Identity & access
-
NHS warns on Citrix exploitation
NHS England Digital says exploitation of a Citrix NetScaler flaw is active, with further attacks assessed as almost certain after public proof of concept code.
-
FortiBleed turns credentials into ransomware risk
Fortinet says the reported FortiBleed activity involves credential reuse and weak authentication, while researchers warn stolen FortiGate access is circulating at scale.
-
Tchap breach tests French messaging
France says a compromised Tchap account exposed public rooms and account data for fewer than 9% of registered users.
-
CERT-EU advisories expose infrastructure risk
CERT-EU’s 2026 advisory stream shows exploited and high-impact flaws across perimeter appliances, identity infrastructure, firewalls, and enterprise network systems.
-
Cursor flaws expose AI coding risk
Cato AI Labs says two critical Cursor IDE vulnerabilities show how prompt injection can escape an agent sandbox and reach developer workstations.
-
Pegasus breach reaches EU spyware oversight
Citizen Lab says a former MEP on the European Parliament’s spyware inquiry was infected with Pegasus, exposing fresh accountability concerns around surveillance, parliamentary confidentiality, and device assurance.
-
MuddyWater widens espionage exposure
WatchGuard’s report on Iran-linked MuddyWater activity points to credential theft, trusted tool abuse, and espionage against high-value organisations.
-
BioShocking exposes AI browser identity risk
LayerX research shows how AI browsers can be manipulated into exposing credentials, code, and signed-in account data.
-
BlueHammer reaches ransomware exposure
CISA’s ransomware link for Microsoft Defender’s BlueHammer flaw changes the operational framing from routine patching to endpoint privilege and containment.
-
GuardFall exposes coding-agent command risk
GuardFall research shows how AI coding agents can be pushed past command safeguards, exposing developer machines, secrets, repositories, and build environments.






