Threats & incidents
-
SimpleHelp flaw exposes managed access risk
Exploitation of a SimpleHelp authentication bypass shows how remote management tooling can become a privileged route into endpoints, cloud credentials, developer systems, and customers.
-
NCSC warns AI is compressing cyber risk
The NCSC and Five Eyes partners have warned that AI is changing cyber risk on a timeline of months, increasing pressure on organisations to test control performance.
-
TfL cyber attackers plead guilty
Two men have pleaded guilty over the 2024 Transport for London cyberattack, creating a rare accountability moment after a major public transport incident.
-
Network Rail faces email threat pressure
Freedom of information data reported by ITPro shows Network Rail blocked more than 7.1 million malicious emails in four months, reflecting persistent pressure on UK transport infrastructure.
-
Operation Endgame disrupts malware infrastructure
European authorities have disrupted SocGholish, StealC, and Amadey infrastructure, targeting malware services used for initial access, credential theft, and follow-on cybercrime.
-
Signal phishing shifts to recovery keys
US agencies say Russian intelligence-linked actors are trying to obtain Signal backup recovery keys, creating account takeover and historic message exposure risk for high-value targets.
-
Hotel phishing campaign targets Europe
Microsoft says hospitality organisations in Europe and Asia are being targeted with photo-themed phishing that delivers a persistent Node.js implant.
-
Europol disrupts malware credential pipeline
European law enforcement has disrupted infrastructure linked to SocGholish, Amadey, and StealC, exposing a credential theft pipeline that feeds ransomware, fraud, and enterprise compromise.
-
NCSC warns on Fortinet VPN exposure
UK organisations using Fortinet SSL VPNs have been urged to investigate after leaked credentials were linked to targeting of internet-facing firewalls and gateways.
-
Fortinet campaign revives edge credential risk
Fortinet says a credential-harvesting campaign is targeting firewall and VPN devices, exposing how old access data and edge infrastructure remain live enterprise risk.








