Hack Incident Response Malware Phishing

North Korean fake recruiters infect over 30,000 devices globally

North Korean state-sponsored hackers have successfully infected more than 30,000 devices worldwide by posing as legitimate corporate recruiters. The attackers use sophisticated social engineering tactics on professional networking platforms to trick unsuspecting job seekers into downloading malicious files disguised as job descriptions. Once executed, the malware grants the threat actors full remote access to steal […]

Incident Response Ransomware Security

FBI Cyber Strategy goes from defense to disruption

The FBI’s new cyber strategy shifts the focus toward actively disrupting adversaries, dismantling infrastructure, seizing funds and imposing real costs on attackers. Four pillars drive the strategy: disrupt cyber adversaries, support victims, strengthen partnerships, and enhance the FBI’s own cyber capabilities. Rapid intelligence sharing and closer public-private cooperation should help organizations detect attacks earlier, contain […]

Compliance Cybersecurity Data Breaches Incident Response

Berlin Cyberattack: stolen government data triggers crisis response

Following the publication of stolen data from Berlin’s administration, a central crisis unit led by the Chief Digital Officer has been established to coordinate the response. Police, cybersecurity authorities, data protection officials and affected government departments are jointly assessing the leaked information and potential risks. IT forensic investigations remain ongoing, with security-critical data and organisations […]

AI Compliance Cybersecurity Privacy Surveillance

Republicans turn against ai surveillance

Republican leaders are turning against Flock Safety, the $8bn AI-surveillance company whose licence-plate cameras have spread across the US. Governors Ron DeSantis and Greg Abbott have restricted Flock cameras or their funding, citing privacy risks, government overreach and documented misuse by law enforcement. The cameras can create a searchable record of vehicle movements, while newer […]

AI Cybersecurity Ethics Privacy

Ai surveillance as police can search for people based on a description

Flock Safety allows police to continuously search camera footage using AI for individuals matching a written description, such as clothing, color, or objects. WIRED reconstructed the interface and found that officers can geofence areas and receive automatic alerts as soon as the AI detects a potential match. Although Flock is introducing new controls, such as […]

Basic Privacy Training Cybersecurity Data Breach Data Protection Privacy

8.7 million airport customers hit by major UK data breach

Cyberattackers have stolen personal data belonging to 8.7 million customers of three major UK airports. The breach affects Manchester, Stansted and East Midlands airports, exposing emails, phone numbers, vehicle registrations and postcodes. The compromised information came from services including parking, lounges, Fast Track bookings and airport Wi-Fi. Manchester Airport Group temporarily disabled its “Manage My […]

Cybersecurity Digital Identity EIDAS

Belgian eID signing software critical flaws shake trust in digital identity

Security researchers uncovered severe vulnerabilities in Belgium’s Connective eID signing software, used by more than 2 million citizens. The technology is deployed by 8 of Belgium’s 10 largest banks, more than 60 government agencies and over 1,000 enterprises. A fundamental weakness was that the software failed to properly verify which website was communicating with the […]

AI Compliance Cybersecurity Infrastructure Security Risk management Security

AI lowers the barrier for attacks on industrial systems

U.S. security agencies warn of active cyber threats targeting Siemens S7 PLCs, used across energy, water, manufacturing, and other critical infrastructure. Attackers are leveraging AI-generated exploits and internet scanning to identify and target exposed or poorly secured industrial control systems. AI makes ICS attacks faster and more accessible, reducing the level of specialized OT expertise […]

Multifactor Authentication Password Management Risk management Vulnerability

Passkeys are strong, but not untouchable

Researchers have uncovered new attack vectors that can undermine passkey authentication, challenging the idea that passwordless automatically means attack-proof. The attacks focus on weaknesses around the authentication flow and implementation, rather than breaking the underlying cryptography. Manipulation of WebAuthn processes, fallback mechanisms and compromised environments can potentially allow attackers to bypass or weaken passkey protection. […]