News
-
SharePoint flaw moves into ransomware attacks
CISA has changed the status of an already exploited SharePoint Server vulnerability to confirm its use in ransomware campaigns, raising the consequence for organisations still running vulnerable on-premises systems.
-
Cisco VPN flaw crashes exposed firewalls
Cisco says attackers are actively exploiting a flaw in ASA and FTD remote-access services that can force vulnerable firewalls to reload, with fixed software available and no workaround.
-
Windows zero-day hits European defence targets
Microsoft has patched a Windows privilege-escalation zero-day that Check Point says was exploited in a Lazarus-linked campaign targeting defence, aerospace, and aviation organisations, including victims in Europe.
-
SAP patches critical Commerce Cloud flaw
SAP’s August security release fixes a maximum-severity authorisation flaw in Commerce Cloud alongside critical vulnerabilities affecting manufacturing and core enterprise platforms.
-
DeadLock ransomware builds resilience around extortion
DeadLock has concentrated more than half of its claimed victims in Europe while using decentralised communications and leak infrastructure intended to make parts of its extortion operation harder to disrupt.
-
GitHub broadens Dependabot malware alerts
GitHub has expanded Dependabot’s malicious-package coverage beyond npm, allowing dependencies across most supported ecosystems to be matched against a wider pool of known malware advisories.
-
Entra will treat device credentials as MFA
Microsoft Entra will recognise Windows Hello for Business and macOS Platform SSO as standalone multifactor authentication in supported scenarios, removing some additional authentication-method prompts.
-
Poisoned logs can redirect privileged AI agents
DEF CON research shows how attacker-controlled information inside trusted operational systems can influence AI agents that have permission to change cloud and security environments.
-
OpenAI widens controlled cyber-model access
OpenAI has launched GPT‑5.6‑Cyber through an expanded Daybreak programme, giving approved researchers access to a model deliberately trained to answer substantially more advanced dual-use cyber requests.
-
Ransomware exploits SonicWall remote-access flaws
CISA says two previously exploited SonicWall SMA1000 vulnerabilities are now associated with ransomware activity, escalating weaknesses in infrastructure that controls privileged remote access.






