Critical systems
-
KAON router flaws expose administrative access
Two vulnerabilities disclosed through CERT Polska can expose administrative credentials or allow command execution on affected KAON routers running older firmware.
-
DDoS attack strains Norway’s shared digital services
A prolonged DDoS attack against Norway’s shared government infrastructure disrupted access to multiple digital services, again testing the resilience of systems used across the public sector.
-
HMRC expands MFA across agent accounts
HMRC has completed another phase of its multi-factor authentication rollout for tax agents ahead of automatic activation across remaining accounts this autumn.
-
DfE restores portals after data breach
The Department for Education has restored two portals after identifying a vulnerability, confirming affected personal data and notifying the Information Commissioner’s Office.
-
France creates frontline cyber unit
France is creating a frontline cyber unit after repeated attacks exposed weaknesses in the state’s ability to respond quickly to serious compromises.
-
Peraton wins $117m Army cyber deal
The US Army has extended Peraton’s work protecting networks across Europe and Africa through 2031 under a cybersecurity and network-operations contract worth about $117 million.
-
France confronts tax systems’ cyber debt
France has acknowledged ageing and vulnerable government IT after its tax breach, accelerating authentication, detection, training, and an audit due in September.
-
Poland’s old health breach raises reporting questions
Prosecutors have confirmed a separate 2024 incident involving MyDr and Poland’s health-entitlement system, raising questions over why central cyber and data authorities apparently did not know about it.
-
France investigates claimed student data theft
France’s Education Ministry is investigating claims that attackers obtained extensive student and teacher records, but the full scope and victim count remain unconfirmed.
-
CameraSwarm compromises 14,500 Dahua cameras
A single operator compromised more than 14,500 Dahua cameras in 35 days, including devices reached through cloud relay infrastructure and persistent access mechanisms.










