Risk & governance
-
Endpoint security PoCs expose privileged attack surface
Public proof-of-concept exploits targeting CrowdStrike Falcon and Avast, alongside a separate Nvidia memory-corruption disclosure, are drawing attention to vulnerabilities inside highly privileged endpoint components.
-
NCSC warns shadow AI is eroding visibility
The UK’s NCSC says unapproved workplace AI can expose sensitive information and create governance blind spots as employees adopt tools outside established organisational controls.
-
Boston Scientific recovery leaves NHS backlog
Boston Scientific has restarted most manufacturing and European distribution after its cyberattack, but NHS customers still face queued orders and intermittent product availability.
-
Trezor breach expands over retained records
Trezor says its ShipMonk breach now affects about 81,000 customers after historical records that should have been deleted remained in the logistics provider’s systems.
-
OpenAI widens disclosure plans after wiki incident
OpenAI has acknowledged that its agents used public wiki sites as message boards during evaluations and says disclosure practices must expand as model misalignment produces real-world effects.
-
French hospital fined €500,000 after data breach
France’s privacy regulator has fined Hôpital Privé de la Loire after finding weak authentication, excessive access, and inadequate monitoring contributed to a major patient-data breach.
-
Netherlands funds small-business cyber controls
The Netherlands is reopening a €1 million cyber-resilience subsidy that will cover half the cost of selected security measures for qualifying small businesses and sole traders.
-
Autonomous pentesting is solving the wrong half of the problem
Jay Kaplan, CEO and Co-founder of Synack, argues autonomous pentesting can expand coverage, but without expert human validation it risks shifting security teams from untested assets to untriaged findings.
-
CREST accredits first AI-enabled penetration-testing providers
CREST has accredited its first ten AI-enabled penetration-testing providers, creating an assurance framework around how artificial intelligence is governed inside professional security testing services.
-
G7 urges faster post-quantum migration
G7 cyber authorities are pressing public and private organisations to accelerate post-quantum migration as European policymakers move from broad timelines towards implementation and prioritisation.










