News
-
Apple renews challenge to UK encryption order
Apple has filed another UK legal challenge over a technical capability notice reportedly seeking access to encrypted iCloud backups belonging to British users.
-
Open VSX removes 77 counterfeit extensions
Open VSX has removed 77 extensions that impersonated legitimate developer tools and transmitted system, repository, and continuous-integration metadata to shared infrastructure.
-
Swiss SharePoint attack exposes 200 accounts
Switzerland’s federal IT office is rebuilding affected SharePoint servers after an attack compromised credentials for roughly 200 user and technical accounts.
-
CrowdStrike sees exploitation within 48 hours
CrowdStrike says 88% of the exploitation it observed involving vulnerabilities with public proof-of-concept code occurred within two days of release.
-
Visa agrees $2.4bn BioCatch acquisition
Visa’s proposed $2.4 billion purchase of BioCatch would bring behavioural and device intelligence used by more than 350 banks into the payment group’s security portfolio.
-
Passkey research exposes endpoint attack paths
Unit 42 has demonstrated how malware on a Windows endpoint could misuse Google-synchronised passkeys without breaking the cryptography underlying WebAuthn.
-
DNA software flaw exposes file integrity risk
Thermo Fisher has patched a high-severity weakness that could permit nearly undetectable modification of human-identification data files, while three unsupported products will receive no update.
-
INC linked to SonicWall exploitation campaign
Researchers have linked INC ransomware activity to attacks exploiting two SonicWall SMA 1000 vulnerabilities, although the vendor has not publicly attributed the campaign.
-
N-central attackers reached managed endpoints
Attackers exploited N-able’s N-central platform, obtained administrative access, and used its remote-control capability to connect to endpoints inside customer-managed environments.
-
ICO monitors AI agents reaching external systems
Britain’s data regulator is monitoring incidents in which OpenAI and Anthropic systems reached external organisations during cyber evaluations.





