Decoding the world of cybersecurity

Risk & governance

  • ServiceNow investigates customer data exposure

    ServiceNow investigates customer data exposure

    ServiceNow has reportedly warned affected customers after unauthenticated access through a vulnerable API endpoint allowed attackers to query customer instance data.

    read more

  • NHS flags critical Veeam flaw

    NHS flags critical Veeam flaw

    NHS England has warned that a critical Veeam Backup & Replication vulnerability could allow authenticated domain users to execute remote code on affected backup servers.

    read more

  • UK presses device makers on child safety

    UK presses device makers on child safety

    The UK Government says technology companies must introduce device-level controls to stop children taking, sharing, receiving, or viewing nude images, with legislation threatened if industry does not act.

    read more

  • G7 sets cyber resilience priorities

    G7 sets cyber resilience priorities

    The European Commission has backed a G7 cybersecurity declaration focused on post-quantum migration, AI security, telecoms resilience, SMEs, and software supply chain transparency.

    read more

  • ENISA ties SBOM adoption to CRA

    ENISA ties SBOM adoption to CRA

    ENISA says the Cyber Resilience Act is accelerating SBOM adoption, moving software component transparency deeper into procurement, vulnerability management, supplier assurance, and product-risk governance.

    read more

  • EU cyber package moves forward

    EU cyber package moves forward

    EU telecoms ministers have advanced work on the Digital Networks Act and Cybersecurity Act 2, bringing infrastructure resilience, ENISA’s role, certification, ICT supply chain risk, and NIS2 simplification into scope.

    read more

  • OpenAI expands ChatGPT Lockdown Mode

    OpenAI expands ChatGPT Lockdown Mode

    OpenAI has expanded Lockdown Mode across logged-in ChatGPT users, giving organisations a concrete control for reducing prompt-injection data-exfiltration paths.

    read more

  • SolarWinds flaw enters exploitation list

    SolarWinds flaw enters exploitation list

    CISA has added a SolarWinds Serv-U denial-of-service vulnerability to its exploited catalogue, putting file-transfer resilience and exposed enterprise infrastructure back under scrutiny.

    read more

  • UK pushes device-level safety controls

    UK pushes device-level safety controls

    The UK government has given Apple and Google three months to implement device-level nudity blocking for children, raising wider questions about endpoint controls, privacy, and platform accountability.

    read more

  • Spanish energy SaaS flaw exposes supplier risk

    Spanish energy SaaS flaw exposes supplier risk

    INCIBE says a critical SQL injection flaw in Nemon energy-sector ERP products has been fixed centrally, highlighting specialist SaaS dependency in critical-sector operations.

    read more

×