Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 4 of 36

76–100 of 879
highCampaignActive

Vastaamo psychotherapy breach: international manhunt reveals ongoing fugitive status of alleged attacker

Finnish authorities have issued a wanted notice for a suspect linked to the Vastaamo psychotherapy data breach, with the defendant's legal counsel indicating the individual is believed to be outside Finland. This suggests the investigation remains active and potentially unresolved months or years after the initial breach.

Vastaamo (Finnish psychotherapy clinic chain)
criticalVulnerabilityActive

DIRAC FileCatalog RCE via SQL Injection + Unsafe eval() in DatasetManager

Authenticated SQL injection in DIRAC's FileCatalog DatasetManager allows attackers to inject malicious Python code that executes via eval(), resulting in remote code execution with service privileges. This disclosure is significant for defenders because it demonstrates a two-stage attack chain (injection → unsafe deserialization) that may exist in other components.

CVE-2026-61667
DIRACGrid/DIRAC
informationalPolicyEmerging

EU age-gating proposal targets social media access for under-13s: regulatory shift with implementation challenges

The European Commission is proposing a regulatory framework to restrict social media access for children under 13, representing a significant policy shift toward age verification and platform accountability. This marks a move beyond current self-regulatory approaches but faces substantial technical and enforcement barriers.

Meta, TikTok, Snapchat +3
highCampaignActive

Concurrent Chinese and Indian intelligence operations against Pakistani law enforcement reveal strategic divergence in South Asian cyber espionage

Chinese and Indian state-sponsored actors conducted separate espionage campaigns targeting the same Pakistani police organisation, each motivated by distinct geopolitical interests in Pakistan's internal security apparatus. This convergence demonstrates how critical infrastructure becomes a contested domain when multiple regional powers perceive overlapping strategic value.

Pakistani law enforcement agencies
informationalToolEmerging

Post-Quantum Cryptography Governance Emerges as Venture-Backed Priority

QIZ Security, an Israeli cryptographic posture management startup, has secured $17 million in funding to commercialise a platform addressing cryptographic governance and post-quantum cryptography readiness. This reflects growing enterprise demand for centralised crypto inventory and compliance tooling ahead of quantum-resistant algorithm transitions.

QIZ Security (vendor), Enterprise organisations using proprietary or legacy cryptographic implementations