Risk & governance
-
Dustin shuts systems after unauthorised access
Nordic IT supplier Dustin has shut parts of its internal environment after detecting unauthorised access, with the scope of the incident and any data exposure still under investigation.
-
Lenovo identity flaw exposed Dropbox accounts
A weakness in Lenovo ID email verification allowed attackers to create fraudulent identities and use the federated login relationship to access associated Dropbox accounts without the victims’ passwords.
-
OpenAI says Astra reaches critical cyber threshold
OpenAI now says Astra meets its highest published cybersecurity capability threshold, moving beyond its August assessment that it could not rule out the classification.
-
Model puts UK battery cyber loss at £10bn
Centrii modelling puts the five-year probability of a major UK battery-storage cyberattack at 92% under baseline assumptions, with potential losses of £2bn to £10bn.
-
Viatel buys EDNX in secure networking push
Viatel has acquired UK network specialist EDNX, extending its secure infrastructure capability across Ireland and Britain after buying Scottish cybersecurity company FullProxy in July.
-
Anthropic resumes cyber tests under tighter controls
Anthropic has resumed external cyber evaluations after models reached unintended real systems, adding stronger sandboxing, real-time intervention, and tighter controls for third-party testing.
-
FSB flags frontier AI cyber risk
The Financial Stability Board has identified cyber risk as the most immediate financial-system concern arising from increasingly capable frontier AI models.
-
Swiss ownership register proceeds after Liechtenstein breach
Switzerland’s beneficial-ownership register remains set for an October launch as neighbouring Liechtenstein commissions a wider security review following the theft of sensitive register data.
-
Exchange outage exposes Microsoft 365 dependency
A multi-hour Exchange Online incident is disrupting email, authentication, and administration as Microsoft tests remediation for a problem involving an authentication component.
-
Tenable patches critical Security Center flaws
Tenable has issued stand-alone patches for Security Center and Enclave Security vulnerabilities, including a critical authenticated remote-code execution flaw rated 9.9 under CVSS v3.1.










