The European Union Agency for Cybersecurity (ENISA) has released a practical Cyber Resilience Maturity Assessment Model to help SMEs prepare for the Cyber Resilience Act (CRA) before it becomes fully applicable in December 2027. The model focuses on five key domains: governance, secure-by-design risk management, vulnerability & patch management, product lifecycle management, and cybersecurity skills. […]
Hugging Face disclosed a groundbreaking cyberattack in which an autonomous AI agent independently executed the entire intrusion—from initial compromise to privilege escalation and lateral movement. The attacker exploited vulnerabilities in the dataset-processing pipeline, performing more than 17,000 automated actions over a single weekend without direct human control. Although public models, datasets, and the software supply […]
China’s National Computer Network Emergency Response Technical Team warned that the open-source AI agent OpenClaw has weak default security settings that attackers could exploit to gain system control. Attackers can use prompt injection, embedding malicious instructions in web pages to trick the AI into leaking sensitive data. Researchers showed that features like link previews in […]
The Canadian government intends to ban the Flipper Zero and similar devices, citing them as tools used by thieves for car theft. The Flipper Zero is a portable pen-testing tool capable of experimenting with and debugging various hardware and digital devices through multiple protocols like RFID, radio, NFC, infrared, and Bluetooth. Users have showcased the […]
The UK’s National Cyber Security Center (NCSC) has called on law firms in the country to arm themselves against ransomware. In 2021, eighteen law firms informed the British regulator SRA that they had fallen victim to a ransomware attack. Documents from 60 court cases were stolen from one law firm and then published on the […]
2023 Data Breach Investigations Report of which the dataset currentlycontains 953,894 incidents, of which 254,968 are confirmed breaches shows that the use of stolen credentials forms 44.7% of the cases. But what else can we learn? 74% of all breaches include the human element, with people being involved either via Error,Privilege Misuse, Use of stolen […]
There is an everlasting need to mitigate Web3 Blockchain risks and security threats. Web3 applications run on blockchain platforms and are gaining popularity, but they come with security risks. Smart contracts are a major source of risk, as they can contain vulnerabilities that can be exploited by attackers. Web3 applications are also vulnerable to phishing […]
Almost half of all Dutch company websites are vulnerable to attacks by cyber criminals due to vulnerabilities in software, configurations and web services. The result is often data theft or extortion through ransomware. “Entrepreneurs are insufficiently aware of the risks,” says cybersecurity specialist ID Control based on three studies of web shops, government websites and […]
The Bundesamt für Sicherheit in der Informationstechnik (BSI), part of the German Ministry of Internal Affairs, has investigated web shops which show that they are often unsafe. Seven out of ten researched webshop platforms use vulnerable JavaScript libraries. In addition, almost all solutions had inadequate password policies and nearly half of the products use end-of-life […]
A cybersecurity insurer predicts that a 13% growth to 1,900 CVEs monthly would include 270 high-severity and 155 critical-severity vulnerabilities. The predictions are based on data collected over the last ten years. For most CVEs, the time to exploit is within 90 days of public disclosure, while the majority of exploits take place within the […]

