Security vulnerabilities stories
Adidas has suffered a data breach via a third-party provider, exposing customer information and highlighting rising cyber risks in retail supply chains.
Picus Security launches Exposure Validation, a tool using real-time attack simulations to identify which vulnerabilities are truly exploitable in organisations.
Google DeepMind has unveiled a new strategy to bolster Gemini 2.5 AI against indirect prompt injection attacks, enhancing its security and resilience.
Nearly 42% of data breaches in top fintech firms stem from third-party vendors, highlighting critical supply chain vulnerabilities despite strong internal security.
Nearly 70% of organisations see AI, especially generative AI, as their top security risk, says Thales' 2025 Data Threat Report based on over 3,100 experts.
Tenable launches connectors and customisable dashboards in Tenable One, unifying security data from multiple tools to enhance risk visibility and management.
Lastwall's Identity Platform has earned FedRAMP Moderate Authorisation, enabling US federal agencies to deploy quantum-resistant Zero Trust cybersecurity solutions.
Kaspersky warns AI-generated passwords from ChatGPT, Llama, and DeepSeek often show predictable patterns, leaving users vulnerable to cyberattacks.
Immersive has launched AppSec Range Exercises, a live training tool to boost secure coding and improve application security in development teams.
Cloudhouse partners with ServiceNow to boost IT governance via integrated Guardian platform, enhancing application compatibility and infrastructure visibility.
Businesses are boosting cloud security efforts as rising cloud adoption brings complex risks, requiring new strategies to protect sensitive data and maintain compliance.
The Cloud Security Alliance's 2025 report reveals repeated cloud security failures, urging firms to bolster identity controls and shared defence measures.
OWASP has released its first Business Logic Abuse Top 10, spotlighting critical cross-domain threats beyond traditional technology-specific vulnerabilities.
Despite rising cyber threat awareness, only 14% of UK employees trained on security receive printer-specific training, leaving devices vulnerable.
Akamai has launched DNS Posture Management, offering centralised control over DNS assets across multicloud platforms to enhance security and compliance.
Distology partners with Flare to enhance threat intelligence and dark web monitoring for UK and European security resellers and MSSPs.
Cybercriminals increasingly target Australia's hospitality sector, exploiting digital gaps with sophisticated attacks and dark web services, Trustwave warns.
Luxury brand Dior and US steel producer Nucor both face major cyberattacks, exposing vulnerabilities in fashion and industrial sectors globally.
e2e-assure partners with Validato to offer businesses continuous cyber security validation, enhancing defence against evolving threats using MITRE ATT&CK framework.
Kaspersky reveals Lazarus Group's 'Operation SyncHole,' targeting South Korean supply chains via software vulnerabilities and watering hole attacks.