Threats & incidents
-
Thirty water systems reveal shared OT exposure
A coordinated attack on more than 30 Minnesota water systems has renewed scrutiny of internet-accessible industrial controls, contractor access, and the resilience of smaller infrastructure operators.
-
Minimum viable operations anchor NCSC recovery guidance
New NCSC guidance treats recovery from disruptive cyberattacks as an organisational programme built around minimum viable operations, investigation, legal duties, and controlled rebuilding.
-
Europe accounts for quarter of ransomware claims
NCC Group recorded 579 European ransomware victims during the second quarter, while industrial organisations, edge infrastructure, and trusted software environments remained prominent targets.
-
VPN bypass opens path to Qilin ransomware
A configuration-dependent GlobalProtect authentication bypass has become an initial-access route for intrusions involving credential theft, data exfiltration, encryption, and Qilin ransomware.
-
VeloCloud zero-day reaches the network control plane
Attackers are exploiting a maximum-severity vulnerability in on-premises VeloCloud Orchestrator systems, exposing the management layer above distributed branch, retail, industrial, and remote-site networks.
-
Remote hiring campaign reaches UK bank
Hundreds of suspicious applications for remote jobs at an unnamed British bank have placed recruitment controls alongside identity governance, insider risk, and sanctions compliance.
-
The backup myth: why copied data won’t save your business
William Thackray, Operations Director of AGT Computer Services, argues that backups alone cannot prove ransomware resilience unless restoration is tested against operational reality.
-
Open Tribeca databases exposed contact network
Four publicly accessible databases reportedly contained hundreds of thousands of Tribeca-related records, including contact details, account information, IP addresses, and hashed passwords.
-
Hostile hotel Wi-Fi reroutes Microsoft logins
Attackers are compromising hospitality gateways and poisoning DNS responses to redirect connected users towards counterfeit Microsoft 365 authentication pages.
-
Thialf disputes ransomware claims after cyberattack
The Dutch arena has confirmed a cyberattack but says neither its data nor its operations were affected, contradicting separate claims of theft and extortion.









