Threats & incidents
-
Alation investigates unauthorised access
Enterprise data platform Alation is investigating unauthorised activity in one of its systems, with the extent of any customer or data impact still unknown.
-
DfE restores portals after data breach
The Department for Education has restored two portals after identifying a vulnerability, confirming affected personal data and notifying the Information Commissioner’s Office.
-
Manic malware targets Ukrainian mobile services
Manic Android malware is combining financial theft, surveillance and remote control while targeting Ukrainian banks, identity services and communications applications.
-
Four exploited vulnerabilities CISOs should check — now
Four vulnerabilities affecting Microsoft, VMware, and Apple products are now listed by CISA as actively exploited, putting patch status, internet exposure, and the role of affected systems under renewed scrutiny.
-
France confronts tax systems’ cyber debt
France has acknowledged ageing and vulnerable government IT after its tax breach, accelerating authentication, detection, training, and an audit due in September.
-
Clop-linked web shell targets Windchill data
A purpose-built web shell targeting PTC Windchill can decrypt stored credentials, map engineering repositories, and run additional code while operating inside the application’s own trust boundary.
-
France investigates claimed student data theft
France’s Education Ministry is investigating claims that attackers obtained extensive student and teacher records, but the full scope and victim count remain unconfirmed.
-
CameraSwarm compromises 14,500 Dahua cameras
A single operator compromised more than 14,500 Dahua cameras in 35 days, including devices reached through cloud relay infrastructure and persistent access mechanisms.
-
Siemens S7 controllers face active attacks
Government agencies have warned that internet-exposed Siemens S7 programmable logic controllers face an active threat capable of disrupting physical processes across critical infrastructure.
-
CSDD leadership quits after Latvia data breach
Latvia’s road authority has lost its senior leadership after a breach exposed data linked to 1.2 million people and prompted an investigation into its cybersecurity arrangements.










