The Commission defines binding interpretation guidelines for the resilience requirements of the NIS2 Directive and thereby clarifies the implementation obligations for critical infrastructure operators.
Automated attack techniques accelerate vulnerability exploitation while traditional patch processes lag behind, and trusted software can become a threat.
The 15-year-old Linux kernel vulnerability GhostLock (CVE-2026-43499) enables root access via local threading calls on nearly all distributions, while patch distribution remains irregular.
CISA took over 48 hours to invalidate leaked AWS keys, ignored nine automatic security alerts, and had no defined incident reporting procedures for its own infrastructure.
The EU imposes sanctions on Russia for coordinated cyberattacks carried out jointly by intelligence agencies and criminal actors, also targeting German institutions.
AI security depends on governance and human accountability, not model size; increased computing power without organizational control only amplifies existing weaknesses.
Forg365 is a PhaaS service sold for 400 dollars monthly that combines device-code phishing and AitM attacks against Microsoft 365 and is optimized through antibot evasion and AI-powered lure automation.
Bosch is being extorted by ransomware group D1R with threats to publish design documentation and CAN protocol materials allegedly stolen via a Synopsys vulnerability.