Threats & incidents
-
VMware vCenter flaw moves into active exploitation
Incident responders have linked successful compromises across 47 countries to the critical VMware vCenter flaw CVE-2026-59310, only days after Broadcom disclosed and patched it.
-
Cl0p claims Philips and Shell data theft
Philips has contained an attempted compromise and Shell is investigating a possible incident after Cl0p claimed to have stolen engineering and project information from both companies.
-
Polish health breach exposes millions of records
Polish authorities are investigating a major breach at healthcare software provider MyDr after roughly 19 million records linked to patients and more than 12,000 medical facilities were stolen.
-
SharePoint exploitation follows public PoC
Honeypots recorded attempts to exploit a patched SharePoint authentication bypass shortly after public PoC code appeared, while a second flaw completes an unauthenticated remote-code-execution chain.
-
Wesco confirms incident in cloud CRM
Wesco has confirmed unauthorised activity involving its cloud CRM environment while disputing the more serious implications of ExfilSquad’s claimed theft of millions of customer and employee records.
-
N-central attacks develop into ransomware campaign
Microsoft has linked Storm-1175 to a new ransomware strain deployed during the N-central attack cycle, while assessing — rather than confirming — CVE-2026-18577 as the likely entry route.
-
SharePoint flaw moves into ransomware attacks
CISA has changed the status of an already exploited SharePoint Server vulnerability to confirm its use in ransomware campaigns, raising the consequence for organisations still running vulnerable on-premises systems.
-
Cisco VPN flaw crashes exposed firewalls
Cisco says attackers are actively exploiting a flaw in ASA and FTD remote-access services that can force vulnerable firewalls to reload, with fixed software available and no workaround.
-
Windows zero-day hits European defence targets
Microsoft has patched a Windows privilege-escalation zero-day that Check Point says was exploited in a Lazarus-linked campaign targeting defence, aerospace, and aviation organisations, including victims in Europe.
-
DeadLock ransomware builds resilience around extortion
DeadLock has concentrated more than half of its claimed victims in Europe while using decentralised communications and leak infrastructure intended to make parts of its extortion operation harder to disrupt.






