News
-
Microsoft confirms ShieldBreak Defender vulnerability
Microsoft has assigned CVE-2026-69414 to ShieldBreak and says it is developing a security update, giving formal vendor recognition to the Defender privilege-escalation issue disclosed last week.
-
Redsquid expands education footprint with ARK deal
Redsquid has acquired ARK ICT, bringing an education-heavy customer base into a UK managed technology group as MSP regulation moves closer.
-
Envelop moves towards full Lloyd’s syndicate
Envelop Risk has received in-principle approval to turn its existing Lloyd’s cyber reinsurance vehicle into a full syndicate from January 2027.
-
UK opens telecoms security regime review
The government has opened the statutory review of Britain’s telecoms security framework, asking whether rules introduced after the 2019 supply chain review are delivering measurable improvements in network security and resilience.
-
GE joins investigation into Cl0p campaign
GE has opened a cyber investigation as Philips confirms a contained server compromise, adding substance — but not full confirmation — to Cl0p’s claims of mass data theft through PTC enterprise software.
-
CRA standards enter formal approval process
Seventeen product-specific cybersecurity standards have entered public enquiry as Europe moves from the Cyber Resilience Act’s legal requirements towards the technical rules manufacturers can use to demonstrate conformity.
-
RingCentral breach data reaches 1.6m addresses
A dataset attributed to RingCentral’s July social-engineering incident contains almost 1.6 million unique email addresses, extending the known public footprint of the breach.
-
Apple spyware alerts reach 110 countries
Apple has sent a fresh wave of mercenary-spyware threat notifications across 110 countries and expanded how high-risk users are warned about targeted attacks.
-
Urgent GeoServer fixes follow exploitation attempts
GeoServer has released urgent security updates for an unauthenticated SQL injection flaw after premature disclosure was followed rapidly by exploitation attempts.
-
Trivy emerges as source of 2,500-org exposure
New analysis indicates that most organisations in a 2,500-plus exposure dataset were caught through the earlier Trivy compromise rather than the short-lived malicious LiteLLM releases.






