Cyberattackers have stolen personal data belonging to 8.7 million customers of three major UK airports. The breach affects Manchester, Stansted and East Midlands airports, exposing emails, phone numbers, vehicle registrations and postcodes. The compromised information came from services including parking, lounges, Fast Track bookings and airport Wi-Fi. Manchester Airport Group temporarily disabled its “Manage My […]
Phocuswright sees that the EU Digital Identity Wallet is gaining ground, but adoption differs strongly between France, Germany, and the UK. Awareness is growing, France leads with 25%, while Germany shows the largest increase from 13% to 21%. Trust is decisive: 54% of Germans trust the Personalausweis, while trust in digital identity systems is clearly […]
Security researchers uncovered severe vulnerabilities in Belgium’s Connective eID signing software, used by more than 2 million citizens. The technology is deployed by 8 of Belgium’s 10 largest banks, more than 60 government agencies and over 1,000 enterprises. A fundamental weakness was that the software failed to properly verify which website was communicating with the […]
U.S. security agencies warn of active cyber threats targeting Siemens S7 PLCs, used across energy, water, manufacturing, and other critical infrastructure. Attackers are leveraging AI-generated exploits and internet scanning to identify and target exposed or poorly secured industrial control systems. AI makes ICS attacks faster and more accessible, reducing the level of specialized OT expertise […]
Researchers have uncovered new attack vectors that can undermine passkey authentication, challenging the idea that passwordless automatically means attack-proof. The attacks focus on weaknesses around the authentication flow and implementation, rather than breaking the underlying cryptography. Manipulation of WebAuthn processes, fallback mechanisms and compromised environments can potentially allow attackers to bypass or weaken passkey protection. […]
AI agents challenge traditional IAM by acting at machine speed and scale, with unpredictable access patterns that human-centric security models weren’t designed for. Prompt injection, credential exposure and multi-agent delegation create attack paths that conventional authentication and authorization controls struggle to govern. Existing behavioral monitoring can be effectively blind to autonomous agents, while ownership, accountability, […]
Gartner sees Verifiable Credentials (VCs) and decentralized identity as transformational technologies poised to reshape digital identity across industries. VCs enable standardized, secure and compliant data exchange between multiple parties at lower cost and higher speed. Instead of repeatedly proving identity, users can receive verified credentials once and reuse them cryptographically across services and transactions. Decentralized […]
Hackers breached the MyDr medical platform, potentially compromising sensitive data belonging to nearly 19 million Polish patients. The platform is used by thousands of clinics and medical practices, dramatically increasing the scale and impact of the breach. The stolen information reportedly includes highly sensitive medical data, with politicians and other public figures among those affected. […]
Apparel giant Levi Strauss & Co. recently disclosed a cybersecurity incident after attackers used targeted social engineering tactics to compromise three employees’ company computers. This initial breach allowed the attackers to gain access to internal files and successfully exfiltrate specific corporate information. Thanks to a rapid incident response, Levi’s managed to contain the intrusion effectively. […]
A new study maps 21 open-source AI risk tools against 32 risk categories, including Promptfoo, Garak, PyRIT, NeMo Guardrails and Langfuse. The ecosystem performs particularly well in AI testing, red teaming, content safety, data governance and post-deployment monitoring. But major gaps remain in board oversight, regulatory compliance, legal remedies and financial/market controls, areas software alone […]

