News
-
G7 sets cyber resilience priorities
The European Commission has backed a G7 cybersecurity declaration focused on post-quantum migration, AI security, telecoms resilience, SMEs, and software supply chain transparency.
-
France contains Tchap account compromise
French officials say an account compromise affected public conversations in Tchap, the government messaging service, while private encrypted conversations remained protected.
-
ENISA ties SBOM adoption to CRA
ENISA says the Cyber Resilience Act is accelerating SBOM adoption, moving software component transparency deeper into procurement, vulnerability management, supplier assurance, and product-risk governance.
-
EU cyber package moves forward
EU telecoms ministers have advanced work on the Digital Networks Act and Cybersecurity Act 2, bringing infrastructure resilience, ENISA’s role, certification, ICT supply chain risk, and NIS2 simplification into scope.
-
OpenAI expands ChatGPT Lockdown Mode
OpenAI has expanded Lockdown Mode across logged-in ChatGPT users, giving organisations a concrete control for reducing prompt-injection data-exfiltration paths.
-
SolarWinds flaw enters exploitation list
CISA has added a SolarWinds Serv-U denial-of-service vulnerability to its exploited catalogue, putting file-transfer resilience and exposed enterprise infrastructure back under scrutiny.
-
WhatsApp asks court to sanction NSO
Meta says WhatsApp disrupted NSO-linked spear-phishing attempts and is asking a US court to hold the spyware vendor in contempt of a permanent injunction.
-
Shai-Hulud hits scientific Python packages
A new Shai-Hulud wave has compromised science-focused PyPI packages, putting developer secrets, research workflows, and bioinformatics environments back in the software supply chain spotlight.
-
Microsoft repo incident exposes agent risk
A reported Miasma supply chain compromise affecting Microsoft-linked GitHub repositories shows how AI coding tools can turn development environments into credential-exfiltration paths.
-
NHS warns on exploited VPN flaw
NHS England has issued a high-severity alert after Check Point confirmed active exploitation of a critical VPN authentication bypass affecting legacy IKEv1 remote-access configurations.



