Data & infrastructure
-
Oracle PeopleSoft exploit exposes enterprise platforms
Oracle has issued an emergency alert for a critical PeopleSoft flaw after active exploitation linked to ShinyHunters, exposing risk in long-lived enterprise HR, finance, and education platforms.
-
EU warns digital gaps threaten 2030 targets
The Commission’s 2026 Digital Decade report says Europe has made progress, but structural gaps in infrastructure, skills, public services, and business digitalisation remain.
-
France moves spy analytics away from Palantir
France’s DGSI is moving sensitive analytics work from Palantir to ChapsVision, bringing sovereignty, migration risk, and security-critical procurement into practical focus.
-
Novo Nordisk incident tests pharma resilience
Novo Nordisk has confirmed unauthorised access to limited internal IT systems, with separate extortion claims increasing scrutiny of clinical data exposure, pharma resilience, and incident disclosure.
-
Databricks moves further into security data
Databricks’ planned acquisition of Panther reflects enterprise pressure to consolidate security telemetry, automate investigation, and rethink legacy SIEM economics.
-
FortiSandbox reports need careful separation
Critical FortiSandbox vulnerabilities require urgent remediation, while public exploitation claims need to be separated from what Fortinet has confirmed.
-
LiteSpeed flaw exposes shared hosting tenants
Active exploitation of a LiteSpeed cPanel plugin flaw shows how shared hosting environments can turn tenant-level access into root-level operational exposure.
-
Fortra PAM flaw hits privileged access control
A critical Fortra Core Privileged Access Manager flaw shows how defects inside PAM platforms can weaken controls built to contain administrator risk.
-
Splunk flaw reaches the telemetry layer
A critical Splunk Enterprise flaw shows how security monitoring platforms can become infrastructure risk when unauthenticated access reaches supporting data services.
-
Malicious plugins put AI keys at risk
A JetBrains Marketplace campaign shows how developer plugins, AI assistants, and API keys can become part of the software supply chain risk surface.







