Risk & governance
-
ServiceNow investigates customer data exposure
ServiceNow has reportedly warned affected customers after unauthenticated access through a vulnerable API endpoint allowed attackers to query customer instance data.
-
NHS flags critical Veeam flaw
NHS England has warned that a critical Veeam Backup & Replication vulnerability could allow authenticated domain users to execute remote code on affected backup servers.
-
UK presses device makers on child safety
The UK Government says technology companies must introduce device-level controls to stop children taking, sharing, receiving, or viewing nude images, with legislation threatened if industry does not act.
-
G7 sets cyber resilience priorities
The European Commission has backed a G7 cybersecurity declaration focused on post-quantum migration, AI security, telecoms resilience, SMEs, and software supply chain transparency.
-
ENISA ties SBOM adoption to CRA
ENISA says the Cyber Resilience Act is accelerating SBOM adoption, moving software component transparency deeper into procurement, vulnerability management, supplier assurance, and product-risk governance.
-
EU cyber package moves forward
EU telecoms ministers have advanced work on the Digital Networks Act and Cybersecurity Act 2, bringing infrastructure resilience, ENISA’s role, certification, ICT supply chain risk, and NIS2 simplification into scope.
-
OpenAI expands ChatGPT Lockdown Mode
OpenAI has expanded Lockdown Mode across logged-in ChatGPT users, giving organisations a concrete control for reducing prompt-injection data-exfiltration paths.
-
SolarWinds flaw enters exploitation list
CISA has added a SolarWinds Serv-U denial-of-service vulnerability to its exploited catalogue, putting file-transfer resilience and exposed enterprise infrastructure back under scrutiny.
-
UK pushes device-level safety controls
The UK government has given Apple and Google three months to implement device-level nudity blocking for children, raising wider questions about endpoint controls, privacy, and platform accountability.
-
Spanish energy SaaS flaw exposes supplier risk
INCIBE says a critical SQL injection flaw in Nemon energy-sector ERP products has been fixed centrally, highlighting specialist SaaS dependency in critical-sector operations.


