Identity & access
-
Microsoft patch load tests enterprise discipline
NHS England has highlighted Microsoft’s June security updates, including an exploited Defender flaw and critical remote code execution vulnerabilities.
-
Ivanti Sentry flaws expose security gateways
NHS England and CERT-EU have warned organisations to patch critical Ivanti Sentry vulnerabilities after exploitation of one flaw was reported in the wild.
-
Spain arrests suspect over state personnel doxing
Spanish police have arrested a suspect accused of leaking personal data linked to sensitive state institutions, including cyber, police, prosecution, and tax bodies.
-
CERT-EU warns on exploited Netlogon flaw
CERT-EU says a critical Windows Netlogon vulnerability affecting domain controllers is being exploited, putting enterprise identity infrastructure under immediate pressure.
-
Another reminder that retired protocols are an active risk
Check Point’s exploited VPN flaw shows how deprecated remote access protocols can remain live inside security infrastructure long after retirement should have removed them.
-
FCA warns agentic AI could scale financial crime
The FCA’s 2026 horizon scan warns that agentic AI could automate fraud, phishing, vulnerability discovery, synthetic identities, and market manipulation.
-
SAP patches critical NetWeaver flaws
SAP’s June security patch day includes critical NetWeaver, Commerce Cloud, and Data Hub flaws, led by a 9.9-rated SAML authentication issue in NetWeaver AS ABAP.
-
France contains Tchap account compromise
French officials say an account compromise affected public conversations in Tchap, the government messaging service, while private encrypted conversations remained protected.
-
WhatsApp asks court to sanction NSO
Meta says WhatsApp disrupted NSO-linked spear-phishing attempts and is asking a US court to hold the spyware vendor in contempt of a permanent injunction.
-
NHS warns on exploited VPN flaw
NHS England has issued a high-severity alert after Check Point confirmed active exploitation of a critical VPN authentication bypass affecting legacy IKEv1 remote-access configurations.







