Threats & incidents
-
Aflac Japan breach exposes portal risk
Aflac says unauthorised access to systems linked to its Japan business exposed policy, personal, and bank account information.
-
Barracuda tracks phishing beyond passwords
Barracuda’s June Email Threat Radar shows phishing moving deeper into session tokens, OAuth flows, device-code lures, split-click evasion, and malware delivery.
-
Insee breach exposes French public-sector staff data
France’s national statistics agency says a cyberattack exposed staff directory information, while passwords, sensitive staff data, and statistical collections were not affected.
-
EU moves to strengthen Europol and Eurojust
The European Commission wants stronger Europol and Eurojust powers as organised crime, hostile actors, cybercrime, and digital investigations become more complex and cross-border.
-
Google maps pro-Russia influence machinery
Google says Russia’s influence ecosystem is moving beyond Ukraine-specific wartime narratives towards wider strategic targets, with Europe, NATO, cyber leaks, and AI in focus.
-
Russian phishing targets Signal recovery keys
US agencies warn Russian intelligence-linked actors are soliciting Signal backup recovery keys, shifting secure messaging risk towards account recovery, user verification, and communications governance.
-
Oracle E-Business Suite flaw exploited
Reported exploitation of a critical Oracle E-Business Suite flaw has put patch latency, payment workflows, and internet-exposed enterprise applications back under scrutiny.
-
SimpleHelp flaw exposes managed access risk
Exploitation of a SimpleHelp authentication bypass shows how remote management tooling can become a privileged route into endpoints, cloud credentials, developer systems, and customers.
-
NCSC warns AI is compressing cyber risk
The NCSC and Five Eyes partners have warned that AI is changing cyber risk on a timeline of months, increasing pressure on organisations to test control performance.
-
TfL cyber attackers plead guilty
Two men have pleaded guilty over the 2024 Transport for London cyberattack, creating a rare accountability moment after a major public transport incident.






