News
-
UK pushes device-level safety controls
The UK government has given Apple and Google three months to implement device-level nudity blocking for children, raising wider questions about endpoint controls, privacy, and platform accountability.
-
Spanish energy SaaS flaw exposes supplier risk
INCIBE says a critical SQL injection flaw in Nemon energy-sector ERP products has been fixed centrally, highlighting specialist SaaS dependency in critical-sector operations.
-
G7 cyber declaration puts resilience first
The G7 cybersecurity declaration links AI security, post-quantum migration, telecoms resilience, and software supply chain transparency to Europe’s widening cyber regulation and infrastructure agenda.
-
Flowise RCE shows AI builder risk
A critical Flowise vulnerability shows how self-hosted AI builder tools can become infrastructure exposure through connectors, credentials, workflow imports, and server-side execution.
-
Microsoft outage exposes identity dependency
Microsoft’s MFA setup and My Sign-Ins incident exposed the operational dependency now carried by cloud identity platforms, enrolment workflows, and access recovery.
-
Red Hat packages hit npm supply chain
A reported Red Hat npm package compromise puts trusted namespaces, CI/CD publishing, cloud credentials, and developer secrets under fresh software supply-chain scrutiny.
-
AUKUS moves undersea resilience into capability
AUKUS partners plan uncrewed undersea systems from 2027, placing cable, pipeline, telecoms, energy, and cloud dependency inside the UK’s cyber-physical resilience agenda.
-
European agencies warn on Russian technology targeting
European intelligence warnings link Russian technology targeting to sanctions pressure, cyber espionage, defence suppliers, dual-use research, and critical infrastructure exposure.
-
France keeps Exchange alert active
France has kept its Exchange Server warning active, keeping exposed mail infrastructure, emergency mitigations, and compromise detection inside the current European risk cycle.
-
France flags enterprise patch pressure
France’s cyber agency has flagged another heavy enterprise patch week, with infrastructure, identity, cloud, application, and security platforms all competing for risk-based remediation.



