News
-
LiteLLM exposure estimate tops 2,500 organisations
CloudSEK estimates that the LiteLLM supply chain compromise potentially exposed more than 2,500 organisations and 434,000 CI/CD pipelines, while stressing that exposure does not establish compromise.
-
European industrial vendors patch critical OT flaws
Siemens, Schneider Electric, and Phoenix Contact have issued August security updates covering critical and high-severity vulnerabilities across industrial, building, and infrastructure technology.
-
Germany moves to widen intelligence cyber powers
Germany’s cabinet has approved draft legislation that would give its intelligence agencies broader cyber, surveillance, and active intervention powers in response to growing hybrid threats.
-
KnowBe4 releases October awareness campaign kit
KnowBe4 has released a free 2026 Cybersecurity Awareness Month package combining training material, tabletop exercises, and campaign resources around phishing, AI threats, data security, and incident reporting.
-
Wesco confirms incident in cloud CRM
Wesco has confirmed unauthorised activity involving its cloud CRM environment while disputing the more serious implications of ExfilSquad’s claimed theft of millions of customer and employee records.
-
Terabit DDoS attacks surge across Cloudflare
Cloudflare says hyper-volumetric DDoS attacks rose sharply in the first half of 2026, with attacks exceeding 1 Tbps becoming substantially more common across its network.
-
Mozilla revokes exposed Firefox signing key
Mozilla has revoked and replaced a GPG subkey used for some Firefox and Thunderbird release artefacts after an unencrypted copy was committed to a private GitHub repository.
-
LexisNexis incident exposes hosting dependency
LexisNexis disconnected three customer-facing services after detecting unusual activity on servers hosted and managed by a third party, disrupting due-diligence, monitoring, and data-feed products.
-
N-central attacks develop into ransomware campaign
Microsoft has linked Storm-1175 to a new ransomware strain deployed during the N-central attack cycle, while assessing — rather than confirming — CVE-2026-18577 as the likely entry route.
-
Poisoned feed compromises BdThemes WordPress plugins
Attackers compromised infrastructure serving a remote data feed used by seven BdThemes WordPress plugins, allowing malicious code to run inside administrators’ browsers without altering plugin files in the official repository.








