Critical systems
-
Germany builds a federal cyber control layer
CyberGovSecure will centralise cyber governance across Germany’s federal administration, with workstreams covering configuration, vulnerability management, logging, detection, and mobile device control.
-
Hospitals get new EU cyber buying guide
ENISA’s first health action plan deliverable pushes hospital cybersecurity into procurement, supplier selection, contracts, and lifecycle management.
-
Treasury report prices financial cyber disruption
HM Treasury research places cyber among the financial system’s leading risks and models extreme annual ransomware losses of hundreds of millions of pounds for larger organisations.
-
TfL attackers jailed after £29m recovery
Two men have received five-and-a-half-year prison sentences for the Transport for London intrusion, which disabled 148 systems and forced password resets for 27,000 employees.
-
Sandworm-linked activity adopts simpler access routes
CERT-UA says a threat cluster associated with Sandworm is combining trojanised torrent downloads, Signal conversations, fake CAPTCHA prompts, PowerShell, and legitimate remote-access tools.
-
KNX exposure reaches building operations
An actively exploited weakness in KNX building automation can allow a network-connected attacker to lock insufficiently protected devices and leave operators unable to restore normal access.
-
Europe’s critical entity regime enters operation
EU governments have reached the deadline for identifying organisations subject to the Critical Entities Resilience Directive, moving the regime from national preparation into supervision and operational delivery.
-
Old UEFI signatures reopen Secure Boot
Eleven old but validly signed bootloaders could be introduced onto modern systems to bypass Secure Boot, extending software supply chain risk beneath the operating system.
-
No patch yet for Siemens PLC simulator
Every version of SIMATIC S7-PLCSIM Advanced is affected by a denial-of-service weakness, leaving industrial operators dependent on network restrictions while Siemens prepares corrected releases.
-
Credential flaw reaches EcoStruxure security console
Schneider Electric has patched a high-severity weakness that could allow a privileged local attacker to alter credentials used to administer cybersecurity policies across electrical operational technology.








