News
-
Fortinet patches two authentication weaknesses
Fortinet has fixed separate authentication weaknesses in FortiWeb and FortiManager, including a configuration-dependent FortiWeb administrator bypass and a FortiManager device-impersonation flaw.
-
Ivanti fixes remotely reachable Endpoint Manager flaws
Ivanti has patched three high-severity Endpoint Manager vulnerabilities, including an unauthenticated agent denial-of-service flaw and a credential exposure requiring a man-in-the-middle position.
-
Adobe patches critical Commerce authorisation flaw
Adobe has fixed a critical unauthenticated authorisation vulnerability in Commerce and Magento Open Source that can allow privilege escalation without administrator access or user interaction.
-
Back-to-school identity sprawl raises cyber exposure
Rapid account provisioning, new devices and expanding EdTech integrations are increasing identity-governance pressure across UK education as schools and colleges prepare for the new academic year.
-
Ransomware fragments as data theft gains ground
Check Point recorded 2,139 ransomware leak-site victims in Q2 2026 as active groups reached a record 93 and smaller affiliate-driven operations gained ground.
-
SEPPmail acquires Denmark’s CyberPilot
Swiss email-security company SEPPmail has acquired Danish awareness-training provider CyberPilot as it builds a broader European platform around technical controls, phishing simulation and human risk.
-
Trezor customers exposed through ShipMonk breach
A breach at logistics provider ShipMonk exposed contact and shipping information belonging to 13,689 Trezor customers across the UK, Europe and other markets.
-
Dutch NCSC confirms macOS Screen Sharing attacks
The Dutch NCSC has observed attackers exploiting CVE-2026-65400 against internet-reachable Macs, gaining root access and installing cryptomining software.
-
VMware vCenter flaw moves into active exploitation
Incident responders have linked successful compromises across 47 countries to the critical VMware vCenter flaw CVE-2026-59310, only days after Broadcom disclosed and patched it.
-
Cl0p claims Philips and Shell data theft
Philips has contained an attempted compromise and Shell is investigating a possible incident after Cl0p claimed to have stolen engineering and project information from both companies.










