Risk & governance
-
Poisoned feed compromises BdThemes WordPress plugins
Attackers compromised infrastructure serving a remote data feed used by seven BdThemes WordPress plugins, allowing malicious code to run inside administrators’ browsers without altering plugin files in the official repository.
-
GitHub broadens Dependabot malware alerts
GitHub has expanded Dependabot’s malicious-package coverage beyond npm, allowing dependencies across most supported ecosystems to be matched against a wider pool of known malware advisories.
-
Poisoned logs can redirect privileged AI agents
DEF CON research shows how attacker-controlled information inside trusted operational systems can influence AI agents that have permission to change cloud and security environments.
-
OpenAI widens controlled cyber-model access
OpenAI has launched GPT‑5.6‑Cyber through an expanded Daybreak programme, giving approved researchers access to a model deliberately trained to answer substantially more advanced dual-use cyber requests.
-
Cyber incidents reach UK factory output
Make UK research links cyber incidents to production downtime, operating costs, supplier disruption, and delayed customer deliveries across British manufacturing.
-
CEVA attack spreads through European supply chains
A cyberattack affecting eight CEVA Logistics warehouses has disrupted European fulfilment and exposed customer information held on behalf of retailers, a bank, a football club, and Valve.
-
OpenAI tightens Astra controls over cyber risk
OpenAI has paused Astra-related internal work that does not meet stronger security requirements after preliminary evaluations left it unable to rule out its highest cybersecurity capability threshold.
-
‘No reply’ domains become accidental data sinks
Researchers controlling plausible placeholder domains are receiving large volumes of misdirected corporate and personal information, exposing persistent weaknesses in automated email and account-deprovisioning processes.
-
Kimi K3 exploits gap in UK benchmark
Kimi K3 retrieved a benchmark solution through an allowed GitHub connection during a UK AI evaluation, exposing how containment design can distort measurements of autonomous cyber capability.
-
Stade Français contains attack on internal systems
Stade Français says a cyberattack affected part of its information system while ticketing and merchandise remained available, as separate claims about leaked player documents remain unconfirmed by the club.







