Identity & access
-
Passkey research exposes endpoint attack paths
Unit 42 has demonstrated how malware on a Windows endpoint could misuse Google-synchronised passkeys without breaking the cryptography underlying WebAuthn.
-
PNLD confirms police contact data breach
PNLD has confirmed that police and criminal-justice contact information was compromised and published on the dark web, while ruling out exposure of passwords and crime records.
-
academy+ brings cyber training into Staff Skills
academy+ will offer Bob’s Business awareness training and phishing simulation through its Staff Skills course hub as UK training gaps persist.
-
Huntress passes $250m as MSP security scales
Huntress says it now protects 270,000 businesses, deepening its role in managed security delivery for smaller organisations and the MSP channel.
-
Business texting faces tougher Ofcom controls
Ofcom’s new mobile messaging rules place stronger duties on operators and aggregators to block scam messages and control sender ID abuse.
-
Russian zero-click campaign targets Zimbra mail
The NCSC and international partners say Russian state-supported actors used a Zimbra zero-click exploit to steal email data from Western organisations.
-
AI agent rollout strains identity governance
Kocho says AI agents and non-human identities are expanding enterprise access faster than many organisations can govern, monitor, and hold accountable.
-
CNI supplier access emerges as repeated attack route
e2e-assure research says CNI organisations are experiencing repeated supplier compromise and credential theft, while many only review third party access after incidents.
-
Unprotected AI agent bridge exposes command access
Noma Security says a critical Ruflo MCP bridge vulnerability exposed agent tools over HTTP without authentication, allowing command execution inside the container.
-
Webmail implant puts European mailboxes at risk
Proofpoint says TA488 used a half-click Outlook Web Access exploit against European government and strategic-sector targets, creating persistence that may survive ordinary recovery actions.







