Security Wire
A curated security and critical-infrastructure wire, filtered through an Irish and EU lens. It pulls a basket of security-news sources and surfaces the slice touching sovereignty-relevant infrastructure — energy, health, telecom and subsea cable, water, government, finance and transport — dropping the global firehose.
-
Global Government
China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans
China's military has begun restricting procurement from top domestic cybersecurity firms, though technical failures are not cited as the reason.
-
Global Government
Trump administration unveils AI-supported clearinghouse for cyber vulnerabilities
Trump administration launches Gold Eagle, an AI-powered platform enabling industry and critical infrastructure operators to detect, prioritize and patch cybersecurity vulnerabilities faster.
-
Global Government
Trump’s DNI pick grilled about election security, voter fraud
Trump's director of national intelligence nominee Jay Clayton faced Senate questioning on election security and voter fraud claims during confirmation hearings.
-
Global Government
LAPD sidelines relationship with license-plate reader company Flock Safety
Los Angeles Police Department suspends use of Flock Safety's automatic license-plate readers, joining other U.S. municipalities reassessing the surveillance technology's deployment.
-
Global Energy & Grid
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell
Siemens, Schneider Electric, and Rockwell Automation released patches for dozens of industrial control system vulnerabilities; CISA and German VDE CERT issued corresponding advisories.
-
Global Transport & Ports
NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Russian state-backed actors are using hacked internet-connected cameras across Europe to surveil NATO logistics and Ukrainian military positions, Dutch intelligence agencies report.
-
EU
EU leaders eye social media ban for children under age 13
EU leaders propose minimum age restriction of 13 for social media access, with implementation left to individual member states and parental discretion.
-
Global Government
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
Russian state-sponsored actors exploit misconfigured routers across critical infrastructure sectors globally, including energy, healthcare and telecommunications networks.
-
EU Government Lead
EU sanctions Russian GRU military hackers over cyberattacks
EU and UK imposed sanctions on Russian GRU military hackers and associated entities for coordinated cyberattacks targeting European infrastructure and networks.
-
EU Government Lead
EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign
EU imposes sanctions on Russian intelligence officers accused of running a years-long cyber-spying campaign targeting government and critical infrastructure.
-
Global Health
Centers Laboratory Data Breach Affects 540,000 Individuals
WorldLeaks extortion group claimed to steal 720 GB of data from healthcare testing provider Centers Laboratory, affecting 540,000 individuals.
-
Global Transport & Ports
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
Security researchers exposed three active phishing operations targeting Microsoft 365 after discovering a misconfigured server with exposed toolkits and operator credentials.
-
EU Energy & Grid Lead
Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions
UK and EU impose first joint cyber sanctions against Russia's FSB unit for attacks on Poland's energy and water infrastructure, plus broader malicious activities.
-
Global Government
Europe revives law allowing big tech to scan for CSAM
European Parliament approved Chat Control 2.0, requiring tech firms to scan user messages for child sexual abuse material, affecting millions across EU.
-
Global Telecom & Subsea
Police suspects Dutch hackers were involved in Odido breach
Dutch National Police report strong indications that Dutch hackers were involved in a February breach at telecom provider Odido, affecting EU critical infrastructure.
-
Global Government
Money launderer accused of stealing seized crypto while in prison
Bulgarian prisoner charged with stealing $290,000 in government-seized cryptocurrency while incarcerated for previous money laundering offences.
-
Global Telecom & Subsea
Dutch police trace Odido telco cyberattack to suspected local accomplice
Dutch police identified a suspected local accomplice in the Odido telecom cyberattack that compromised data of over six million customers, implicating Dutch criminals in the breach.
-
Global Government
UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge
UK government launches agentic AI cybersecurity defence plan with industry pledge; Ireland and EU should note UK's autonomous AI security approach divergence.
-
Ireland Lead
EU takes member states to court over unimplemented cybersecurity law
EU initiates legal action against Ireland, Spain, France, and Netherlands for failing to transpose NIS2 critical infrastructure cybersecurity directive over 20 months past deadline.
-
Global Government
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
AI-accelerated cyberattacks now compress multi-day campaigns into minutes, outpacing traditional defence workflows designed for slower threat landscapes.
-
Global Energy & Grid
Schneider Electric Easergy MiCOM Px40 Series
Schneider Electric disclosed a vulnerability in its Easergy MiCOM Px40 Series protection relays used in medium and high voltage grid infrastructure across Europe.
-
Global Transport & Ports
Summer of Clearinghouses
Security researchers established multiple vulnerability clearinghouses recently; one firm's Athena system had been operational quietly for months before public announcement.
-
Global Government
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
Researchers identified GodDamn ransomware, which uses PoisonX kernel driver to disable endpoint security software before encrypting systems.
-
Global Finance
AssuranceAmerica data breach exposes records of 6.9 million drivers
US insurance firm AssuranceAmerica disclosed a breach affecting 6.9 million drivers' records after attackers accessed its systems in early 2024.
-
Global Finance
Cash App owner to pay $45 million to settle allegations of lax security
Block Inc., owner of Cash App, will pay $45 million to settle allegations it misrepresented security protections to users and failed adequate safeguards.
-
Global Finance
SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users
Mexican banking malware campaign uses fake CAPTCHA pages to trick users into executing commands; similar tactics could be adapted for EU financial sector targets.
-
Global Telecom & Subsea
Telco giant KDDI says data breach affects over 12 million people
Japanese telecoms giant KDDI confirms breach affecting over 12 million people's email addresses and passwords across five ISPs' shared platform.
-
Global Government
CISA orders feds to patch max severity ColdFusion flaw by Friday
U.S. CISA mandates federal agencies patch critical Adobe ColdFusion vulnerability by Friday amid active exploitation reports.
-
Global Government
County Government Reportedly Paid $1 Million to Cyber Extortion Group
A U.S. county government reportedly paid $1 million to a cyber extortion group to prevent release of stolen sensitive data.
-
Global Finance
RedWing MaaS Packages Android Bank Fraud as a Telegram Rental Service
RedWing malware-as-a-service on Telegram enables low-skill criminals to steal banking credentials and authentication codes from Android users' devices across potentially affected EU financial systems.
-
Global Energy & Grid
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
GitHub Actions workflows can evade traditional CI security scanners, leaving development pipelines vulnerable despite passing security checks.
-
Global Government
CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws
US cybersecurity agency CISA is reportedly using Anthropic's AI tool to scan government software for vulnerabilities as part of its attack surface evaluation programme.
-
Global Finance
UK cyber pledge draws only a handful of top firms despite ministerial appeal
UK government's cybersecurity pledge attracts limited uptake from major firms, with only Aviva, London Stock Exchange Group and Marks & Spencer among signatories.
-
Global Government
Webinar tomorrow: Why modern email attacks require a new approach to defense
Upcoming webinar examines how behavioral AI can improve detection of sophisticated phishing and business email compromise attacks while reducing security alert fatigue.
-
Global Energy & Grid
Siemens Mendix Studio Pro
Siemens released patches for Mendix Studio Pro vulnerability allowing arbitrary code execution through malicious project files during build processes.
-
Global Energy & Grid
What Changes When Your Software Supply Chain Includes AI Writing Your Code?
AI-generated code in software supply chains creates new security risks alongside traditional dependency vulnerabilities, complicating verification processes for enterprises.
-
Global Government
Iran-Linked Hackers Use New Cavern C2 Framework to Target Israeli Organizations
Iranian state-linked hackers deployed a new command-and-control framework targeting Israeli IT providers and government sectors, according to cybersecurity researchers.
-
Global Health
Major medical device manufacturer notifies nearly 4 million of breach
Medical device manufacturer breached, affecting nearly 4 million people's Social Security numbers and health data; company reports no public disclosure evidence.
-
Global Government
Armored Likho APT Targeting Government, Electric Power Entities
Armored Likho APT group targets government and electric power sector entities using modular remote access trojans and information-stealing malware for financial gain and espionage.
-
Global Energy & Grid
Suspected China-Nexus Hackers Use Fake Indian Tax Filing Utility to Deploy DcRAT
China-linked hackers deployed malware disguised as an Indian tax utility to target taxpayers and finance professionals, attempting to steal sensitive data via remote access trojan.
-
Global Telecom & Subsea
New TrojPix Attack Leaks Data From Air-Gapped Systems via Video Cable Emissions
Researchers demonstrate TrojPix attack extracting data from isolated computers via imperceptible pixel manipulation and video cable emissions, requiring prior malware infection.
-
Global Government
U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case
US federal agency paid $1 million to data-theft extortionists calling themselves Kairos to prevent leak of stolen files, according to blockchain analysis.
-
Global Energy & Grid
Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer
Threat actor Armored Likho deployed BusySnake stealer against government agencies and power sector entities in Russia, Brazil, and Kazakhstan, combining financial fraud with espionage operations.
-
Global Government
European Parliament Member Investigating Spyware Was Hacked With Pegasus
Former EU Parliament member investigating Pegasus spyware was targeted with the same surveillance tool while serving on an oversight committee examining its misuse.
-
Global Government
Spyware found on phone of European Parliament member probing it
European Parliament member Stelios Kouloglou, who investigated commercial spyware misuse, was infected twice with Pegasus spyware while serving on the investigative committee.
-
EU
Supreme Court decision threatens EU-US data transfer agreement
Austrian privacy activist Max Schrems plans legal action to invalidate the EU-US Data Privacy Framework allowing personal data transfers to American companies.
-
EU
Google loses final appeal to overturn €4.1 billion EU fine
EU Court of Justice upholds €4.1 billion antitrust fine against Google for using Android to unfairly promote Chrome browser and search services.
-
Global Health
Medtronic notifies customers impacted by ShinyHunters data breach
Medtronic has notified customers of a data breach exposing personal information, with potential implications for EU healthcare infrastructure dependent on the device manufacturer.
-
Global Transport & Ports
Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters
Unpatched vulnerability in Argo CD repo-server allows unauthenticated code execution and potential Kubernetes cluster takeover; no fix currently available.
-
Global Finance
Ousaban Banking Trojan Targets Iberian Bank Users with Fake PDF Lures
Ousaban banking trojan targets Spanish and Portuguese bank users via phishing PDFs; EU financial infrastructure threatened by Brazil-linked malware campaign.
-
Global Government
US lifts export controls on Anthropic’s frontier cybersecurity AI models
US removes export restrictions on Anthropic's advanced AI cybersecurity models following government agreements, potentially expanding the company's reach to international markets including the EU.
-
Global Energy & Grid
Frangoteam FUXA SCADA/HMI
Frangoteam FUXA SCADA/HMI contains a vulnerability allowing unauthenticated remote attackers to enumerate user accounts and role assignments on industrial control systems.
-
Global Government
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
China-linked hacking group Mustang Panda exploited Zoho WorkDrive to command malware in Indian government and hydropower sector networks.
-
Global Finance
Lessons for life: Why children’s data is a long-term identity risk
Children's early data breaches pose long-term identity theft risks; experts advise parents on protecting minors' digital information from collection and misuse.
-
Global Water
This month in security with Tony Anscombe – May 2026 edition
Polish water treatment facilities suffered cyberattacks; Google identified first AI-generated zero-day exploit; AI-directed attacks failed against Mexican infrastructure.
-
EU
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
Dutch authorities arrested two men operating hosting companies that provided infrastructure for Russian cyberattacks, influence operations and disinformation targeting EU members, seizing 800 servers.
-
Global Government
GopherWhisper: A burrow full of malware
ESET researchers identified GopherWhisper, a China-aligned advanced persistent threat group targeting Mongolian government institutions with malware.
-
Global Energy & Grid
DynoWiper update: Technical analysis and attribution
ESET researchers provide technical analysis of DynoWiper malware used in a data destruction attack against a Polish energy sector company.
-
Global Energy & Grid
ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025
ESET researchers attribute a cyberattack on Poland's power grid in late 2025 to Russian state-sponsored group Sandworm, involving previously undocumented data-wiping malware.
-
Global Government
LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan
ESET researchers identified China-aligned APT group LongNosedGoblin targeting Southeast Asian and Japanese government networks using Group Policy for cyberespionage tool deployment.
Headlines, short summaries and links only — full articles remain with their publishers, and each item links back to the source. Aggregated automatically; classification is keyword-derived and may miss or mislabel. Independent, no images, no tracking.