News
-
Apollo breach exposes cloud identity risk
Apollo Global Management says a social-engineering incident gave attackers access to cloud platforms for several days and exposed sensitive personal information.
-
Device trust blocks ReliaQuest breach escalation
A ReliaQuest employee surrendered credentials and approved an MFA prompt during a vishing attack, but device-trust controls prevented the attacker reaching business applications.
-
Oracle flaw moves into active exploitation
A critical Oracle HTTP Server and WebLogic proxy vulnerability first patched in January is now confirmed as actively exploited and has entered CISA’s priority catalogue.
-
miniOrange SAML flaws expose WordPress admins
Attackers are probing miniOrange SAML authentication flaws that can allow forged identity assertions or malformed signatures to produce administrator access to WordPress sites.
-
Zimbra flaw moves into active exploitation
Attackers are exploiting a Zimbra Collaboration command-injection vulnerability that can allow unauthenticated remote command execution on servers with specific SNMP functionality enabled.
-
Cyberattack shuts UK generator for four days
A cyber incident forced a small UK electricity generator offline for four days, although the government says there was no threat to the wider energy system.
-
Industrial ransomware rises across most regions
Kaspersky telemetry shows ransomware detections rising across most industrial regions in Q2 2026 even as the overall share of ICS computers encountering malicious objects declined.
-
KAON router flaws expose administrative access
Two vulnerabilities disclosed through CERT Polska can expose administrative credentials or allow command execution on affected KAON routers running older firmware.
-
EU details AI Act enforcement powers
The European Commission has detailed how AI Act investigations, model evaluations, inspections and fines will work as key enforcement provisions take effect across the EU.
-
Swiss cyber reporting exposes enterprise attack patterns
Switzerland received 200 mandatory critical-infrastructure cyber reports in the first half of 2026, alongside rising Microsoft 365 phishing and persistent ransomware activity.










