News
-
CREST accredits first AI-enabled penetration-testing providers
CREST has accredited its first ten AI-enabled penetration-testing providers, creating an assurance framework around how artificial intelligence is governed inside professional security testing services.
-
GeoNetwork flaws expose government geoportal backends
Two GeoNetwork vulnerabilities can be chained for unauthenticated remote code execution, with researchers reporting vulnerable internet-facing deployments across government-heavy geospatial infrastructure.
-
Link11 sees fewer but heavier DDoS attacks
Link11 recorded fewer DDoS attacks against its European customer network in early 2026, but peak bandwidth, packet rates, and cumulative attack traffic all increased sharply.
-
G7 urges faster post-quantum migration
G7 cyber authorities are pressing public and private organisations to accelerate post-quantum migration as European policymakers move from broad timelines towards implementation and prioritisation.
-
Pegasus found on Serbian protest activist’s iPhone
Citizen Lab has forensically confirmed Pegasus spyware on a Serbian student activist’s iPhone after an iMessage zero-click attack, while the identity of the operator remains unknown.
-
Dustin shuts systems after unauthorised access
Nordic IT supplier Dustin has shut parts of its internal environment after detecting unauthorised access, with the scope of the incident and any data exposure still under investigation.
-
Public exploit raises Cleo Harmony exposure
Exploit material has been published for a newly disclosed Cleo Harmony authentication weakness, increasing exposure around a managed-file-transfer platform with a history of criminal targeting.
-
SonicWall confirms SMA1000 zero-days under attack
SonicWall says two vulnerabilities affecting SMA1000 secure-access appliances are being actively exploited, including a critical pre-authentication SSRF flaw and a post-authentication code-execution weakness.
-
Lenovo identity flaw exposed Dropbox accounts
A weakness in Lenovo ID email verification allowed attackers to create fraudulent identities and use the federated login relationship to access associated Dropbox accounts without the victims’ passwords.
-
Git trust flaw hits AI coding agents
Manifold Security has disclosed a class of execution flaws across AI coding agents that can allow untrusted repository configuration to run commands before normal workspace trust controls.










