News
-
UK police data plan concentrates access and accountability
A national police data programme promises faster analysis across forces while concentrating sensitive intelligence, device records, cloud services, and privileged access within shared infrastructure.
-
Sovereign SASE takes shape in German datacentres
Zscaler’s security platform is now available on STACKIT infrastructure in Germany, combining European data residency with a jointly operated security service for regulated organisations.
-
EV charging enters Germany’s cyber security programme
Germany’s BSI is developing requirements for connected charging infrastructure, where backend services, remote maintenance, payments, and grid integration turn product weaknesses into operational risk.
-
GitHub narrows access to its bug bounty
GitHub has lowered public bounty payments while formalising a higher-paying invitation-only programme, citing growing volumes of low-quality and AI-generated vulnerability reports.
-
Cyber-specific model joins Microsoft remediation system
Microsoft’s first dedicated cyber model will identify, validate, prioritise, and patch software vulnerabilities inside a controlled multi-agent system, with access restricted because of its dual-use capability.
-
Open alliance assembles AI security stack
Nvidia, SAP, Siemens, Microsoft, and other technology companies have formed an alliance to develop open tools for AI-agent identity, testing, monitoring, vulnerability discovery, and governance.
-
GitLab exploit emerges from an understated patch
Researchers have published a working GitLab remote code execution chain after the relevant dependency update shipped without a CVE, severity rating, or prominent security classification.
-
Spyware claim clears UK immunity hurdle
A divided Supreme Court has ruled that foreign-state hacking of a computer in Britain can constitute an act in the UK, allowing a civil spyware claim against Bahrain to proceed.
-
TeamCity flaw puts build systems at risk
An unauthenticated vulnerability affecting every TeamCity On-Premises version can give remote attackers command execution on servers holding source code, credentials, artefacts, and deployment access.
-
September reporting deadline comes into focus under CRA guidance
European Commission guidance clarifies product scope, support periods, open source treatment, risk assessments, and reporting duties before the Cyber Resilience Act’s first operational deadline.






