News
-
Unprotected AI agent bridge exposes command access
Noma Security says a critical Ruflo MCP bridge vulnerability exposed agent tools over HTTP without authentication, allowing command execution inside the container.
-
Rails image flaw puts application secrets at risk
Rails has fixed CVE-2026-66066, an Active Storage vulnerability that may allow arbitrary file reads and remote code execution in affected applications.
-
Critical VMware fixes put vCenter under scrutiny
Broadcom has issued critical VMware updates for vCenter and ESX, including two CVSS 9.8 vCenter vulnerabilities with no workaround.
-
Exploited Cisco flaw exposes firewall management
Cisco says attackers are exploiting a static credential flaw in Secure Firewall Management Center and has urged customers to patch and rotate credentials, keys, and certificates.
-
Public sector breach reaches education and policing
The Department for Education and the Police National Legal Database were reportedly affected by a cyber attack exposing helpdesk, education, police, and criminal-justice contact data.
-
Cloud providers enter UK finance resilience regime
UK financial regulators are now directly overseeing the first critical third parties, bringing major cloud providers inside a system-wide operational resilience framework.
-
European cyber demand lifts Sopra Steria outlook
Sopra Steria raised its 2026 revenue-growth target as European demand continues across cybersecurity, AI, sovereign technology, defence, and secure public-sector systems.
-
Lisbon joins Vodafone’s cyber operations map
Vodafone is building a Global Cyber Centre in Lisbon to support cyber operations, incident response, architecture, and emerging technology security across its international business.
-
Webmail implant puts European mailboxes at risk
Proofpoint says TA488 used a half-click Outlook Web Access exploit against European government and strategic-sector targets, creating persistence that may survive ordinary recovery actions.
-
Cyber remains undefined in England’s technical education plan
England’s planned technical pathways for pupils from age 14 include AI and digital subjects, although the place of cyber security within the curriculum has not been defined.










