Compliance Cybersecurity Data Breaches Incident Response

Berlin Cyberattack: stolen government data triggers crisis response

Following the publication of stolen data from Berlin’s administration, a central crisis unit led by the Chief Digital Officer has been established to coordinate the response. Police, cybersecurity authorities, data protection officials and affected government departments are jointly assessing the leaked information and potential risks. IT forensic investigations remain ongoing, with security-critical data and organisations […]

Basic Privacy Training Cybersecurity Data Breach Data Protection Privacy

8.7 million airport customers hit by major UK data breach

Cyberattackers have stolen personal data belonging to 8.7 million customers of three major UK airports. The breach affects Manchester, Stansted and East Midlands airports, exposing emails, phone numbers, vehicle registrations and postcodes. The compromised information came from services including parking, lounges, Fast Track bookings and airport Wi-Fi. Manchester Airport Group temporarily disabled its “Manage My […]

Cybersecurity Digital Identity EIDAS

Belgian eID signing software critical flaws shake trust in digital identity

Security researchers uncovered severe vulnerabilities in Belgium’s Connective eID signing software, used by more than 2 million citizens. The technology is deployed by 8 of Belgium’s 10 largest banks, more than 60 government agencies and over 1,000 enterprises. A fundamental weakness was that the software failed to properly verify which website was communicating with the […]

AI Compliance Cybersecurity Infrastructure Security Risk management Security

AI lowers the barrier for attacks on industrial systems

U.S. security agencies warn of active cyber threats targeting Siemens S7 PLCs, used across energy, water, manufacturing, and other critical infrastructure. Attackers are leveraging AI-generated exploits and internet scanning to identify and target exposed or poorly secured industrial control systems. AI makes ICS attacks faster and more accessible, reducing the level of specialized OT expertise […]

Multifactor Authentication Password Management Risk management Vulnerability

Passkeys are strong, but not untouchable

Researchers have uncovered new attack vectors that can undermine passkey authentication, challenging the idea that passwordless automatically means attack-proof. The attacks focus on weaknesses around the authentication flow and implementation, rather than breaking the underlying cryptography. Manipulation of WebAuthn processes, fallback mechanisms and compromised environments can potentially allow attackers to bypass or weaken passkey protection. […]

AI Cybersecurity Digital Identity Identity & Access Management Zero Trust

When AI agents break IAM then Identity becomes the fault line

AI agents challenge traditional IAM by acting at machine speed and scale, with unpredictable access patterns that human-centric security models weren’t designed for. Prompt injection, credential exposure and multi-agent delegation create attack paths that conventional authentication and authorization controls struggle to govern. Existing behavioral monitoring can be effectively blind to autonomous agents, while ownership, accountability, […]

Compliance Data Breaches Privacy

Massive MyDr cyberattack exposes medical data of nearly 19 million Poles

Hackers breached the MyDr medical platform, potentially compromising sensitive data belonging to nearly 19 million Polish patients. The platform is used by thousands of clinics and medical practices, dramatically increasing the scale and impact of the breach. The stolen information reportedly includes highly sensitive medical data, with politicians and other public figures among those affected. […]

Data Breaches Incident Response Social engineering

Levi Strauss hit by social engineering cyberattack

Apparel giant Levi Strauss & Co. recently disclosed a cybersecurity incident after attackers used targeted social engineering tactics to compromise three employees’ company computers. This initial breach allowed the attackers to gain access to internal files and successfully exfiltrate specific corporate information. Thanks to a rapid incident response, Levi’s managed to contain the intrusion effectively. […]

Data Protection Data Rights Encryption Privacy Privacy Procedures and Policy

Apple vs. UK where encryption showdown enters a new chapter

Apple is challenging the UK government’s renewed demand for access to encrypted iCloud backups of British users through the Investigatory Powers Tribunal. The tech giant reiterates it will never build a backdoor into its products, arguing it would weaken security for everyone. The UK says lawful access is essential for tackling terrorism, serious crime, and […]