Identity & access
-
Langflow attacks expose AI workflow risk
Observed exploitation of Langflow vulnerabilities shows how self-hosted AI workflow tools can expose API keys, cloud secrets, and agent infrastructure before governance catches up.
-
TfL cyber attackers plead guilty
Two men have pleaded guilty over the 2024 Transport for London cyberattack, creating a rare accountability moment after a major public transport incident.
-
Operation Endgame disrupts malware infrastructure
European authorities have disrupted SocGholish, StealC, and Amadey infrastructure, targeting malware services used for initial access, credential theft, and follow-on cybercrime.
-
Cisco flaw reaches communications layer
An exploited Cisco Unified Communications Manager flaw exposes how collaboration and telephony platforms can become privileged infrastructure risk.
-
VS Code tasks expose developer risk
JFrog says hijacked npm packages used hidden VS Code tasks and blockchain dead drops to deploy a credential and cryptocurrency stealer.
-
Signal phishing shifts to recovery keys
US agencies say Russian intelligence-linked actors are trying to obtain Signal backup recovery keys, creating account takeover and historic message exposure risk for high-value targets.
-
Hotel phishing campaign targets Europe
Microsoft says hospitality organisations in Europe and Asia are being targeted with photo-themed phishing that delivers a persistent Node.js implant.
-
Europol disrupts malware credential pipeline
European law enforcement has disrupted infrastructure linked to SocGholish, Amadey, and StealC, exposing a credential theft pipeline that feeds ransomware, fraud, and enterprise compromise.
-
NCSC warns on Fortinet VPN exposure
UK organisations using Fortinet SSL VPNs have been urged to investigate after leaked credentials were linked to targeting of internet-facing firewalls and gateways.
-
Cisco ISE flaws test identity resilience
Cisco ISE and ISE-PIC vulnerabilities expose how identity infrastructure can become operationally sensitive when access control systems require urgent patching.








