Critical systems
-
ECB stress test finds cyber modelling gaps
The ECB found weaknesses in how eurozone banks connect severe geopolitical and cyber scenarios to capital, liquidity, and credible management action.
-
The energy sector cyber security strategy: why leadership must act now
Rafael Narezzi, CEO of Centrii, argues that the UK’s energy cyber strategy makes resilience a leadership and operational priority, not a deferred compliance task.
-
Russian zero-click campaign targets Zimbra mail
The NCSC and international partners say Russian state-supported actors used a Zimbra zero-click exploit to steal email data from Western organisations.
-
UK education and police support data stolen
Hackers have claimed data from Department for Education and Police National Legal Database-linked systems, exposing public-sector contact records and staff details.
-
Rail supplier portal breach reaches Stadler
A supplier platform incident at Stadler exposed technical data without affecting rail vehicles, production, personal data, or operational systems.
-
CNI supplier access emerges as repeated attack route
e2e-assure research says CNI organisations are experiencing repeated supplier compromise and credential theft, while many only review third party access after incidents.
-
Critical VMware fixes put vCenter under scrutiny
Broadcom has issued critical VMware updates for vCenter and ESX, including two CVSS 9.8 vCenter vulnerabilities with no workaround.
-
Public sector breach reaches education and policing
The Department for Education and the Police National Legal Database were reportedly affected by a cyber attack exposing helpdesk, education, police, and criminal-justice contact data.
-
Lisbon joins Vodafone’s cyber operations map
Vodafone is building a Global Cyber Centre in Lisbon to support cyber operations, incident response, architecture, and emerging technology security across its international business.
-
Exposed BMCs leave server control outside normal defences
Researchers found tens of thousands of internet-accessible server-management controllers, including more than 24,000 that disclosed password-derived material before authentication.









