Threats & incidents
-
INC linked to SonicWall exploitation campaign
Researchers have linked INC ransomware activity to attacks exploiting two SonicWall SMA 1000 vulnerabilities, although the vendor has not publicly attributed the campaign.
-
N-central attackers reached managed endpoints
Attackers exploited N-able’s N-central platform, obtained administrative access, and used its remote-control capability to connect to endpoints inside customer-managed environments.
-
PNLD confirms police contact data breach
PNLD has confirmed that police and criminal-justice contact information was compromised and published on the dark web, while ruling out exposure of passwords and crime records.
-
Liechtenstein attack exposes ownership register data
Attackers copied beneficial-owner data relating to around 31,000 legal entities, while Liechtenstein suspended several other government systems to check for wider exposure.
-
Amgen cloud breach exposed patient data
Amgen has declared a material cybersecurity incident after proprietary information and patient health data were exfiltrated from third-party cloud environments.
-
Arch Linux freezes AUR changes
Arch Linux disabled package adoption and later all pushes to its user repository while responding to malicious package takeovers and follow-on commits.
-
Adform code targeted crypto wallet addresses
Malicious code delivered through Adform technology attempted to replace cryptocurrency wallet addresses copied by visitors to affected websites.
-
FlashStart expands DNS-layer protection
FlashStart 2026 adds DNS-layer malware protection, service-provider APIs, microservices architecture, and data sovereignty features for enterprises and managed providers.
-
EY tax support breach exposes client data
A breach involving a third-party support platform used by EY tax teams exposed personal and financial information held in tickets and documents.
-
Russian zero-click campaign targets Zimbra mail
The NCSC and international partners say Russian state-supported actors used a Zimbra zero-click exploit to steal email data from Western organisations.




