Critical systems
-
Root access chain reaches Siemens industrial switches
Three vulnerabilities affecting Siemens RUGGEDCOM ROX II switches can be chained to expose sensitive files, obtain root privileges, and establish persistence across a reboot.
-
Iran-linked attacks widen across industrial controllers
US authorities have expanded an alert on Iran-affiliated activity to include Siemens and Schneider controllers widely deployed across European infrastructure.
-
Stadler breach stops short of rail operations
Attackers stole technical documents through a supplier platform, but Stadler says its production systems, trains, and internal IT remained unaffected.
-
Property deals freeze after Romania registry attack
A cyberattack on Romania’s national land registry disrupted property sales, mortgage processing, and legal work while recovery teams checked that authoritative ownership records remained intact.
-
ONS cyber FOI exposes reporting gaps
An ONS freedom of information response shows how retention limits and security exemptions can narrow public visibility of cyber exposure.
-
Craneware breach tests healthcare supplier trust
UK-listed healthcare technology supplier Craneware says unauthorised access affected part of its data environment, with employee, customer, and partner records accessed and exfiltrated.
-
Germany builds a federal cyber control layer
CyberGovSecure will centralise cyber governance across Germany’s federal administration, with workstreams covering configuration, vulnerability management, logging, detection, and mobile device control.
-
Hospitals get new EU cyber buying guide
ENISA’s first health action plan deliverable pushes hospital cybersecurity into procurement, supplier selection, contracts, and lifecycle management.
-
Treasury report prices financial cyber disruption
HM Treasury research places cyber among the financial system’s leading risks and models extreme annual ransomware losses of hundreds of millions of pounds for larger organisations.
-
TfL attackers jailed after £29m recovery
Two men have received five-and-a-half-year prison sentences for the Transport for London intrusion, which disabled 148 systems and forced password resets for 27,000 employees.









