News
-
Researchers detail closed ChatGPT cross-account channel
Check Point has disclosed a now-closed ChatGPT cross-account channel that used shared internal package infrastructure to relay hidden tasks and data between isolated execution environments.
-
Microsoft fixes two exploited Windows zero-days
Microsoft’s September Patch Tuesday fixes two exploited privilege-escalation zero-days amid its largest monthly security release, although third-party counts differ slightly by methodology.
-
UK space strategy puts resilience first
The UK will develop a resilient national satellite communications system as a £7.8 billion space strategy brings infrastructure, defence, procurement, and economic security under one plan.
-
CRA reporting platform enters operational phase
EU manufacturers face new 24-hour and 72-hour reporting deadlines from 11 September as the Cyber Resilience Act’s Single Reporting Platform goes live.
-
Berlin breach deepens with credential leak
Berlin has confirmed that a second package of stolen government data contained access credentials, prompting tighter controls and temporary restrictions on some administrative systems.
-
Researchers redraw North Korea’s cyber structure
Sekoia and Kudelski Security have divided the old Lazarus umbrella into six operational clusters spanning espionage, financial operations, cryptocurrency theft, and fraudulent IT-worker activity.
-
France arrests suspects in ZeroBytes investigation
French prosecutors have confirmed arrests in the ZeroBytes investigation following attacks including the compromise of the national tax administration.
-
SAP fixes critical enterprise software flaws
SAP’s September security release includes a CVSS 10.0 memory-corruption flaw and three other critical vulnerabilities across NetWeaver, cloud application components, and SAP GUI for Java.
-
Bavarian utility keeps services running through attack
Stadtwerke Landsberg kept electricity, water, heating, fibre, and other services operating after attackers encrypted central IT systems, while forensic work continues over possible data exposure.
-
Endpoint security PoCs expose privileged attack surface
Public proof-of-concept exploits targeting CrowdStrike Falcon and Avast, alongside a separate Nvidia memory-corruption disclosure, are drawing attention to vulnerabilities inside highly privileged endpoint components.










