Risk & governance
-
EU-US data deal faces independence test
noyb says a US Supreme Court ruling has weakened the FTC’s independence, putting a key enforcement pillar of the EU-US Data Privacy Framework under pressure.
-
Pegasus breach reaches EU spyware oversight
Citizen Lab says a former MEP on the European Parliament’s spyware inquiry was infected with Pegasus, exposing fresh accountability concerns around surveillance, parliamentary confidentiality, and device assurance.
-
MuddyWater widens espionage exposure
WatchGuard’s report on Iran-linked MuddyWater activity points to credential theft, trusted tool abuse, and espionage against high-value organisations.
-
Cisco flaw reaches network management layer
Cisco’s July advisory set includes a Catalyst Center arbitrary file read flaw, putting network management platforms back into patch planning.
-
AutoJack breaks localhost trust in AI agents
Microsoft’s AutoJack research shows how a malicious web page rendered by an AI browsing agent can reach local control planes.
-
BioShocking exposes AI browser identity risk
LayerX research shows how AI browsers can be manipulated into exposing credentials, code, and signed-in account data.
-
UK cyber bill enters Lords scrutiny
The Cyber Security and Resilience Bill has moved into the Lords, where scrutiny will test the UK’s expansion of cyber duties and supplier accountability.
-
Intruder opens exposure management free tier
Intruder’s permanent free plan gives smaller organisations access to vulnerability scans, cloud checks, attack surface monitoring, and limited AI pentesting.
-
Ofgem puts supplier security into energy resilience
Ofgem’s downstream gas and electricity guidance points to a more structured model for managing supplier security risk across the UK energy system.
-
Check Point enters AWS sovereign cloud
Check Point’s Cloud Firewall availability on AWS European Sovereign Cloud adds security tooling to Europe’s regulated cloud procurement market.









