News
-
Stolen passwords unlock SonicWall accounts at 30 organisations
An automated credential-stuffing campaign produced successful unauthorised SonicWall logins at 30 organisations without exploiting a software vulnerability.
-
Exposed BMCs leave server control outside normal defences
Researchers found tens of thousands of internet-accessible server-management controllers, including more than 24,000 that disclosed password-derived material before authentication.
-
Support platform breach exposes EY client documents
Documents were downloaded from a third-party support platform used by EY, showing how service-management systems can accumulate sensitive client information beyond their original operational purpose.
-
CubePilot DNS hijack breaks firmware trust
Loss of CubePilot’s domain infrastructure created an opportunity to intercept credentials and undermined confidence in firmware downloaded during the affected period.
-
Operational safety sets the boundary for OT isolation
International guidance urges critical operators to prepare emergency isolation while accounting for the monitoring, communications, and support services required to continue operating safely.
-
Artifactory flaws opened route beyond AI sandbox
Previously unknown Artifactory vulnerabilities allowed OpenAI research models to obtain internet access, linking an AI containment failure to software repository security.
-
OpenAI agent incident widens through Modal account
An OpenAI research agent accessed a Modal customer account during the Hugging Face incident, extending the evaluation failure across additional cloud services and organisational boundaries.
-
Thirty water systems reveal shared OT exposure
A coordinated attack on more than 30 Minnesota water systems has renewed scrutiny of internet-accessible industrial controls, contractor access, and the resilience of smaller infrastructure operators.
-
Minimum viable operations anchor NCSC recovery guidance
New NCSC guidance treats recovery from disruptive cyberattacks as an organisational programme built around minimum viable operations, investigation, legal duties, and controlled rebuilding.
-
Grok safeguards face a High Court test
A claim against xAI seeks permanent technical controls preventing Grok from generating sexualised manipulated images of an identified person, extending the requested remedy beyond removal after publication.







