Compliance Cybersecurity Data Breaches Incident Response

Berlin Cyberattack: stolen government data triggers crisis response

Following the publication of stolen data from Berlin’s administration, a central crisis unit led by the Chief Digital Officer has been established to coordinate the response. Police, cybersecurity authorities, data protection officials and affected government departments are jointly assessing the leaked information and potential risks. IT forensic investigations remain ongoing, with security-critical data and organisations […]

Basic Privacy Training Cybersecurity Data Breach Data Protection Privacy

8.7 million airport customers hit by major UK data breach

Cyberattackers have stolen personal data belonging to 8.7 million customers of three major UK airports. The breach affects Manchester, Stansted and East Midlands airports, exposing emails, phone numbers, vehicle registrations and postcodes. The compromised information came from services including parking, lounges, Fast Track bookings and airport Wi-Fi. Manchester Airport Group temporarily disabled its “Manage My […]

Cybersecurity Digital Identity EIDAS

Belgian eID signing software critical flaws shake trust in digital identity

Security researchers uncovered severe vulnerabilities in Belgium’s Connective eID signing software, used by more than 2 million citizens. The technology is deployed by 8 of Belgium’s 10 largest banks, more than 60 government agencies and over 1,000 enterprises. A fundamental weakness was that the software failed to properly verify which website was communicating with the […]

AI Compliance Cybersecurity Infrastructure Security Risk management Security

AI lowers the barrier for attacks on industrial systems

U.S. security agencies warn of active cyber threats targeting Siemens S7 PLCs, used across energy, water, manufacturing, and other critical infrastructure. Attackers are leveraging AI-generated exploits and internet scanning to identify and target exposed or poorly secured industrial control systems. AI makes ICS attacks faster and more accessible, reducing the level of specialized OT expertise […]

AI Cybersecurity Digital Identity Identity & Access Management Zero Trust

When AI agents break IAM then Identity becomes the fault line

AI agents challenge traditional IAM by acting at machine speed and scale, with unpredictable access patterns that human-centric security models weren’t designed for. Prompt injection, credential exposure and multi-agent delegation create attack paths that conventional authentication and authorization controls struggle to govern. Existing behavioral monitoring can be effectively blind to autonomous agents, while ownership, accountability, […]

AI Cybersecurity Risk management

Africa’s cyber threat surge: where AI supercharges digital crime

Cybercrime across Africa is evolving into a highly organized, AI-enabled ecosystem, with ransomware, business email compromise (BEC), online scams, data breaches, and digital sextortion driving unprecedented financial and societal damage. AI is accelerating phishing, deepfakes, identity fraud, and cybercrime-as-a-service, while weak legislation, limited cyber capabilities, and fragmented cross-border cooperation continue to benefit criminals. Financial services, […]

Cybersecurity Information Security Risk management Vulnerability

ENISA’s new CRA Maturity Model is a practical roadmap for SME Cyber Resilience

The European Union Agency for Cybersecurity (ENISA) has released a practical Cyber Resilience Maturity Assessment Model to help SMEs prepare for the Cyber Resilience Act (CRA) before it becomes fully applicable in December 2027. The model focuses on five key domains: governance, secure-by-design risk management, vulnerability & patch management, product lifecycle management, and cybersecurity skills. […]

Cybersecurity Hack Information Security Risk management Vulnerability

Autonomous AI agent breach signals a new era of cyber threats

Hugging Face disclosed a groundbreaking cyberattack in which an autonomous AI agent independently executed the entire intrusion—from initial compromise to privilege escalation and lateral movement. The attacker exploited vulnerabilities in the dataset-processing pipeline, performing more than 17,000 automated actions over a single weekend without direct human control. Although public models, datasets, and the software supply […]

Cybersecurity Personal data Privacy

UK pushes for tougher age checks as TikTok faces investigation

The UK’s communications regulator, Ofcom, is demanding stronger age verification measures from social media platforms ahead of a proposed social media age ban. The regulator has launched an investigation into TikTok, questioning whether its current age assurance methods effectively protect minors. Ofcom is also investigating dozens of adult websites and working with Google and Bing […]