Critical systems
-
CubePilot DNS hijack breaks firmware trust
Loss of CubePilot’s domain infrastructure created an opportunity to intercept credentials and undermined confidence in firmware downloaded during the affected period.
-
Operational safety sets the boundary for OT isolation
International guidance urges critical operators to prepare emergency isolation while accounting for the monitoring, communications, and support services required to continue operating safely.
-
Thirty water systems reveal shared OT exposure
A coordinated attack on more than 30 Minnesota water systems has renewed scrutiny of internet-accessible industrial controls, contractor access, and the resilience of smaller infrastructure operators.
-
Minimum viable operations anchor NCSC recovery guidance
New NCSC guidance treats recovery from disruptive cyberattacks as an organisational programme built around minimum viable operations, investigation, legal duties, and controlled rebuilding.
-
UK police data plan concentrates access and accountability
A national police data programme promises faster analysis across forces while concentrating sensitive intelligence, device records, cloud services, and privileged access within shared infrastructure.
-
EV charging enters Germany’s cyber security programme
Germany’s BSI is developing requirements for connected charging infrastructure, where backend services, remote maintenance, payments, and grid integration turn product weaknesses into operational risk.
-
Europe accounts for quarter of ransomware claims
NCC Group recorded 579 European ransomware victims during the second quarter, while industrial organisations, edge infrastructure, and trusted software environments remained prominent targets.
-
VeloCloud zero-day reaches the network control plane
Attackers are exploiting a maximum-severity vulnerability in on-premises VeloCloud Orchestrator systems, exposing the management layer above distributed branch, retail, industrial, and remote-site networks.
-
Malicious models threaten Rockwell simulation users
Four memory-corruption flaws in Arena Simulation can execute code when a user opens a malicious file, placing trusted engineering exchanges under scrutiny.
-
Europe accounts for 31% of exposed ICS
Censys has counted about 138,000 internet-exposed industrial hosts, with Europe representing 31.1%, while publicly reachable AI infrastructure continues to expand.







