Risk & governance
-
VS Code tasks expose developer risk
JFrog says hijacked npm packages used hidden VS Code tasks and blockchain dead drops to deploy a credential and cryptocurrency stealer.
-
Bank tests cloud disruption risk
The Bank of England is using CORST26 and SIMEX to examine how disruption at a major cloud provider could affect financial market infrastructure.
-
Signal phishing shifts to recovery keys
US agencies say Russian intelligence-linked actors are trying to obtain Signal backup recovery keys, creating account takeover and historic message exposure risk for high-value targets.
-
Europol disrupts malware credential pipeline
European law enforcement has disrupted infrastructure linked to SocGholish, Amadey, and StealC, exposing a credential theft pipeline that feeds ransomware, fraud, and enterprise compromise.
-
e2e-assure brings AI into sovereign SOCs
e2e-assure’s updated Cumulo platform brings sovereign AI, digital twins, and IT/OT monitoring into the UK debate over machine-speed cyber defence.
-
Accenture makes $4.2bn OT cyber move
Accenture’s planned Dragos, runZero, and NetRise deals would combine OT detection, asset intelligence, and firmware visibility for critical infrastructure security.
-
ICO complaints duty raises accountability
UK organisations must now have a data protection complaints process, adding a formal accountability layer around data handling, security concerns, and post-incident evidence.
-
NGINX flaws widen patch pressure
Fresh NGINX vulnerabilities affecting gateway, open source, and commercial versions put infrastructure visibility and patch coordination back in focus.
-
Cisco ISE flaws test identity resilience
Cisco ISE and ISE-PIC vulnerabilities expose how identity infrastructure can become operationally sensitive when access control systems require urgent patching.
-
Splunk AI flaw hits privileged tooling
A critical Splunk AI Toolkit vulnerability shows how AI add-ons inside monitoring platforms can introduce execution risk into trusted security environments.








