Risk & governance
-
Claude tests crossed into live systems
Anthropic says three cyber evaluation incidents allowed Claude models to reach the internet and access real production systems through a third-party test environment.
-
Product security gets an SME playbook
ENISA’s secure-by-design and secure-by-default playbook gives smaller manufacturers practical steps for building product security into engineering and release work.
-
AI agent rollout strains identity governance
Kocho says AI agents and non-human identities are expanding enterprise access faster than many organisations can govern, monitor, and hold accountable.
-
AI-discovered flaws show ordinary exploitation rates
VulnCheck says only 14 of 1,061 AI-assisted vulnerability discoveries were confirmed as exploited in the wild during the first half of 2026.
-
CNI supplier access emerges as repeated attack route
e2e-assure research says CNI organisations are experiencing repeated supplier compromise and credential theft, while many only review third party access after incidents.
-
North Korean campaign connects npm compromises
Amazon says compromises of axios, debug, chalk, and typo-crypto were linked to the same DPRK-linked actor, reframing separate incidents as a wider supply chain campaign.
-
Self-hosted Gitea platforms face RCE risk
Gitea has disclosed a critical remote code execution flaw that can let repository writers execute shell commands as the Gitea OS user.
-
Rails image flaw puts application secrets at risk
Rails has fixed CVE-2026-66066, an Active Storage vulnerability that may allow arbitrary file reads and remote code execution in affected applications.
-
Critical VMware fixes put vCenter under scrutiny
Broadcom has issued critical VMware updates for vCenter and ESX, including two CVSS 9.8 vCenter vulnerabilities with no workaround.
-
Exploited Cisco flaw exposes firewall management
Cisco says attackers are exploiting a static credential flaw in Secure Firewall Management Center and has urged customers to patch and rotate credentials, keys, and certificates.










