News
-
TikTok age controls face Ofcom investigation
Ofcom has opened an Online Safety Act investigation into whether TikTok’s age-assurance controls are sufficiently effective at identifying children and limiting their exposure to harmful content.
-
Oracle Payments flaw enters active exploitation
An unauthenticated Oracle E-Business Suite vulnerability capable of compromising the Payments component has been added to the US government’s exploited-vulnerability catalogue.
-
Starland RAT hides inside familiar software
A Russian-speaking criminal operation is disguising malware as familiar administration, database, conferencing, and gaming software, with potential exposure identified in Germany and Romania.
-
ClickLock puts macOS identity stores at risk
A newly documented macOS stealer targets Keychain records, browser sessions, password managers, wallets, and developer credentials, with more than half of identified victims located in Europe.
-
Sandworm-linked activity adopts simpler access routes
CERT-UA says a threat cluster associated with Sandworm is combining trojanised torrent downloads, Signal conversations, fake CAPTCHA prompts, PowerShell, and legitimate remote-access tools.
-
KNX exposure reaches building operations
An actively exploited weakness in KNX building automation can allow a network-connected attacker to lock insufficiently protected devices and leave operators unable to restore normal access.
-
Europe’s critical entity regime enters operation
EU governments have reached the deadline for identifying organisations subject to the Critical Entities Resilience Directive, moving the regime from national preparation into supervision and operational delivery.
-
WINDTRE faces €1.7m penalty after retail breaches
Italy’s privacy regulator has fined WINDTRE after attackers exploited retail support processes and weak credential and certificate controls to access data belonging to more than 365,000 customers.
-
Microsoft 365 phishing moves beyond passwords
Jalisco and OmegaLord target Microsoft 365 identities by abusing device-code authentication and collecting information that can support interception of weaker MFA methods.
-
Gemini CLI ran a live botnet migration
Trend Micro says a Russian-speaking operator used Gemini CLI to migrate, debug, and control a small botnet through natural-language instructions rather than direct technical commands.




