Threats & incidents
-
Fire Ant targets trusted network infrastructure
Sygnia says the China-nexus actor it tracks as Fire Ant is compromising routers, authentication systems, and Linux management hosts to reach connected high-value environments.
-
Cursor enters European cyber intrusions
Recovered chat logs show a ransomware operator using Cursor during attacks affecting European organisations, with researchers documenting repeated attempts to bypass the coding agent’s safety controls.
-
Manchester airports confirm customer data theft
Manchester Airports Group says an unauthorised third party obtained customer information linked to airport services, although operational systems, payment data, passenger safety, and aviation security were unaffected.
-
PaperCut attacks expose pre-authentication route
PaperCut is responding to active attacks against NG and MF after researchers reproduced a pre-authentication route from configuration manipulation to arbitrary code execution.
-
Berlin confirms data theft in extortion attack
Berlin has confirmed data was taken during the cyberattack on its state network as officials reject an extortion demand and continue forensic work across affected departments.
-
US water-sector targeting exceeds 100 systems
More than 100 internet-exposed systems in the US water and wastewater sector were targeted during July, widening the known scale of recent attacks on operational technology.
-
Unit 42 finds AI malware mostly experimental
Unit 42 says only a small fraction of more than 400 AI-associated malware samples in its study appeared on production endpoints, underscoring a gap between research artefacts and operational attacks.
-
OpenAI disrupts Russia-origin influence campaign
OpenAI has banned accounts it says very likely originated in Russia and were used to support an elaborate but relatively low-reach covert influence campaign.
-
Gitea flaw moves into active exploitation
CISA has added a Gitea code-injection flaw to its exploited-vulnerability catalogue, weeks after the self-hosted Git platform released a fix.
-
Boston Scientific cyber incident disrupts shipments
Boston Scientific says a cyber incident has disrupted IT systems used to process and ship customer orders, with no timetable yet for full restoration.










