Risk & governance
-
UK puts load controllers into cyber regulation
The UK wants large electricity load controllers brought into cyber regulation as smart appliances, batteries, heat pumps, and EV charging reshape grid risk.
-
Aikido buys Root for open source patching
Belgian security company Aikido has acquired Root, adding technology for backported open source fixes as dependency risk moves deeper into developer workflows.
-
ENISA finds SME readiness gap on CRA
ENISA’s SME survey shows that Europe’s Cyber Resilience Act will depend on practical support for smaller suppliers as much as formal legal duties.
-
Insee breach exposes French public-sector staff data
France’s national statistics agency says a cyberattack exposed staff directory information, while passwords, sensitive staff data, and statistical collections were not affected.
-
Cequence puts agents inside API security
Cequence Platform 9.0 adds an AI assistant and MCP server, bringing agent-operated workflows into API security, compliance evidence, and control changes.
-
EU moves to strengthen Europol and Eurojust
The European Commission wants stronger Europol and Eurojust powers as organised crime, hostile actors, cybercrime, and digital investigations become more complex and cross-border.
-
Google maps pro-Russia influence machinery
Google says Russia’s influence ecosystem is moving beyond Ukraine-specific wartime narratives towards wider strategic targets, with Europe, NATO, cyber leaks, and AI in focus.
-
Russian phishing targets Signal recovery keys
US agencies warn Russian intelligence-linked actors are soliciting Signal backup recovery keys, shifting secure messaging risk towards account recovery, user verification, and communications governance.
-
Oracle E-Business Suite flaw exploited
Reported exploitation of a critical Oracle E-Business Suite flaw has put patch latency, payment workflows, and internet-exposed enterprise applications back under scrutiny.
-
NCSC warns AI is compressing cyber risk
The NCSC and Five Eyes partners have warned that AI is changing cyber risk on a timeline of months, increasing pressure on organisations to test control performance.







