Threats & incidents
-
UK education and police support data stolen
Hackers have claimed data from Department for Education and Police National Legal Database-linked systems, exposing public-sector contact records and staff details.
-
Rail supplier portal breach reaches Stadler
A supplier platform incident at Stadler exposed technical data without affecting rail vehicles, production, personal data, or operational systems.
-
Cyber sanctions widen across Europe
Eight European partner countries have aligned with EU cyber sanctions targeting individuals and entities linked to attacks against the Union and its partners.
-
North Korean campaign connects npm compromises
Amazon says compromises of axios, debug, chalk, and typo-crypto were linked to the same DPRK-linked actor, reframing separate incidents as a wider supply chain campaign.
-
Exploited Cisco flaw exposes firewall management
Cisco says attackers are exploiting a static credential flaw in Secure Firewall Management Center and has urged customers to patch and rotate credentials, keys, and certificates.
-
Public sector breach reaches education and policing
The Department for Education and the Police National Legal Database were reportedly affected by a cyber attack exposing helpdesk, education, police, and criminal-justice contact data.
-
Webmail implant puts European mailboxes at risk
Proofpoint says TA488 used a half-click Outlook Web Access exploit against European government and strategic-sector targets, creating persistence that may survive ordinary recovery actions.
-
Stolen passwords unlock SonicWall accounts at 30 organisations
An automated credential-stuffing campaign produced successful unauthorised SonicWall logins at 30 organisations without exploiting a software vulnerability.
-
Support platform breach exposes EY client documents
Documents were downloaded from a third-party support platform used by EY, showing how service-management systems can accumulate sensitive client information beyond their original operational purpose.
-
CubePilot DNS hijack breaks firmware trust
Loss of CubePilot’s domain infrastructure created an opportunity to intercept credentials and undermined confidence in firmware downloaded during the affected period.









