Threats & incidents
-
Spain arrests suspect over state personnel doxing
Spanish police have arrested a suspect accused of leaking personal data linked to sensitive state institutions, including cyber, police, prosecution, and tax bodies.
-
CERT-EU warns on exploited Netlogon flaw
CERT-EU says a critical Windows Netlogon vulnerability affecting domain controllers is being exploited, putting enterprise identity infrastructure under immediate pressure.
-
Europol disrupts ransomware laundering pipeline
European law enforcement has helped dismantle AudiA6, a crypto laundering service suspected of processing more than €336 million for ransomware and cybercrime groups.
-
Another reminder that retired protocols are an active risk
Check Point’s exploited VPN flaw shows how deprecated remote access protocols can remain live inside security infrastructure long after retirement should have removed them.
-
Nottingham student records incident exposes platform risk
The University of Nottingham says student and alumni data was accessed in a cyber incident affecting its Campus Solutions records platform.
-
Novo Nordisk says cyber incident exposed trial data
Novo Nordisk has disclosed unauthorised access to internal IT systems, with copied non-public data including limited pseudonymised clinical trial information.
-
Chrome zero-day intensifies browser patch pressure
Google has fixed a V8 flaw exploited in the wild, making browser update discipline a live enterprise exposure rather than routine endpoint maintenance.
-
Gogs flaw puts self-hosted Git servers at risk
Rapid7 says an authenticated command execution flaw in Gogs can expose private repositories, credentials, and development infrastructure where self-hosted Git is weakly governed.
-
ANSSI puts G7 Evian summit on cyber alert
France’s cyber agency is supporting G7 summit preparations as major diplomatic events remain exposed to espionage, destabilisation, extortion, and denial-of-service activity.
-
ServiceNow investigates customer data exposure
ServiceNow has reportedly warned affected customers after unauthenticated access through a vulnerable API endpoint allowed attackers to query customer instance data.








