News
-
OpenAI expands ChatGPT Lockdown Mode
OpenAI has expanded Lockdown Mode across logged-in ChatGPT users, giving organisations a concrete control for reducing prompt-injection data-exfiltration paths.
-
SolarWinds flaw enters exploitation list
CISA has added a SolarWinds Serv-U denial-of-service vulnerability to its exploited catalogue, putting file-transfer resilience and exposed enterprise infrastructure back under scrutiny.
-
WhatsApp asks court to sanction NSO
Meta says WhatsApp disrupted NSO-linked spear-phishing attempts and is asking a US court to hold the spyware vendor in contempt of a permanent injunction.
-
Shai-Hulud hits scientific Python packages
A new Shai-Hulud wave has compromised science-focused PyPI packages, putting developer secrets, research workflows, and bioinformatics environments back in the software supply chain spotlight.
-
Microsoft repo incident exposes agent risk
A reported Miasma supply chain compromise affecting Microsoft-linked GitHub repositories shows how AI coding tools can turn development environments into credential-exfiltration paths.
-
NHS warns on exploited VPN flaw
NHS England has issued a high-severity alert after Check Point confirmed active exploitation of a critical VPN authentication bypass affecting legacy IKEv1 remote-access configurations.
-
UK pushes device-level safety controls
The UK government has given Apple and Google three months to implement device-level nudity blocking for children, raising wider questions about endpoint controls, privacy, and platform accountability.
-
Spanish energy SaaS flaw exposes supplier risk
INCIBE says a critical SQL injection flaw in Nemon energy-sector ERP products has been fixed centrally, highlighting specialist SaaS dependency in critical-sector operations.
-
G7 cyber declaration puts resilience first
The G7 cybersecurity declaration links AI security, post-quantum migration, telecoms resilience, and software supply chain transparency to Europe’s widening cyber regulation and infrastructure agenda.
-
Flowise RCE shows AI builder risk
A critical Flowise vulnerability shows how self-hosted AI builder tools can become infrastructure exposure through connectors, credentials, workflow imports, and server-side execution.



