News
-
ENISA turns CRA readiness towards SMEs
ENISA has published a Cyber Resilience Act maturity model for smaller organisations that manufacture, integrate, or support products with digital elements.
-
EU sets plan for AI cyber risk
The European Commission’s plan links advanced AI, model evaluation, critical infrastructure protection, open-source security, and Europe’s cyber capability base.
-
NCSC warns on Russian router targeting
The NCSC and allied agencies say Russian FSB-linked actors are exploiting weakly configured routers and network devices across critical sectors.
-
UK and EU sanction Russian cyber networks
The coordinated package targets Russian state-linked cyber operators, criminal proxies, Lumma Stealer actors, and information operations tied to attacks across Europe.
-
Passkey vishing targets Entra users
Okta says vishing actors are using fake Microsoft Entra passkey enrolment flows, showing how attackers are adapting to passwordless authentication.
-
Databarracks expands resilience services
Databarracks’ acquisition of Acumen extends its business continuity capabilities as cyber recovery, crisis planning, and operational resilience continue to converge.
-
NCSC opens Cyber Essentials Pathways
The NCSC is widening Cyber Essentials Pathways, giving complex organisations a managed route to show equivalent security outcomes without weakening certification trust.
-
Microsoft pushes faster Windows patching
Microsoft says AI will increase the pace and volume of Windows security updates, forcing organisations to revisit patch windows, deferrals, and change risk.
-
Dialogflow flaw exposes AI isolation risk
A patched Dialogflow CX flaw shows how AI chatbot infrastructure can turn a single agent permission into conversation exposure and cross-agent risk.
-
Claude Code alert becomes trust test
China’s warning over Claude Code should be treated as a disputed product-security and geopolitical trust story, not a confirmed backdoor case.










