Risk & governance
-
GitHub narrows access to its bug bounty
GitHub has lowered public bounty payments while formalising a higher-paying invitation-only programme, citing growing volumes of low-quality and AI-generated vulnerability reports.
-
Cyber-specific model joins Microsoft remediation system
Microsoft’s first dedicated cyber model will identify, validate, prioritise, and patch software vulnerabilities inside a controlled multi-agent system, with access restricted because of its dual-use capability.
-
Open alliance assembles AI security stack
Nvidia, SAP, Siemens, Microsoft, and other technology companies have formed an alliance to develop open tools for AI-agent identity, testing, monitoring, vulnerability discovery, and governance.
-
Europe accounts for quarter of ransomware claims
NCC Group recorded 579 European ransomware victims during the second quarter, while industrial organisations, edge infrastructure, and trusted software environments remained prominent targets.
-
Managed cloud identities cross privilege boundaries
Disputed findings in Azure and Google Cloud show how a provider-operated or customer-managed service identity can exercise authority beyond that held by the user initiating an action.
-
GitLab exploit emerges from an understated patch
Researchers have published a working GitLab remote code execution chain after the relevant dependency update shipped without a CVE, severity rating, or prominent security classification.
-
Remote hiring campaign reaches UK bank
Hundreds of suspicious applications for remote jobs at an unnamed British bank have placed recruitment controls alongside identity governance, insider risk, and sanctions compliance.
-
Spyware claim clears UK immunity hurdle
A divided Supreme Court has ruled that foreign-state hacking of a computer in Britain can constitute an act in the UK, allowing a civil spyware claim against Bahrain to proceed.
-
The backup myth: why copied data won’t save your business
William Thackray, Operations Director of AGT Computer Services, argues that backups alone cannot prove ransomware resilience unless restoration is tested against operational reality.
-
TeamCity flaw puts build systems at risk
An unauthenticated vulnerability affecting every TeamCity On-Premises version can give remote attackers command execution on servers holding source code, credentials, artefacts, and deployment access.







