Threats & incidents
-
Network Rail faces email threat pressure
Freedom of information data reported by ITPro shows Network Rail blocked more than 7.1 million malicious emails in four months, reflecting persistent pressure on UK transport infrastructure.
-
Operation Endgame disrupts malware infrastructure
European authorities have disrupted SocGholish, StealC, and Amadey infrastructure, targeting malware services used for initial access, credential theft, and follow-on cybercrime.
-
Signal phishing shifts to recovery keys
US agencies say Russian intelligence-linked actors are trying to obtain Signal backup recovery keys, creating account takeover and historic message exposure risk for high-value targets.
-
Hotel phishing campaign targets Europe
Microsoft says hospitality organisations in Europe and Asia are being targeted with photo-themed phishing that delivers a persistent Node.js implant.
-
Europol disrupts malware credential pipeline
European law enforcement has disrupted infrastructure linked to SocGholish, Amadey, and StealC, exposing a credential theft pipeline that feeds ransomware, fraud, and enterprise compromise.
-
NCSC warns on Fortinet VPN exposure
UK organisations using Fortinet SSL VPNs have been urged to investigate after leaked credentials were linked to targeting of internet-facing firewalls and gateways.
-
Fortinet campaign revives edge credential risk
Fortinet says a credential-harvesting campaign is targeting firewall and VPN devices, exposing how old access data and edge infrastructure remain live enterprise risk.
-
Oracle PeopleSoft exploit exposes enterprise platforms
Oracle has issued an emergency alert for a critical PeopleSoft flaw after active exploitation linked to ShinyHunters, exposing risk in long-lived enterprise HR, finance, and education platforms.
-
NCSC warns state actors dominate critical attacks
The NCSC says hostile states are linked to around three-quarters of incidents affecting UK critical systems, placing resilience and accountability at the centre of national cyber policy.
-
Novo Nordisk incident tests pharma resilience
Novo Nordisk has confirmed unauthorised access to limited internal IT systems, with separate extortion claims increasing scrutiny of clinical data exposure, pharma resilience, and incident disclosure.









