News
-
Polish health breach exposes millions of records
Polish authorities are investigating a major breach at healthcare software provider MyDr after roughly 19 million records linked to patients and more than 12,000 medical facilities were stolen.
-
Microsoft August patch load tops 400 flaws
Microsoft’s August security release covers 421 vulnerabilities, including an exploited Windows privilege-escalation flaw, as enterprise patch volumes remain far above historic norms.
-
Zoom patches meeting-based code execution flaw
Zoom has patched a high-severity annotation vulnerability that could allow one meeting participant to execute code on another participant’s device through network interaction.
-
Plug and Play trust enables SYSTEM attacks
Researchers have demonstrated attack chains that make Windows install signed vendor software for emulated devices, creating routes to SYSTEM privileges through trusted Plug and Play behaviour.
-
Guest access campaign targets Salesforce and ServiceNow
Researchers are tracking a campaign extracting information from exposed Salesforce and ServiceNow portals through legitimate guest-access mechanisms rather than vulnerabilities in either SaaS platform.
-
SharePoint exploitation follows public PoC
Honeypots recorded attempts to exploit a patched SharePoint authentication bypass shortly after public PoC code appeared, while a second flaw completes an unauthenticated remote-code-execution chain.
-
Mindgard raises $30m for AI security expansion
UK-rooted AI security company Mindgard has raised $30 million to expand a platform built around adversarial testing of models, agents, and AI applications.
-
NCSC sets out resilient private 5G priorities
The NCSC is seeking industry input on private 5G systems designed to continue operating through infrastructure failures and cyber incidents, with identity, recovery, and monitoring among its priorities.
-
ICO reprimands ACRO over security failures
The ICO has reprimanded ACRO after finding unclear patching responsibilities and inadequate alert investigation during a prolonged compromise that potentially exposed highly sensitive personal information.
-
Guardsix acquires Logmanager in European security deal
Denmark’s Guardsix is acquiring Czech security company Logmanager, combining log management with SIEM, NDR, and SOAR capabilities in a platform focused on European customers and data residency.








