Threats & incidents
-
Ransomware groups link supply chain theft
Sophos says Vect and TeamPCP have created an operational pipeline from open-source supply chain compromise to ransomware deployment.
-
JadePuffer makes agentic ransomware concrete
Sysdig says JadePuffer used an LLM-driven agent to conduct database extortion after exploiting Langflow and chaining routine techniques at speed.
-
FortiBleed turns credentials into ransomware risk
Fortinet says the reported FortiBleed activity involves credential reuse and weak authentication, while researchers warn stolen FortiGate access is circulating at scale.
-
NHS warns on Ivanti Sentry exploitation
NHS England Digital has warned that exploitation of a critical Ivanti Sentry flaw is being reported in the wild and further exploitation is almost certain.
-
European ransomware puts suppliers under pressure
Black Kite says European ransomware incidents rose sharply in early 2026, with supplier compromise becoming a major route into affected organisations.
-
Tchap breach tests French messaging
France says a compromised Tchap account exposed public rooms and account data for fewer than 9% of registered users.
-
CERT-EU advisories expose infrastructure risk
CERT-EU’s 2026 advisory stream shows exploited and high-impact flaws across perimeter appliances, identity infrastructure, firewalls, and enterprise network systems.
-
UK ransomware figures expose reporting gap
Report Fraud says 323 organisations reported ransomware attacks in a year, with SMEs accounting for more than half of the disclosed cases.
-
Indra ransomware case tests supplier assurance
Spanish defence and technology group Indra says a ransomware incident at one subsidiary was contained, with services continuing normally and the wider group unaffected.
-
MuddyWater widens espionage exposure
WatchGuard’s report on Iran-linked MuddyWater activity points to credential theft, trusted tool abuse, and espionage against high-value organisations.





