Risk & governance
-
EU warns digital gaps threaten 2030 targets
The Commission’s 2026 Digital Decade report says Europe has made progress, but structural gaps in infrastructure, skills, public services, and business digitalisation remain.
-
ENISA meeting puts AI access in focus
ENISA’s planned meeting with Anthropic comes as European cyber agencies confront access, assurance, and dependency issues around powerful AI models used in security work.
-
France moves spy analytics away from Palantir
France’s DGSI is moving sensitive analytics work from Palantir to ChapsVision, bringing sovereignty, migration risk, and security-critical procurement into practical focus.
-
Novo Nordisk incident tests pharma resilience
Novo Nordisk has confirmed unauthorised access to limited internal IT systems, with separate extortion claims increasing scrutiny of clinical data exposure, pharma resilience, and incident disclosure.
-
Databricks moves further into security data
Databricks’ planned acquisition of Panther reflects enterprise pressure to consolidate security telemetry, automate investigation, and rethink legacy SIEM economics.
-
FortiSandbox reports need careful separation
Critical FortiSandbox vulnerabilities require urgent remediation, while public exploitation claims need to be separated from what Fortinet has confirmed.
-
LiteSpeed flaw exposes shared hosting tenants
Active exploitation of a LiteSpeed cPanel plugin flaw shows how shared hosting environments can turn tenant-level access into root-level operational exposure.
-
Fortra PAM flaw hits privileged access control
A critical Fortra Core Privileged Access Manager flaw shows how defects inside PAM platforms can weaken controls built to contain administrator risk.
-
Splunk flaw reaches the telemetry layer
A critical Splunk Enterprise flaw shows how security monitoring platforms can become infrastructure risk when unauthenticated access reaches supporting data services.
-
Chip security meets post-quantum design
Agile Analog and Xiphera are combining anti-tamper semiconductor IP with post-quantum cryptographic IP for long-life secure chip designs.







