Risk & governance
-
Credential flaw reaches EcoStruxure security console
Schneider Electric has patched a high-severity weakness that could allow a privileged local attacker to alter credentials used to administer cybersecurity policies across electrical operational technology.
-
Europe’s fraud machine ran like a multinational
Dutch police say an alleged investment-fraud network employed more than 700 people, operated approximately 20 call centres, and generated over €100 million a month.
-
AI enters the live intrusion chain
Check Point research documents AI performing operational work during live intrusions, while enterprise telemetry shows rising prompt injection and sensitive-data exposure through routine AI use.
-
US indicts alleged bulletproof hosting operators
US prosecutors have unsealed charges against three Russian nationals and two companies accused of providing infrastructure used in cybercrime affecting international victims.
-
Adobe warns ColdFusion flaw is exploited
Adobe says CVE-2026-48282 has been exploited in limited attacks against ColdFusion, with updates available for ColdFusion 2025 and 2023.
-
SAP fixes critical NetWeaver and Commerce flaws
SAP’s July Security Patch Day includes critical issues in NetWeaver Application Server ABAP, SAP Approuter, SAP Commerce Cloud, and NetWeaver Application Server Java.
-
Microsoft patches exploited AD FS and SharePoint flaws
Microsoft’s July security update includes exploited vulnerabilities affecting Active Directory Federation Services and SharePoint Server.
-
SonicWall warns SMA flaws are exploited
SonicWall says two SMA 1000 vulnerabilities are being actively exploited and is urging customers to upgrade, investigate, and reset credentials where needed.
-
UK expands public-sector vulnerability monitoring
UK Government Security says its Vulnerability Monitoring Service now covers more than 6,000 public-sector organisations and has expanded active scanning.
-
UK adds cyber risks to national register
The UK has added cyber attacks on data, water, and police infrastructure to the National Risk Register, alongside digital resilience failure after CrowdStrike.





