<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>CipherWatch — Security &amp; Risk Management</title><description>Security intelligence covering Security &amp; Risk Management: Governance, compliance, ethics, risk frameworks, legal regulations, and business continuity planning.</description><link>https://cipherwatch.io/</link><language>en-gb</language><item><title>DOJ Seizes CFAKE.com and SOCFAKE.com in First Criminal Enforcement Under the TAKE IT DOWN Act</title><link>https://cipherwatch.io/articles/2026-06-16-doj-seizes-cfake-socfake-take-it-down-act-deepfake/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-16-doj-seizes-cfake-socfake-take-it-down-act-deepfake/</guid><description>US authorities seized two of the largest non-consensual deepfake pornography platforms in a joint operation with French and Italian law enforcement, marking the first major criminal enforcement action under the TAKE IT DOWN Act signed into law in May 2025. A French national was arrested in Nice on 10 June; cryptocurrency proceeds have been seized pending forfeiture.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>deepfake</category><category>legislation</category><category>take-it-down-act</category><category>doj</category><category>ai-misuse</category><category>non-consensual-imagery</category></item><item><title>Europol Dismantles AudiA6 Cryptocurrency Laundering Service That Processed €336M+ for Ransomware Gangs</title><link>https://cipherwatch.io/articles/2026-06-15-europol-audia6-crypto-laundering-ransomware/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-15-europol-audia6-crypto-laundering-ransomware/</guid><description>Europol, in coordination with German BKA, Dutch FIOD, and Lithuanian law enforcement, has dismantled AudiA6 — a professional cryptocurrency money laundering service that processed more than €336 million in criminal proceeds for ransomware groups including Conti, REvil, and BlackCat/ALPHV. Seven individuals have been arrested across three countries and the service&apos;s infrastructure seized.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>europol</category><category>cryptocurrency</category><category>money-laundering</category><category>ransomware</category><category>law-enforcement</category><category>audia6</category><category>financial-crime</category><category>takedown</category></item><item><title>AI Workflow Builder Security Governance: Langflow CVE-2026-5027 and the Unmanaged AI Tool Problem</title><link>https://cipherwatch.io/articles/2026-06-13-ai-workflow-security-governance-langflow-risk/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-13-ai-workflow-security-governance-langflow-risk/</guid><description>Langflow CVE-2026-5027&apos;s active exploitation is accelerating because many enterprise Langflow deployments are outside the formal IT security perimeter — deployed by data science and developer teams without security review, not in the CMDB, not in the vulnerability scanning scope. This article provides a governance framework for bringing AI workflow tools under security management.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate><category>langflow</category><category>cve-2026-5027</category><category>ai-governance</category><category>shadow-it</category><category>risk-management</category><category>vulnerability-management</category><category>ai-tools</category><category>enterprise-security</category><category>procurement</category></item><item><title>Enterprise Guide: Prioritising the June 2026 Patch Tuesday Across 198 CVEs</title><link>https://cipherwatch.io/articles/2026-06-11-june-2026-patch-tuesday-enterprise-prioritisation/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-11-june-2026-patch-tuesday-enterprise-prioritisation/</guid><description>Security teams face 198 CVEs from Microsoft&apos;s June 2026 Patch Tuesday plus concurrent advisories from SAP, Ivanti, Palo Alto, and CISA. This guide provides a decision framework for prioritising remediation across different infrastructure tiers — from internet-facing servers to workstations — with specific guidance for each of the highest-risk vulnerabilities.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>patch-management</category><category>risk-management</category><category>microsoft</category><category>patch-tuesday</category><category>vulnerability-management</category><category>enterprise-security</category><category>remediation</category><category>cvss</category><category>2026</category></item><item><title>SAP June 2026 Security Patch Day: CVSS 9.9 SAML Authentication Bypass CVE-2026-44748 in NetWeaver ABAP</title><link>https://cipherwatch.io/articles/2026-06-09-sap-netweaver-cve-2026-44748-saml-bypass-cvss-9-9/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-09-sap-netweaver-cve-2026-44748-saml-bypass-cvss-9-9/</guid><description>SAP&apos;s June 2026 Security Patch Day includes CVE-2026-44748, a CVSS 9.9 authentication bypass in SAP NetWeaver Application Server ABAP that allows unauthenticated remote attackers to forge SAML assertions and impersonate any user including system administrators. Twenty-one additional CVEs were patched, including three rated Critical.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>sap</category><category>netweaver</category><category>abap</category><category>cve-2026-44748</category><category>saml</category><category>authentication-bypass</category><category>cvss-9-9</category><category>erp-security</category><category>enterprise-applications</category></item><item><title>OpenAI Rolls Out ChatGPT Lockdown Mode to Block Prompt-Injection Data Exfiltration</title><link>https://cipherwatch.io/articles/2026-06-06-openai-chatgpt-lockdown-mode-enterprise-ai-security/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-06-openai-chatgpt-lockdown-mode-enterprise-ai-security/</guid><description>OpenAI has released ChatGPT Lockdown Mode, a security configuration that prevents ChatGPT from loading external URLs, rendering images from arbitrary sources, or executing third-party plugin calls — the primary vectors for prompt-injection attacks that cause ChatGPT to exfiltrate data to attacker-controlled endpoints. Enterprise and education customers can now enforce Lockdown Mode organisation-wide via the admin console.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><category>openai</category><category>chatgpt</category><category>prompt-injection</category><category>ai-security</category><category>lockdown-mode</category><category>enterprise-ai</category><category>data-exfiltration</category><category>llm-security</category></item><item><title>Verizon DBIR 2026: Vulnerability Exploitation Surpasses Phishing as Top Initial Access Vector — Enterprise Implications</title><link>https://cipherwatch.io/articles/2026-06-05-verizon-dbir-2026-vulnerability-exploitation-breach-vector/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-05-verizon-dbir-2026-vulnerability-exploitation-breach-vector/</guid><description>Verizon&apos;s 2026 Data Breach Investigations Report, published mid-May, documents a structural shift in breach methodology: vulnerability exploitation has overtaken phishing as the most common initial access pathway in analysed breaches. The shift reflects a maturing attacker ecosystem that increasingly uses automated exploit delivery rather than requiring human interaction. Enterprise security programmes built around phishing awareness need recalibration.</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>verizon-dbir</category><category>vulnerability-management</category><category>breach-analysis</category><category>threat-intelligence</category><category>initial-access</category><category>patch-management</category><category>2026</category></item><item><title>Healthcare Ransomware Business Continuity: Prioritising Recovery When Clinical Systems Go Down</title><link>https://cipherwatch.io/articles/2026-06-04-ransomware-healthcare-business-continuity-recovery/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-04-ransomware-healthcare-business-continuity-recovery/</guid><description>When ransomware hits a healthcare organisation, the recovery sequence matters as much as the containment response. Clinical systems have dependencies that make naive &apos;restore in alphabetical order&apos; approaches catastrophic. This guide covers healthcare-specific BCP prioritisation for ransomware recovery, including the clinical dependency chain that drives sequencing decisions.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate><category>ransomware</category><category>healthcare</category><category>business-continuity</category><category>incident-response</category><category>recovery</category><category>bcp</category><category>clinical-systems</category><category>disaster-recovery</category></item><item><title>ITSM Platform Security Governance: Why ServiceNow, Jira, and Freshservice Are High-Value Targets</title><link>https://cipherwatch.io/articles/2026-06-02-itsm-platform-security-governance-servicenow-jira/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-02-itsm-platform-security-governance-servicenow-jira/</guid><description>The ServiceNow API breach this week highlights a category of platform that organisations consistently underestimate as an attack target: IT Service Management tools. ITSM platforms aggregate privileged information about the organisation&apos;s infrastructure, credentials, and operational processes — making them a high-value target and a high-consequence breach.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>servicenow</category><category>itsm</category><category>jira</category><category>freshservice</category><category>platform-security</category><category>risk-management</category><category>data-governance</category><category>credential-security</category></item><item><title>Enterprise Java Middleware Security Governance: Bringing WebLogic and JBoss into the Vulnerability Management Programme</title><link>https://cipherwatch.io/articles/2026-06-01-enterprise-middleware-security-governance-weblogic/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-06-01-enterprise-middleware-security-governance-weblogic/</guid><description>Oracle WebLogic, Red Hat JBoss/WildFly, and IBM WebSphere are foundational enterprise application infrastructure that frequently falls outside the scope of corporate vulnerability management programmes. CVE-2024-21182&apos;s CISA KEV addition — 18 months after the patch — reflects what happens when middleware is governed outside the security programme.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>oracle</category><category>weblogic</category><category>middleware</category><category>vulnerability-management</category><category>governance</category><category>enterprise-java</category><category>risk-management</category><category>application-security</category></item><item><title>Q2 2026 Enterprise Threat Landscape: Unprecedented Vulnerability Density and What It Means for Security Programmes</title><link>https://cipherwatch.io/articles/2026-05-31-q2-2026-enterprise-threat-landscape-vulnerability-density/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-31-q2-2026-enterprise-threat-landscape-vulnerability-density/</guid><description>Q2 2026 (April–June) has produced more simultaneous high-severity vulnerabilities in enterprise-critical infrastructure than any comparable period in recent years. Netlogon CVSS 9.8, three CVSS 10.0 in UniFi OS, AMD microarchitecture flaws, Linux kernel LPEs, and two Citrix exploitation waves — analysing the pattern reveals structural implications for how enterprises manage vulnerability risk.</description><pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate><category>vulnerability-management</category><category>threat-landscape</category><category>q2-2026</category><category>risk-management</category><category>enterprise-security</category><category>vulnerability-density</category><category>ciso</category></item><item><title>May 2026 Vulnerability Retrospective: Patch Prioritisation Guide for Enterprise Security Teams</title><link>https://cipherwatch.io/articles/2026-05-30-may-2026-vulnerability-retrospective-patch-prioritisation/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-30-may-2026-vulnerability-retrospective-patch-prioritisation/</guid><description>May 2026 produced an unusually dense cluster of high-severity vulnerabilities: Netlogon CVSS 9.8, Ubiquiti CVSS 10.0 × 3, AMD Zen 2 CVSS 8.8, golang/crypto CVSS 10.0, Linux ptrace four-exploit-chain. This retrospective ranks them by risk for organisations still working through the patching backlog.</description><pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate><category>patch-management</category><category>vulnerability-prioritisation</category><category>may-2026</category><category>risk-management</category><category>ciso</category><category>enterprise-security</category><category>retrospective</category></item><item><title>Netlogon CVE-2026-41089: Enterprise Risk Management Framework for Active Directory Compromise Scenarios</title><link>https://cipherwatch.io/articles/2026-05-29-netlogon-vulnerability-enterprise-risk-management/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-29-netlogon-vulnerability-enterprise-risk-management/</guid><description>A CVSS 9.8 vulnerability with active exploitation and a public PoC against domain controllers requires risk management decisions at the business level, not just patching at the technical level. This guide covers the risk assessment, escalation triggers, and business continuity considerations that security leadership should present to boards and executives.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><category>risk-management</category><category>active-directory</category><category>netlogon</category><category>cve-2026-41089</category><category>business-continuity</category><category>incident-response</category><category>governance</category><category>ciso</category></item><item><title>Developer Workstations as Supply-Chain Risk: Governance Framework for Engineering Environments</title><link>https://cipherwatch.io/articles/2026-05-27-developer-workstation-supply-chain-risk-management/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-27-developer-workstation-supply-chain-risk-management/</guid><description>TeamPCP&apos;s simultaneous three-vector attack on developer tooling reveals a governance gap that exists in most organisations: developer workstations accumulate privileged access over time but operate outside the security governance processes that manage server infrastructure. A developer machine with production credentials is server-equivalent infrastructure.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><category>developer-security</category><category>supply-chain</category><category>risk-management</category><category>governance</category><category>credential-security</category><category>workstation-security</category></item><item><title>Food and Beverage Sector Ransomware: Why Critical Infrastructure Classification Has Not Improved Security Outcomes</title><link>https://cipherwatch.io/articles/2026-05-26-food-sector-ransomware-critical-infrastructure-risk/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-26-food-sector-ransomware-critical-infrastructure-risk/</guid><description>The US food and agriculture sector was designated critical infrastructure in 2003. In 2026, ransomware attacks against it are rising 80 per cent year on year. The gap between regulatory classification and actual security maturity reflects structural problems in how cybersecurity investment decisions are made in distributed, margin-sensitive industries.</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>critical-infrastructure</category><category>food-sector</category><category>ransomware</category><category>regulatory-compliance</category><category>risk-management</category><category>ot-security</category></item><item><title>WordPress Plugin Security Is an Enterprise Problem That Keeps Getting Treated as a Web Developer Problem</title><link>https://cipherwatch.io/articles/2026-05-23-wordpress-plugin-security-enterprise-governance/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-23-wordpress-plugin-security-enterprise-governance/</guid><description>Four CVSS 8.8 vulnerabilities in a 100,000-install WordPress plugin — discoverable by any registered member with a subscriber account — highlight the structural mismatch between how WordPress CMS security is governed in enterprise organisations and the actual risk it carries. Membership sites, intranet portals, and course platforms built on WordPress process regulated data and host privileged access, but rarely receive enterprise-grade security governance.</description><pubDate>Sat, 23 May 2026 00:00:00 GMT</pubDate><category>wordpress</category><category>cms-security</category><category>plugin-governance</category><category>enterprise-security</category><category>risk-management</category><category>supply-chain</category></item><item><title>Nine CVEs in One Go Cryptography Library: What Mass Advisories in Open-Source Crypto Mean for Enterprise Risk Management</title><link>https://cipherwatch.io/articles/2026-05-22-open-source-cryptography-supply-chain-risk-management/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-22-open-source-cryptography-supply-chain-risk-management/</guid><description>The nine-CVE golang.org/x/crypto advisory is the latest in a pattern of mass security advisories from widely used open-source cryptographic libraries. For enterprise risk managers, the recurring pattern raises questions about how dependency-level cryptography risk is assessed, tracked, and communicated — and whether current SCA tooling is adequate for the velocity of advisory publication.</description><pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate><category>open-source</category><category>supply-chain</category><category>cryptography</category><category>golang</category><category>dependency-management</category><category>sca</category><category>risk-management</category><category>sbom</category></item><item><title>After Pwn2Own Berlin 2026: A Risk Manager&apos;s Assessment of 47 Zero-Days in Enterprise Infrastructure</title><link>https://cipherwatch.io/articles/2026-05-18-pwn2own-berlin-enterprise-risk-management-47-zero-days/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-18-pwn2own-berlin-enterprise-risk-management-47-zero-days/</guid><description>Pwn2Own Berlin 2026 produced 47 unique zero-day vulnerabilities across Windows 11, VMware ESXi, Exchange Server, SharePoint, Oracle VirtualBox, Red Hat Enterprise Linux, and five AI products. For enterprise risk managers and CISOs, the results require a structured response that goes beyond individual CVE patches and addresses the systemic implications.</description><pubDate>Mon, 18 May 2026 00:00:00 GMT</pubDate><category>pwn2own</category><category>risk-management</category><category>enterprise-security</category><category>vulnerability-management</category><category>ciso</category><category>governance</category></item><item><title>West Pharmaceutical Services Files SEC 8-K After Ransomware Encrypts Systems and Exfiltrates Manufacturing Data</title><link>https://cipherwatch.io/articles/2026-05-13-west-pharmaceutical-ransomware-sec-8k/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-13-west-pharmaceutical-ransomware-sec-8k/</guid><description>West Pharmaceutical Services, an S&amp;P 500 drug delivery component manufacturer, disclosed a ransomware attack via SEC Form 8-K, confirming system encryption and data exfiltration affecting its manufacturing and quality systems. The incident highlights regulatory obligations for publicly listed companies to disclose material cybersecurity incidents and the specific risks facing pharmaceutical supply chain manufacturers.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>ransomware</category><category>sec-disclosure</category><category>pharmaceutical</category><category>manufacturing</category><category>regulatory</category></item><item><title>Instructure Confirms ShinyHunters Exploited Canvas LMS to Deface University Login Portals in Mass Extortion Campaign</title><link>https://cipherwatch.io/articles/2026-05-11-canvas-lms-shinyhunters-deface-universities-confirmed/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-11-canvas-lms-shinyhunters-deface-universities-confirmed/</guid><description>Instructure has confirmed that the ShinyHunters threat group exploited a vulnerability in Canvas LMS to deface login portals across multiple university clients with extortion messages. The attack moved beyond the data exposure incident disclosed on May 3 into active defacement — university login pages were replaced with ransom demands visible to students and staff. Instructure is notifying affected institutions and has issued an emergency patch.</description><pubDate>Mon, 11 May 2026 00:00:00 GMT</pubDate><category>canvas-lms</category><category>instructure</category><category>shinyhunters</category><category>breach</category><category>education</category><category>extortion</category><category>data-breach</category><category>defacement</category></item><item><title>DOJ Indicts North Korean Developer for Leading Sales of DDoS and Cyberterrorism Tools for Regime Revenue</title><link>https://cipherwatch.io/articles/2026-05-09-north-korea-dprk-dev-indicted-ddos-cyberterrorism-tools/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-09-north-korea-dprk-dev-indicted-ddos-cyberterrorism-tools/</guid><description>The US Department of Justice has indicted a North Korean software developer on charges of conspiracy to develop and sell cyberattack tools — including distributed denial-of-service infrastructure and cyberterrorism-enabling toolkits — through front companies operated by the Workers&apos; Party of Korea. The indictment provides rare detail into how DPRK IT workers generate hard currency for the regime through offensive cyber tool sales, complementing the well-documented cryptocurrency theft and IT contractor programmes.</description><pubDate>Sat, 09 May 2026 00:00:00 GMT</pubDate><category>north-korea</category><category>dprk</category><category>doj-indictment</category><category>ddos</category><category>cyberterrorism</category><category>sanctions</category><category>threat-actor</category><category>nation-state</category><category>revenue-generation</category></item><item><title>FTC Bans Kochava Subsidiary from Selling Sensitive Location Data in Landmark Enforcement Settlement</title><link>https://cipherwatch.io/articles/2026-05-08-ftc-bans-kochava-location-data-sales-settlement/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-08-ftc-bans-kochava-location-data-sales-settlement/</guid><description>The US Federal Trade Commission has reached a settlement banning Kochava and its Collective Data Solutions subsidiary from selling sensitive location data derived from consumer mobile devices — marking the FTC&apos;s most significant enforcement action against the location data broker industry. The settlement establishes a precedent with direct implications for any organisation that monetises or purchases precise consumer location data, including advertising technology companies, retail analytics firms, and financial services using location data for fraud detection.</description><pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate><category>ftc</category><category>privacy</category><category>location-data</category><category>data-broker</category><category>enforcement</category><category>kochava</category><category>adtech</category><category>regulatory</category><category>gdpr</category><category>compliance</category></item><item><title>Fortinet 2026 Global Threat Landscape: Ransomware Victims Up 389% Year-over-Year, AI Crime Industrialising</title><link>https://cipherwatch.io/articles/2026-05-05-fortinet-2026-global-threat-landscape-ransomware-389pct/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-05-fortinet-2026-global-threat-landscape-ransomware-389pct/</guid><description>Fortinet&apos;s 2026 Global Threat Landscape Report documents 7,831 confirmed ransomware victims in 2025 — a 389% increase over 2024&apos;s approximately 1,600 — alongside the first systematic evidence of AI-enabled cybercrime tooling (WormGPT, FraudGPT, BruteForceAI) being used at scale. Manufacturing, business services, and retail are the hardest-hit sectors. The report reframes the threat environment as fundamentally changed, not merely intensified.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><category>threat-intelligence</category><category>ransomware</category><category>ai-crime</category><category>fortinet</category><category>annual-report</category><category>threat-landscape</category><category>manufacturing</category><category>financial-crime</category></item><item><title>KidsProtect Stalkerware Abuses VS Code Tunnels and Discord Webhooks as Covert C2 Infrastructure</title><link>https://cipherwatch.io/articles/2026-05-05-kidsprotect-android-stalkerware-vscode-tunnel-c2/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-05-kidsprotect-android-stalkerware-vscode-tunnel-c2/</guid><description>A commercially marketed Android application called KidsProtect, presented as a parental control tool, has been analysed and found to function as stalkerware — secretly recording device location, SMS messages, call logs, and browser history without consent. The tool evades conventional network monitoring by routing command-and-control traffic through legitimate VS Code Remote Tunnels and Discord webhook endpoints. Its developer explicitly markets it as an undetectable monitoring solution on underground forums.</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><category>stalkerware</category><category>android</category><category>mobile-security</category><category>privacy</category><category>vs-code-tunnel-abuse</category><category>discord-abuse</category><category>consent</category><category>domestic-surveillance</category></item><item><title>Europol Dismantles €50M Crypto Investment Fraud Network — 12 Arrested Across Six Countries</title><link>https://cipherwatch.io/articles/2026-05-04-europol-cryptofraud-50m-12-arrests/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-04-europol-cryptofraud-50m-12-arrests/</guid><description>Europol has coordinated the dismantling of a €50 million cryptocurrency investment fraud network operating across six European countries, resulting in 12 arrests, 30 property searches, and the seizure of cryptocurrency holdings, luxury assets, and fraud operation infrastructure. The network ran AI-enhanced investment scam call centres and operated fraudulent crypto trading platforms that fabricated returns to sustain victim investment before executing exit scams.</description><pubDate>Mon, 04 May 2026 00:00:00 GMT</pubDate><category>europol</category><category>cryptocurrency</category><category>investment-fraud</category><category>social-engineering</category><category>law-enforcement</category><category>financial-crime</category><category>pig-butchering</category></item><item><title>Two Former Cybersecurity Professionals Sentenced to Four Years for BlackCat/ALPHV Ransomware Operations</title><link>https://cipherwatch.io/articles/2026-05-03-blackcat-alphv-two-sentenced-four-years/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-03-blackcat-alphv-two-sentenced-four-years/</guid><description>A US federal court has sentenced two individuals with professional cybersecurity backgrounds to four-year prison terms for their roles in the BlackCat/ALPHV ransomware-as-a-service operation, marking a notable law enforcement outcome that demonstrates insider security knowledge is not a prosecution shield. The sentences follow guilty pleas and cooperation with investigators.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate><category>ransomware</category><category>law-enforcement</category><category>blackcat-alphv</category><category>cybercrime-prosecution</category><category>deterrence</category></item><item><title>FBI Warns of $725M Cyber-Enabled Cargo Theft Wave Targeting Transportation and Logistics</title><link>https://cipherwatch.io/articles/2026-05-01-fbi-cyber-cargo-theft-725-million/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-05-01-fbi-cyber-cargo-theft-725-million/</guid><description>The FBI has issued a warning documenting a sharp surge in cyber-enabled cargo theft targeting the US transportation and logistics industry, with losses exceeding $725 million in 2025. Criminal organisations use phishing, broker impersonation, and freight marketplace account takeovers to divert physical shipments. Supply chain security teams and freight brokers should treat this advisory as a direct threat to physical goods in transit.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>fbi-advisory</category><category>cargo-theft</category><category>social-engineering</category><category>logistics-security</category><category>freight-fraud</category><category>supply-chain-risk</category></item><item><title>WordPress Redirect Plugin Carried Dormant Backdoor for Three Years Before Activation</title><link>https://cipherwatch.io/articles/2026-04-30-wordpress-redirect-plugin-dormant-backdoor/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-30-wordpress-redirect-plugin-dormant-backdoor/</guid><description>Researchers have uncovered a dormant backdoor in a widely-installed WordPress redirect management plugin that remained inactive for approximately three years before being activated by the attackers. The backdoor, present across an estimated 200,000+ active installations, highlights the long-game threat of supply chain compromise in the WordPress plugin ecosystem and the limits of periodic security scanning.</description><pubDate>Thu, 30 Apr 2026 00:00:00 GMT</pubDate><category>wordpress</category><category>supply-chain</category><category>backdoor</category><category>plugin-security</category><category>website-security</category><category>cms-security</category></item><item><title>FTC: Americans Lost $2.1 Billion to Social Media Scams in 2025 — AI-Enhanced Fraud Doubles Investment Losses</title><link>https://cipherwatch.io/articles/2026-04-28-ftc-social-media-fraud-2-1-billion-ai-scams/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-28-ftc-social-media-fraud-2-1-billion-ai-scams/</guid><description>The US Federal Trade Commission&apos;s annual consumer fraud report records $2.1 billion in social media scam losses in 2025, a 47% increase from 2024 driven by AI-generated deepfake impersonations, synthetic romance fraud accounts, and AI-personalised investment scam targeting. Investment scams account for 53% of losses at $1.1 billion. The report carries compliance implications for organisations under FTC Section 5 and EU AI Act Article 50 transparency obligations.</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><category>fraud</category><category>ftc</category><category>social-media</category><category>ai-fraud</category><category>deepfake</category><category>regulatory</category><category>investment-scam</category></item><item><title>NIST Halts NVD Enrichment for Lowest-Priority CVEs as Submission Volume Surges 263% — Vulnerability Management Impact</title><link>https://cipherwatch.io/articles/2026-04-27-nist-nvd-enrichment-lowest-priority-halt/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-27-nist-nvd-enrichment-lowest-priority-halt/</guid><description>NIST has announced it will no longer provide full CVSS scoring, CPE matching, and CWE classification for the lowest-priority tier of CVE submissions in the NVD. The change, driven by a 263% surge in annual CVE volumes since 2024, means thousands of CVE records will remain in an unenriched &apos;DEFERRED&apos; state — with no CVSS score, no affected product mapping, and no severity rating. Enterprise vulnerability management programmes that rely on NVD as their authoritative source must adapt their workflows immediately.</description><pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate><category>nvd</category><category>nist</category><category>vulnerability-management</category><category>cvss</category><category>patch-management</category><category>risk-prioritisation</category></item><item><title>Germany BKA Identifies REvil and GandCrab Leader &apos;UNKN&apos; as Russian National Daniil Shchukin</title><link>https://cipherwatch.io/articles/2026-04-26-germany-bka-identifies-revil-gandcrab-leader-unkn/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-26-germany-bka-identifies-revil-gandcrab-leader-unkn/</guid><description>Germany&apos;s federal criminal police (BKA) publicly attributed the REvil and GandCrab ransomware-as-a-service platforms to 31-year-old Russian national Daniil Shchukin, holding him responsible for 130+ attacks in Germany causing over €35 million in economic damage. Shchukin operates from Krasnodar and remains beyond extradition reach, but the attribution breaks the historical anonymity of top-tier RaaS operators and may precede US OFAC sanctions.</description><pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate><category>ransomware</category><category>attribution</category><category>revil</category><category>gandcrab</category><category>germany</category><category>russia</category><category>law-enforcement</category></item><item><title>CISA Adds Four Exploited Flaws to KEV — SimpleHelp RMT and Samsung MagicINFO Head New Additions</title><link>https://cipherwatch.io/articles/2026-04-25-cisa-kev-simplehelp-samsung-magicinfo-new-additions/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-25-cisa-kev-simplehelp-samsung-magicinfo-new-additions/</guid><description>CISA&apos;s Known Exploited Vulnerabilities catalogue has grown by four entries including critical flaws in SimpleHelp remote management tooling and Samsung&apos;s MagicINFO digital signage platform. Federal agencies face a May 2026 remediation deadline. Enterprise operators of RMM tools and display infrastructure should treat these as urgent.</description><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate><category>cisa-kev</category><category>simplehelp</category><category>samsung</category><category>rmm-tools</category><category>actively-exploited</category><category>compliance</category></item><item><title>NASA OIG: Chinese Spear-Phishing Campaign Targeted Defence Software Over Four Years</title><link>https://cipherwatch.io/articles/2026-04-24-nasa-oig-chinese-spearphishing-defence-software-song-wu/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-24-nasa-oig-chinese-spearphishing-defence-software-song-wu/</guid><description>A newly released NASA OIG report details a sustained Chinese spear-phishing operation by Song Wu that targeted NASA, DoD contractors, and universities to steal defence software source code. The campaign ran from 2017 to 2021 — a defence supply chain IP theft template that remains relevant today.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><category>spear-phishing</category><category>nation-state</category><category>china</category><category>intellectual-property</category><category>defence</category></item><item><title>SAP BPC SQL Injection (CVE-2026-27681, CVSS 9.9) Gives Low-Privilege Users Full Access to Financial ERP Data</title><link>https://cipherwatch.io/articles/2026-04-24-sap-abap-sql-injection-cve-2026-27681-erp-financial-risk/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-24-sap-abap-sql-injection-cve-2026-27681-erp-financial-risk/</guid><description>A near-perfect CVSS 9.9 SQL injection vulnerability in SAP Business Planning and Consolidation and BW/4HANA allows any authenticated user with standard access to read, modify, and delete financial consolidation data. SAP patched the flaw in its April 2026 Security Patch Day; organisations should treat unpatched SAP financial systems as having their financial data integrity at risk from any internal user with SAP credentials.</description><pubDate>Fri, 24 Apr 2026 00:00:00 GMT</pubDate><category>sap</category><category>sql-injection</category><category>erp</category><category>financial-security</category><category>patch-management</category><category>enterprise-risk</category></item><item><title>Anthropic&apos;s Claude Mythos AI Discovers Thousands of Zero-Days Across Every Major OS — Project Glasswing Offers Private Access</title><link>https://cipherwatch.io/articles/2026-04-22-anthropic-claude-mythos-ai-zero-day-discovery/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-22-anthropic-claude-mythos-ai-zero-day-discovery/</guid><description>Anthropic&apos;s specialised vulnerability-hunting AI, Claude Mythos, has systematically discovered thousands of zero-day vulnerabilities across Windows, macOS, Linux, and major browsers — including a 17-year-old NFS RCE in FreeBSD and a 27-year-old OpenBSD denial-of-service. Project Glasswing provides private early access to Microsoft, Google, Apple, and select others. The implications for enterprise risk governance are immediate.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><category>ai-security</category><category>zero-day</category><category>vulnerability-research</category><category>anthropic</category><category>risk-governance</category><category>threat-landscape</category></item><item><title>ShinyHunters Leaks 78.6M Rockstar Records — The Real Story Is Anodot&apos;s Access</title><link>https://cipherwatch.io/articles/2026-04-16-rockstar-shinyhunters-anodot-snowflake-third-party-breach/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-16-rockstar-shinyhunters-anodot-snowflake-third-party-breach/</guid><description>ShinyHunters has released 78.6 million records stolen from Rockstar Games, following the company&apos;s refusal to pay a ransom by the April 14 deadline. The breach did not involve Rockstar&apos;s own systems: attackers compromised Anodot, a third-party SaaS analytics vendor with direct access to Rockstar&apos;s Snowflake data warehouse. No player records were exposed, but the incident illustrates the persistent enterprise risk of SaaS vendor data access.</description><pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate><category>third-party-risk</category><category>snowflake</category><category>saas-security</category><category>data-breach</category><category>shinyhunters</category><category>supply-chain</category><category>anodot</category><category>extortion</category><category>vendor-risk</category></item><item><title>CISA Flags SharePoint Zero-Day CVE-2026-32201 as Actively Exploited — Patch Arrives Tomorrow</title><link>https://cipherwatch.io/articles/2026-04-14-sharepoint-cve-2026-32201-kev-no-patch-zero-day/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-14-sharepoint-cve-2026-32201-kev-no-patch-zero-day/</guid><description>CISA has added CVE-2026-32201, a Microsoft SharePoint Server spoofing vulnerability under active exploitation, to the KEV catalogue with a 28 April remediation deadline. The timing is unusual: Microsoft has not yet released a patch as of this alert, with the fix expected in tomorrow&apos;s Patch Tuesday release. Organisations must decide whether to implement mitigations today or accept overnight exposure until the patch lands.</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate><category>microsoft</category><category>sharepoint</category><category>zero-day</category><category>cisa-kev</category><category>patch-tuesday</category><category>risk-management</category><category>cve</category><category>no-patch</category></item><item><title>NIS2 Moves From Grace Period to Enforcement — Germany&apos;s BSI Registration Deadline Is Now</title><link>https://cipherwatch.io/articles/2026-04-11-nis2-enforcement-maturity-germany-bsi-deadline/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-11-nis2-enforcement-maturity-germany-bsi-deadline/</guid><description>Eighteen months after the NIS2 transposition deadline, EU member states are moving from legislative implementation to active supervisory enforcement. Germany&apos;s BSI has set April 2026 as the registration deadline for essential and important entities under the national NIS2 implementation (NIS2UmsuCG). Organisations still treating NIS2 as a future requirement face immediate regulatory exposure as national competent authorities begin audit and penalty activity.</description><pubDate>Sat, 11 Apr 2026 00:00:00 GMT</pubDate><category>nis2</category><category>gdpr</category><category>compliance</category><category>regulatory</category><category>germany</category><category>bsi</category><category>incident-reporting</category><category>governance</category><category>eu</category></item><item><title>CIRCIA Final Rule Expected May 2026: What Critical Infrastructure Operators Must Do Now</title><link>https://cipherwatch.io/articles/2026-04-10-circia-final-rule-mandatory-incident-reporting/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-10-circia-final-rule-mandatory-incident-reporting/</guid><description>CISA is expected to publish the long-awaited CIRCIA final rule in May 2026, mandating 72-hour cyber incident reporting and 24-hour ransomware payment reporting for critical infrastructure sectors. With weeks remaining, organisations that have not started preparing face significant compliance and legal exposure when the rule takes effect.</description><pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate><category>circia</category><category>regulatory-compliance</category><category>incident-reporting</category><category>ransomware</category><category>critical-infrastructure</category><category>cisa</category><category>governance</category></item><item><title>Handala Ransomware Surges to 23 Victims in March — Geopolitically-Motivated Wiper Threat Expands Beyond Israel</title><link>https://cipherwatch.io/articles/2026-04-06-handala-ransomware-surge-geopolitical-enterprise-risk/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-06-handala-ransomware-surge-geopolitical-enterprise-risk/</guid><description>Handala ransomware claimed 23 victims in March 2026 — the group&apos;s most active month, accounting for more than half of its total 2026 activity to date. While predominantly targeting Israeli organisations with suspected IRGC ties, Handala has begun extending its reach into European financial services, healthcare, and utilities. The group deploys wiper functionality alongside ransomware, meaning recovery from an attack is frequently impossible even without a ransom payment.</description><pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate><category>ransomware</category><category>handala</category><category>wiper</category><category>geopolitical</category><category>iran</category><category>threat-intelligence</category><category>business-continuity</category></item><item><title>March 2026 Patch Cycle: The Governance and Risk Metrics That CISOs Should Be Reporting</title><link>https://cipherwatch.io/articles/2026-04-05-march-patch-tuesday-ciso-governance-risk/</link><guid isPermaLink="true">https://cipherwatch.io/articles/2026-04-05-march-patch-tuesday-ciso-governance-risk/</guid><description>March 2026 has been an unusually demanding patch cycle — 83 Microsoft CVEs, three new CISA KEV additions across F5, Citrix, and Active Directory, and concurrent exploitable vulnerabilities across Linux, PAN-OS, and Dell hardware. CISOs face board-level questions about patching velocity and exposure windows. This analysis provides the governance framework and risk metrics to answer those questions accurately.</description><pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate><category>patch-management</category><category>governance</category><category>ciso</category><category>risk-metrics</category><category>kpi</category><category>board-reporting</category><category>compliance</category></item></channel></rss>