Data & infrastructure
-
ICO complaints duty raises accountability
UK organisations must now have a data protection complaints process, adding a formal accountability layer around data handling, security concerns, and post-incident evidence.
-
NCSC warns on Fortinet VPN exposure
UK organisations using Fortinet SSL VPNs have been urged to investigate after leaked credentials were linked to targeting of internet-facing firewalls and gateways.
-
NGINX flaws widen patch pressure
Fresh NGINX vulnerabilities affecting gateway, open source, and commercial versions put infrastructure visibility and patch coordination back in focus.
-
Cisco ISE flaws test identity resilience
Cisco ISE and ISE-PIC vulnerabilities expose how identity infrastructure can become operationally sensitive when access control systems require urgent patching.
-
Splunk AI flaw hits privileged tooling
A critical Splunk AI Toolkit vulnerability shows how AI add-ons inside monitoring platforms can introduce execution risk into trusted security environments.
-
Barracuda targets email attacks after delivery
Barracuda has launched Integrated Email Protection for Microsoft 365 and Google Workspace, combining AI-assisted detection, verdict explanation, quarantine control, and message clawback.
-
Databricks deal pushes security lakehouse model
Databricks has agreed to acquire Panther, extending its push into security operations as AI, data scale, and SIEM costs reshape enterprise detection and response.
-
Rockwell advisories expose OT patching pressure
CISA has published several Rockwell Automation advisories, including flaws affecting controllers and industrial software, highlighting the operational challenge of patching industrial systems.
-
Copilot flaw exposes AI data risk
Varonis says Microsoft patched a critical Copilot vulnerability chain that could have allowed sensitive Microsoft 365 data to be extracted through a crafted link.
-
Fortinet campaign revives edge credential risk
Fortinet says a credential-harvesting campaign is targeting firewall and VPN devices, exposing how old access data and edge infrastructure remain live enterprise risk.









