Risk & governance
-
Germany builds a federal cyber control layer
CyberGovSecure will centralise cyber governance across Germany’s federal administration, with workstreams covering configuration, vulnerability management, logging, detection, and mobile device control.
-
Hospitals get new EU cyber buying guide
ENISA’s first health action plan deliverable pushes hospital cybersecurity into procurement, supplier selection, contracts, and lifecycle management.
-
Four terabytes in an encrypted USB drive
Apricorn has launched a 4TB hardware-encrypted USB device for moving large sensitive datasets where network transfer is impractical, with FIPS 140-3 validation still in progress.
-
Shadow AI grows alongside basic security failures
WatchGuard research suggests unauthorised AI use is rising alongside password reuse, weak application visibility, and inconsistent remote-working controls across smaller and mid-market organisations.
-
Treasury report prices financial cyber disruption
HM Treasury research places cyber among the financial system’s leading risks and models extreme annual ransomware losses of hundreds of millions of pounds for larger organisations.
-
Critical Tenable flaw reaches privileged endpoints
A path-traversal and signature-verification weakness in Tenable Agent could lead to code execution through software deployed with extensive privileges across enterprise endpoints.
-
A repository can trigger code in Cursor
Mindgard says Cursor automatically runs a malicious Git binary placed inside an opened Windows repository, without displaying a warning or requiring further user action.
-
AsyncAPI release breach poisons npm packages
Attackers compromised AsyncAPI release processes and published malicious npm packages capable of installing a persistent remote shell on developer workstations and build systems.
-
Credential flaw reaches EcoStruxure security console
Schneider Electric has patched a high-severity weakness that could allow a privileged local attacker to alter credentials used to administer cybersecurity policies across electrical operational technology.
-
Europe’s fraud machine ran like a multinational
Dutch police say an alleged investment-fraud network employed more than 700 people, operated approximately 20 call centres, and generated over €100 million a month.










