Threats & incidents
-
Iran-linked attacks widen across industrial controllers
US authorities have expanded an alert on Iran-affiliated activity to include Siemens and Schneider controllers widely deployed across European infrastructure.
-
Check Point flaw reaches firewall control plane
An actively exploited authentication bypass exposed internet-facing Check Point management systems, placing firewall policy and administrative infrastructure within an attacker’s reach.
-
Zimbra zero-day opens mailboxes on view
A Russian state-supported group exploited a Zimbra zero-day to steal mail and authentication material when victims merely viewed a malicious message.
-
Notepad++ bundle conceals Ukrainian espionage malware
UAC-0099 packaged legitimate Notepad++ software with a malicious plugin, abusing a trusted application without compromising the vendor’s official distribution chain.
-
Stadler breach stops short of rail operations
Attackers stole technical documents through a supplier platform, but Stadler says its production systems, trains, and internal IT remained unaffected.
-
Property deals freeze after Romania registry attack
A cyberattack on Romania’s national land registry disrupted property sales, mortgage processing, and legal work while recovery teams checked that authoritative ownership records remained intact.
-
Langflow exploit puts AI workflows under pressure
CISA has added an actively exploited Langflow vulnerability to KEV, raising concern over exposed AI workflow and agent-building infrastructure.
-
Craneware breach tests healthcare supplier trust
UK-listed healthcare technology supplier Craneware says unauthorised access affected part of its data environment, with employee, customer, and partner records accessed and exfiltrated.
-
WordPress Core flaws raise mass exploit risk
CERT-FR has warned that chained WordPress Core vulnerabilities may allow unauthenticated remote code execution in affected versions.
-
Kratos takedown exposes the limits of MFA
German and US authorities have disrupted Kratos, a phishing-as-a-service kit used to steal Microsoft 365 credentials and session cookies.










