Risk & governance
-
Open Tribeca databases exposed contact network
Four publicly accessible databases reportedly contained hundreds of thousands of Tribeca-related records, including contact details, account information, IP addresses, and hashed passwords.
-
September reporting deadline comes into focus under CRA guidance
European Commission guidance clarifies product scope, support periods, open source treatment, risk assessments, and reporting duties before the Cyber Resilience Act’s first operational deadline.
-
AI-generated apps fail access-control tests
Testing of AI-assisted applications identified 434 validated security flaws, including broken authorisation, resource exhaustion, secrets exposure, and remote code execution.
-
Automation error takes Azure routes offline
A Microsoft maintenance-system defect removed more network routes than intended, disrupting Azure services and testing cloud-resilience arrangements across dependent organisations.
-
UK cyber brief survives Whitehall restructure
Baroness Liz Lloyd has received joint appointments across two reorganised departments, preserving ministerial continuity as the UK expands cyber regulation and infrastructure oversight.
-
Thialf disputes ransomware claims after cyberattack
The Dutch arena has confirmed a cyberattack but says neither its data nor its operations were affected, contradicting separate claims of theft and extortion.
-
TeamViewer disclosure delay draws €240,000 fine
Germany’s financial regulator has fined TeamViewer after finding that its 2024 cyberattack should have been disclosed to the market without delay.
-
Europe sets assurance baseline for cyber providers
ENISA’s proposed certification scheme would establish common assurance requirements for managed security services, beginning with incident response and providers supporting the EU Cybersecurity Reserve.
-
Adobe extension crossed into WhatsApp Web
A patched Adobe Acrobat browser-extension flaw allowed malicious websites to read information rendered inside an open WhatsApp Web session.
-
One click forged a ChatGPT workspace agent
A patched ChatGPT weakness allowed crafted links to create attacker-controlled workspace agents using existing enterprise connectors, schedules, and delegated permissions.










