News
-
Ransomware claims rise as confirmations lag
Comparitech recorded 799 ransomware incidents and criminal claims in July, but only 51 had been confirmed by affected organisations when its analysis was published.
-
Supplier account opens route into Żabka systems
Attackers used an external provider’s account to access Żabka resources supporting its franchise network, although payments, shops, consumer services, and Żappka data remained unaffected.
-
Logistics breach stalls De Bijenkorf orders
Unauthorised access at a De Bijenkorf logistics provider has delayed orders, returns, and refunds, with customer contact and purchase information potentially exposed.
-
Hungarian Treasury isolates farm systems after attack
Hungary has isolated systems administering agricultural and rural-development funding after a cyberattack encrypted files, while claims of data theft and an exposed WebLogic server remain under investigation.
-
AvePoint links data classification to recovery
AvePoint is linking continuously updated sensitivity classification with sequenced recovery, although its new Kinetic Classification capability remains in private preview.
-
AI features in 55% of African cybercrime
INTERPOL says AI featured in 55% of reported cybercrime cases across Africa, while fragmented laws and weak cross-border data sharing continue to impede investigations.
-
TP-Link provisioning flaws expose network control
Fifteen newly disclosed vulnerabilities show how weaknesses in automated TP-Link device enrolment could be chained against controllers, cloud services, credentials, and managed network infrastructure.
-
ChainDrop worm compromises 400 npm packages
A self-propagating credential-stealing worm has reached more than 400 npm packages, turning compromised publishing identities into a mechanism for further software supply chain infection.
-
UK relaunches £350,000 security innovation call
UK Defence Innovation has opened a security competition offering projects up to £350,000 to develop prototypes addressing cyber resilience, protective security, and Home Office priorities.
-
Greatness adds device-code phishing to service
The Greatness phishing service has added device-code and OAuth-consent attacks, expanding beyond credential interception into token-centred Microsoft 365 account compromise.









