Risk & governance
-
Cl0p claims Philips and Shell data theft
Philips has contained an attempted compromise and Shell is investigating a possible incident after Cl0p claimed to have stolen engineering and project information from both companies.
-
Polish health breach exposes millions of records
Polish authorities are investigating a major breach at healthcare software provider MyDr after roughly 19 million records linked to patients and more than 12,000 medical facilities were stolen.
-
Microsoft August patch load tops 400 flaws
Microsoft’s August security release covers 421 vulnerabilities, including an exploited Windows privilege-escalation flaw, as enterprise patch volumes remain far above historic norms.
-
ICO reprimands ACRO over security failures
The ICO has reprimanded ACRO after finding unclear patching responsibilities and inadequate alert investigation during a prolonged compromise that potentially exposed highly sensitive personal information.
-
LiteLLM exposure estimate tops 2,500 organisations
CloudSEK estimates that the LiteLLM supply chain compromise potentially exposed more than 2,500 organisations and 434,000 CI/CD pipelines, while stressing that exposure does not establish compromise.
-
KnowBe4 releases October awareness campaign kit
KnowBe4 has released a free 2026 Cybersecurity Awareness Month package combining training material, tabletop exercises, and campaign resources around phishing, AI threats, data security, and incident reporting.
-
Wesco confirms incident in cloud CRM
Wesco has confirmed unauthorised activity involving its cloud CRM environment while disputing the more serious implications of ExfilSquad’s claimed theft of millions of customer and employee records.
-
Terabit DDoS attacks surge across Cloudflare
Cloudflare says hyper-volumetric DDoS attacks rose sharply in the first half of 2026, with attacks exceeding 1 Tbps becoming substantially more common across its network.
-
LexisNexis incident exposes hosting dependency
LexisNexis disconnected three customer-facing services after detecting unusual activity on servers hosted and managed by a third party, disrupting due-diligence, monitoring, and data-feed products.
-
N-central attacks develop into ransomware campaign
Microsoft has linked Storm-1175 to a new ransomware strain deployed during the N-central attack cycle, while assessing — rather than confirming — CVE-2026-18577 as the likely entry route.








