Risk & governance
-
ICO complaints duty raises accountability
UK organisations must now have a data protection complaints process, adding a formal accountability layer around data handling, security concerns, and post-incident evidence.
-
NGINX flaws widen patch pressure
Fresh NGINX vulnerabilities affecting gateway, open source, and commercial versions put infrastructure visibility and patch coordination back in focus.
-
Cisco ISE flaws test identity resilience
Cisco ISE and ISE-PIC vulnerabilities expose how identity infrastructure can become operationally sensitive when access control systems require urgent patching.
-
Splunk AI flaw hits privileged tooling
A critical Splunk AI Toolkit vulnerability shows how AI add-ons inside monitoring platforms can introduce execution risk into trusted security environments.
-
Bulgaria faces surveillance export scrutiny
Human Rights Watch says Bulgarian authorities licensed exports of surveillance technology to governments with records of repression, exposing weaknesses in Europe’s cyber-surveillance controls.
-
Databricks deal pushes security lakehouse model
Databricks has agreed to acquire Panther, extending its push into security operations as AI, data scale, and SIEM costs reshape enterprise detection and response.
-
Rockwell advisories expose OT patching pressure
CISA has published several Rockwell Automation advisories, including flaws affecting controllers and industrial software, highlighting the operational challenge of patching industrial systems.
-
Copilot flaw exposes AI data risk
Varonis says Microsoft patched a critical Copilot vulnerability chain that could have allowed sensitive Microsoft 365 data to be extracted through a crafted link.
-
Oracle PeopleSoft exploit exposes enterprise platforms
Oracle has issued an emergency alert for a critical PeopleSoft flaw after active exploitation linked to ShinyHunters, exposing risk in long-lived enterprise HR, finance, and education platforms.
-
NCSC warns state actors dominate critical attacks
The NCSC says hostile states are linked to around three-quarters of incidents affecting UK critical systems, placing resilience and accountability at the centre of national cyber policy.








