From the Desk
CISO & Security Leaders
Strategic threat landscape, regulatory changes, board-level risk intelligence.
20
Stories filed
4
Desks covered
≥ 7/10
Editorial floor
Coverage:RegulatoryThreat IntelComplianceSecurity
§
On the CISO & Security Leaders Desk
The latest stories filtered for your beat, organised by sub-section.
Threat Intel13 stories
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without AuthenticationMikroTik routers are widespread in European SME and branch-office networks; unauthenticated SSH takeover can give attackers a persistent foothold inside the perimeter.1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsA vendor's own environment was breached via a known TeamCity vulnerability, resulting in AWS credential exposure for downstream Cadence users — a textbook supply-chain compromise.2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchainOver 5,400 compromised small-business websites serving ClickFix payloads via blockchain-hosted smart contracts make takedown nearly impossible, raising prolonged supply-chain and brand-impersonation risk.2d
- New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web TrafficA supply-chain implant compiled directly into production HAProxy binaries represents a stealthy, persistent compromise vector that bypasses traditional file-integrity checks on config files.3d
- Angry Birds: Toy Ghouls’ new toys3d
- Version 1.0: Deutsche Institutionen über TerminalFix-Kampagne kompromittiertBSI has issued an active-exploitation warning indicating that German institutions have been compromised via the TerminalFix campaign — this is a high-confidence, nationally relevant threat.3d
- US offers $10 million for info on Iranian allegedly behind cyberattacks on critical infrastructureThe US $10 million bounty on the IRGC's cyber-unit leader underscores the escalating state-sponsored threat to critical infrastructure — European operators in energy and water should take note.4d
- Large Enterprises Targeted in Fake Merger & Acquisition ScamsThe 'Phantom Deal' campaign targets midlevel employees during M&A activity — a period of heightened trust and urgency that amplifies business-email-compromise risk.4d
- Large group of Serbian opposition, activist figures targeted with spywareState-level spyware deployment against political opposition within Europe directly implicates EU human rights norms and raises strategic questions about commercial surveillance technology governance.4d
- BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory4d
- 'Breeze Comet' Tears Into Brazilian & Global Financial SystemsA sophisticated Brazilian threat group targeting financial systems globally signals direct risk for European financial institutions with Latin American operations or correspondent banking relationships.4d
Security4 stories
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was DeletedTrezor's disclosure reveals that a third-party logistics provider retained customer data it was contractually obligated to delete, exposing 67K records — a cautionary tale for vendor data-lifecycle management.2d
- IDScan sued over alleged data breach affecting 153 million driversA breach of 153 million driver's licenses at an identity-verification vendor highlights catastrophic third-party risk for any organisation relying on outsourced ID checks.3d
- Your Employee’s Password Appeared in an Infostealer Log. Now What?Infostealer logs increasingly expose not just passwords but active sessions that bypass MFA, making identity compromise a board-level risk requiring updated incident-response playbooks.4d
- US and Canadian court data exposed in Thomson Reuters breachA breach exposing sealed court records and sensitive personal data from a major legal information provider highlights third-party data-aggregation risk relevant to any enterprise relying on similar services.4d
Compliance2 stories
- Compliance teams have gone continuous, but their evidence-gathering hasn’t caught up3d
- French hospital fined €500,000 after breach exposes data of 727,000A €500k CNIL fine against a French hospital for inadequate data protection shows European regulators are actively penalising healthcare providers, raising the bar for all sectors.4d