IT Brief UK - Technology news for CIOs & IT decision-makers

Data exfiltration stories

Flux result e138c2c7 10d5 44b8 b5f2 1566c9a08fa9

Proofpoint flags mailbox rule abuse in Microsoft 365

2 days ago
#
edutech
#
mfa
#
cloud security
Proofpoint says mailbox rule abuse is becoming a routine Microsoft 365 takeover tactic, helping attackers hide alerts, hijack threads and drive fraud.
Flux result 20e12820 27f4 4e8a 9da9 1c2ee2ea902d

Sonatype warns of surge in trusted open-source malware

3 days ago
#
application security
#
devsecops
#
supply chain
Sonatype flags 21,764 malicious open-source packages in Q1 2026, with npm hit hardest as attackers used trusted workflows to steal secrets.
Flux result f3a23773 f3c5 4ab1 8315 098438942b1a

AI agents expose major API security gap, Salt warns

Last week
#
manufacturing
#
digital transformation
#
cloud security
Salt warns AI agents are widening the API security gap, with 92% of organisations still short of advanced defences and 47% delaying releases.
Franklin

From DSPM to data protection: Closing the last mile on sensitive data in the era of AI

Last week
#
storage
#
data protection
#
cloud security
AI-era data security needs more than DSPM visibility, as firms must track how sensitive information moves and enforce controls in real time.
Sarah wilkinson

Small alert, big defense: Inside a SOC's early-morning response

Last week
#
vpns
#
ransomware
#
mfa
UK SOC spots Monday-morning conditional access failure from Germany, helps reset compromised Microsoft 365 account before attackers can strike.
Flux result 3a2b4af2 8b5c 40e9 ae67 f7ddfcdfbb0b

Nutanix & NetApp launch virtualisation migration tie-up

Last week
#
storage
#
virtualisation
#
data protection
Nutanix and NetApp team up on migration tools to help enterprises modernise virtualised systems, cut complexity and bolster ransomware defences.
Flux result 9a5fbf33 4cd5 4f62 a705 c822376a1b61

Claude Code flaw leaves deny rules vulnerable in long workflows

Last week
#
cloud security
#
application security
#
socs
Anthropic’s Claude Code is under scrutiny after researchers found deny rules can weaken in long workflows, raising fresh concerns for AI-driven development.
Flux result 2a0e4632 8072 4ed3 9f1d 043e15c75687

Microsoft warns of Storm-1175's rapid Medusa attacks

Last week
#
ransomware
#
cybersecurity
#
microsoft
Microsoft says Storm-1175 is exploiting newly disclosed flaws within hours, hitting organisations in the UK and elsewhere with fast-moving Medusa ransomware.
Flux result 8ebd1272 347f 4407 acbc d4999522fad4

Permiso launches sandbox for AI agent skill security

Last week
#
firewalls
#
network security
#
cloud security
Permiso launches SandyClaw sandbox to detonate AI agent skills and expose hidden runtime risks before they reach enterprise systems.
Flux result b89f46aa 0edc 4965 9487 cdd46bf5a418

ChatGPT flaw let hackers steal data via DNS queries

This month
#
firewalls
#
data protection
#
devops
ChatGPT flaw may have let attackers siphon sensitive user data via DNS queries, prompting OpenAI to issue a fix after researchers exposed the bug.
Flux result 4fd4ec51 3ee5 4138 9d86 cf53ec65c7ba

F5 & Forcepoint come together to secure enterprise AI

This month
#
data protection
#
hybrid cloud
#
digital transformation
F5 and Forcepoint have teamed up to link data discovery with runtime controls, aiming to curb AI risks as enterprises move systems into production.
Flux result 40d5bcdc 27bf 48a0 8c08 a87cb6325b88

Zscaler flags Xloader malware's tougher obfuscation

This month
#
malware
#
firewalls
#
encryption
Zscaler says Xloader malware has added layered encryption, decoy servers and new obfuscation tricks to hinder analysts.
Flux result a9ab9287 96dd 4887 9a3e 050aa7603299

Foxit adds PDF Action Inspector to spot hidden risks

This month
#
data protection
#
document management
#
ecm
Foxit's latest PDF Editor update adds Action Inspector to uncover hidden scripts and redaction-bypassing behaviour in business documents.
Flux result 6459960a 8b91 4ad1 9ab4 cab1e0e740d2

DeepLoad malware steals credentials via ClickFix campaign

This month
#
malware
#
firewalls
#
network infrastructure
ReliaQuest flags DeepLoad malware stealing live credentials in enterprise networks, with AI-style obfuscation, USB spread and hidden WMI persistence.
Flux result 0140b590 dfa2 4fdb 8cad 8fa28d461048

Firms warned on ransomware amid backup & AI sprawl

This month
#
saas
#
firewalls
#
data protection
Experts warn firms must improve visibility and backup resilience as automated ransomware campaigns and hidden SaaS and AI assets widen exposure.
Flux result 2dd6e765 d72a 468e ae19 7b5d4c3c4c21

Codenotary launches AgentMon for AI agent oversight

Last month
#
data protection
#
digital transformation
#
application security
Codenotary unveils AgentMon to help Chief Information Officers and security teams track AI agent behaviour, costs and policy risks.
Ryan mahoney

Why AI-powered security needs network telemetry across the hybrid cloud

Last month
#
firewalls
#
private cloud
#
hybrid cloud
AI security tools are only as smart as the data they see, and network telemetry is emerging as the missing piece in hybrid cloud oversight.
John maddison  chief marketing officer at f5

F5 & Forcepoint join forces on enterprise AI security

Last month
#
data protection
#
digital transformation
#
application security
F5 and Forcepoint team up to give enterprises continuous AI security, linking data discovery with runtime controls to reduce risk in production systems.
Flux result 05469706 4bde 42de be79 376351dd4b3e

OpenAI launches safety bug bounty for AI abuse risks

Last month
#
physical security
#
ai security
#
risk & compliance
OpenAI opens public Safety Bug Bounty to find agentic prompt injection, data exfiltration and other AI misuse risks.
Flux result 71688744 a7df 404c 89a9 713dc308b84c

F5 & Forcepoint join to secure enterprise AI systems

Last month
#
firewalls
#
data protection
#
hybrid cloud
F5 and Forcepoint have teamed up to link data governance with live runtime controls, closing security gaps across enterprise AI lifecycles.