir data risk
The FCA says its Palantir trial uses encrypted data under regulator control, but MPs and campaigners want clearer answers on US legal exposure, procurement dependency, and public-sector AI governance.
-
Residential proxies are breaking trusted traffic
A Dutch botnet takedown shows how residential proxy abuse is weakening old assumptions about trusted traffic, with consequences for IP reputation, geolocation, identity controls, and fraud detection.
-
The security stack now needs its own controls
Recent Fortinet and Trend Micro disclosures show how endpoint management and security platforms have become privileged infrastructure, requiring governance that goes beyond patching and product trust.
-
Microsoft exposes npm dependency campaign
Microsoft has identified 33 malicious npm packages abusing dependency confusion. The campaign profiled developer environments and targeted the weak boundary between internal code and public package registries.
-
GlobalProtect flaw is under attack
Palo Alto Networks has updated its GlobalProtect vulnerability advisory again. The affected PAN-OS issue can allow unauthorised VPN connections in specific configurations and is now marked as attacked.







