Identity & access
-
CERT-EU warns on exploited Netlogon flaw
CERT-EU says a critical Windows Netlogon vulnerability affecting domain controllers is being exploited, putting enterprise identity infrastructure under immediate pressure.
-
Another reminder that retired protocols are an active risk
Check Point’s exploited VPN flaw shows how deprecated remote access protocols can remain live inside security infrastructure long after retirement should have removed them.
-
FCA warns agentic AI could scale financial crime
The FCA’s 2026 horizon scan warns that agentic AI could automate fraud, phishing, vulnerability discovery, synthetic identities, and market manipulation.
-
SAP patches critical NetWeaver flaws
SAP’s June security patch day includes critical NetWeaver, Commerce Cloud, and Data Hub flaws, led by a 9.9-rated SAML authentication issue in NetWeaver AS ABAP.
-
France contains Tchap account compromise
French officials say an account compromise affected public conversations in Tchap, the government messaging service, while private encrypted conversations remained protected.
-
WhatsApp asks court to sanction NSO
Meta says WhatsApp disrupted NSO-linked spear-phishing attempts and is asking a US court to hold the spyware vendor in contempt of a permanent injunction.
-
NHS warns on exploited VPN flaw
NHS England has issued a high-severity alert after Check Point confirmed active exploitation of a critical VPN authentication bypass affecting legacy IKEv1 remote-access configurations.
-
Microsoft outage exposes identity dependency
Microsoft’s MFA setup and My Sign-Ins incident exposed the operational dependency now carried by cloud identity platforms, enrolment workflows, and access recovery.
-
Belgium warns Netlogon flaw is exploited
Belgium says a critical Netlogon flaw is now being exploited, putting domain-controller patching, compromise detection, and Active Directory recovery at the centre of enterprise identity risk.
-
Residential proxies are breaking trusted traffic
A Dutch botnet takedown shows how residential proxy abuse is weakening old assumptions about trusted traffic, with consequences for IP reputation, geolocation, identity controls, and fraud detection.







