loader image
EU Commission Proposes Cybersecurity Act Overhaul

The EU Commission proposes a revised Cybersecurity Act aimed at strengthening Europe’s cyber resilience and securing its information and communication technology supply chains. The update reflects growing concerns over digital infrastructure vulnerabilities and the increasing sophistication of cyberattacks targeting European markets and essential services. The proposed changes seek to expand the role of the European […]

EU Moves to Bar Huawei, ZTE From Critical Networks

In a decisive step to tighten control over its digital infrastructure, the EU moves to revise its cybersecurity rules to reduce reliance on high-risk suppliers. A draft proposal released Tuesday outlines updates to the EU’s Cybersecurity Act and the Network Information Systems Directive. If adopted, the changes would require member states to gradually eliminate the […]

GCVE Launches Decentralized Vulnerability Registry

A European cybersecurity group has unveiled a major shift in how software flaws are cataloged as the GCVE launches a decentralized vulnerability system. This new system departs from traditional centralized databases, offering a more distributed method to identify and assign numbers to security vulnerabilities. The innovation could dramatically reshape how developers, researchers and organizations track […]

Orval Hit by Critical Code-Injection Flaw

The open-source tool Orval, used by developers to generate type-safe clients from OpenAPI specifications, has been hit by a vulnerability that experts rate as critical. According to a security alert published earlier today, the flaw allows for potential code injection and carries a CVSS score of 9.3, indicating severe risk. Security researchers have linked the […]

Zendesk Tickets Hijacked in Global Spam Wave

A widespread spam campaign is exploiting vulnerable helpdesk systems, with Zendesk tickets hijacked to send out floods of unwanted emails globally. Victims have reported receiving hundreds of messages through compromised support channels. The emails arrive with strange, sometimes alarming subject lines, raising concerns about potential phishing or malware distribution. Security researchers say the spam appears […]

MITRE Unveils ESTM 3.0 to Secure Embedded Systems

MITRE unveils ESTM 3.0, a cybersecurity framework designed to strengthen protections for embedded systems used across critical infrastructure sectors. The latest version of the Embedded System Security Technical Mitigations (ESTM) framework introduces updated guidelines aimed at addressing evolving cyber threats, particularly in environments such as energy, transportation, and manufacturing. The 3.0 release offers enhanced capabilities […]

Cisco Unified CM Zero-Day Under Attack

Hackers are actively exploiting a Cisco Unified CM zero-day vulnerability that allows remote code execution without authentication, prompting the company to release an urgent security fix. Identified as CVE-2026-20045, the flaw affects Cisco’s communication platform and poses a critical risk to organizations relying on the software for enterprise connectivity. The company issued patches to address […]

EU to Force Removal of High-Risk Telecom Suppliers

The European Union is preparing a major cybersecurity overhaul that would require telecom operators to exclude high-risk foreign suppliers from core infrastructure. This legislative proposal, introduced by the European Commission, aims to fortify the EU’s digital defenses amid growing threats from state-sponsored hackers and cybercriminals targeting critical services. Under the new plan, member states must […]

Everest Ransomware Claims McDonald’s India Breach

A ransomware group known as Everest ransomware claims a McDonald’s India data breach that reportedly exposed sensitive customer information. The attackers say they accessed and exfiltrated internal company data, including customer records tied to the fast-food giant’s operations in India. A screenshot posted online appears to show folders containing financial records, HR information, and client […]

Poland President Vetoes Digital Services Act

Poland President vetoes a key legislative act, halting the country’s plans to implement the Digital Services Act (DSA) after two years of negotiations. The veto sends the process back to the drawing board, requiring legislators to start from scratch. The long-awaited implementation was intended to align Poland with the European Union’s digital framework, but the […]

EU’s GCVE Cuts Reliance on Global Systems

The European Union has launched its own public vulnerability platform, marking a notable advancement in digital sovereignty. The EU’s GCVE cuts reliance on global systems, such as the U.S.-based Common Vulnerabilities and Exposures (CVE), by offering a European-managed alternative for tracking cybersecurity flaws. Operated under the GCVE initiative, the newly live EU Vulnerability Database enables […]

EDRi Seeks EU-Wide Spyware Ban

European Digital Rights (EDRi) seeks a spyware ban across the EU with the launch of a new document pool focused on surveillance technologies. The pool compiles EDRi’s research, advocacy, and policy analysis, alongside selected third-party materials, to support a comprehensive ban on spyware. By centralizing resources, EDRi aims to bolster transparency and equip civil society […]