Practical compliance thinking, not vendor noise.
GRC automation, AI governance, third-party risk, DPO best practice and cyber security — written by the people who build the platform.
Citrix NetScaler zero-days under attack: a brutal week for the network edge
Citrix confirmed two actively exploited remote code execution flaws in NetScaler ADC and Gateway on 27 September. Five days earlier CISA had flagged exploited flaws in Check Point, Arista and F5 kit. The pattern matters more than any single CVE.
27 companies breached for $25 a go: AI agents as attack tooling
One operator chained three open-source AI agent frameworks to breach at least 27 organisations in under a week, at an average cost of $25.46 per target. The interesting number is not 27. It is $25.46.
The payroll app that never existed: a lesson in checking the obvious
Attackers built convincing download pages for desktop clients of three US payroll platforms, each installing legitimate remote access software. The detail that undoes the whole scheme: none of those vendors offers a desktop client.
Malware that asks four AI models what to do next
Cisco Talos has documented a Windows implant that queries up to four large language models, takes a vote, and chooses its own next move. It has not been seen deployed in the wild — which makes this the right moment to think about detection.
Could your tracking IDs stop being personal data? The Council thinks maybe
A Council compromise text on the Digital Omnibus would let pseudonymised data be treated as non-personal by any party unable to re-identify the individual. For advertising identifiers, that is a structural change — and 127 organisations have objected.
A third of GenAI users are hiding it from their employer
Deloitte UK's survey of 25,000 workers puts numbers on something most compliance teams already suspected. The finding that should worry you is not the third who hide it — it is the £958 million they are spending personally.
A WAF rule is not a patch: the PeopleSoft bypass
Attackers linked to ShinyHunters used a simple encoding trick to slip past the web application firewall rules many organisations relied on instead of patching Oracle PeopleSoft. The technique is old. The lesson keeps needing to be relearned.
Singapore is using AI to pen test 2,000 government systems. Should you?
Faced with a persistent state-linked threat and thousands of systems, Singapore built AI tooling to automate parts of penetration testing. It is a serious answer to a real problem, and a useful lens on what automation can and cannot replace.
SalesBleed: when a single untrusted lead can hijack your AI agent
Zenity Labs disclosed three flaws in Salesforce Agentforce that let a single untrusted lead turn a trusted enterprise agent into a data exfiltration and phishing channel. Salesforce fixed them. The design lesson applies to every agent you deploy.
California wants independent verifiers inside AI companies
California has appointed four experts to advise on an executive order exploring onsite independent verification inside frontier AI companies, third-party verification of safety disclosures and a tested emergency shutoff. The direction of travel matters more than the detail.
The platform wasn't breached. Your shoppers' data still left.
Attackers used compromised credentials for a third-party app to inject malicious scripts into BigCommerce merchant storefronts and harvest shopper details. BigCommerce's own platform was not breached, which is precisely the problem.
The AI Act stopped being theoretical: first inspections begin
The European Commission has used its AI Act investigatory powers for the first time, and the AI Office has opened a coordinated inspection wave with 24 national authorities. Three high-risk categories are in scope, and two of them sit in ordinary HR and lending functions.
The high-risk AI deadline may move. Plan as if it won't.
Proposed changes would delay the AI Act's high-risk obligations by more than a year and loosen the threshold for using special category data in bias testing. Europe's data protection authorities are unimpressed — and delay is a weak basis for a compliance plan.
Sweden fined the supplier, not its customers. That should get your attention.
Sweden's data protection authority fined an IT supplier used by around 80% of the country's municipalities after a breach affecting 2.2 million people. What the regulator faulted was specific, and it is exactly what most supplier questionnaires never ask about.
23.6 million records, 490 million images, and a notification problem
An attacker exploited an upload server to reach Gyazo's backend, taking 23.6 million user records and metadata covering roughly 490 million images. The response was fast. The hard part is telling anonymous users what happened to them.
Leaked GDPR draft would ease AI training on personal data
Documents published by noyb show EU governments discussing a GDPR change that would make legitimate interest the default route for AI development. It is not law yet, and your AI governance should not wait for it.
Google’s €403m location data fine: lessons for every controller
Ireland’s Data Protection Commission has fined Google €403 million over how it handled location data. The lessons on transparency, defaults and retention apply far beyond Big Tech.
Revolut data theft: when the ‘police request’ is the attack
Attackers claim they obtained data on around 700 Revolut customers by posing as Italian authorities. The weak point was not a firewall but a disclosure process. Here is how to harden yours.
DPDP cross-border rules aren’t live yet: how to prepare wisely
Contracts are being redrafted as if India’s DPDP cross-border rules already apply. They don’t, yet. Here is what is actually in force, what is coming and how to prepare without over-engineering.
Brevo supply-chain attack: one leaked key, 100,000 websites
A single hardcoded API key let attackers turn Brevo’s embedded forms and widgets into a malware delivery system for up to 100,000 websites. It is a textbook lesson in fourth-party risk.
The ICO becomes the Information Commission on 30 September
The UK data protection regulator moves from a single Commissioner to a board-led Commission on 30 September. The name barely changes, but how decisions are made does.
Cisco ISE zero-day (CVE-2026-76460): patch now, then hunt
Cisco has confirmed active exploitation of a maximum-severity flaw in Identity Services Engine, days after another exploited zero-day in its email gateway. Here is what to patch and what to check.
Humans may read your AI chats. What that means for your data
Reports that contractors review real ChatGPT conversations, and Apple’s new opt-in for Siri training, are a reminder: what employees paste into AI tools may not stay between them and the machine.
EU Cyber Resilience Act reporting is live: the 24-hour clock
The first binding obligations of the EU Cyber Resilience Act now apply. Manufacturers of hardware and software sold in the EU must report actively exploited vulnerabilities and severe incidents on a 24-hour clock.
IDScan breach: the hidden risk in outsourced ID checks
Businesses scanned customers’ IDs for good reasons. A breach at their verification provider has left more than 150 million licence records in criminal hands. Here is what it teaches about vendor risk.
Shadow AI Is Already Inside Your Organisation. Here's What To Do About It.
Your staff are using ChatGPT, Claude and Gemini today, whether or not there's a policy for it. We break down what's actually leaving the building, and the five-step response that works better than a ban.
DORA's Third-Party Register: What Financial Firms Still Get Wrong
A year into enforcement, the register of information remains the single biggest DORA compliance gap we see. Here's the checklist we use with clients.

Praeferre signs MoU with SRPOST to advance Responsible AI in Korea
Praeferre partners with SRPOST via an MoU to strengthen Responsible AI, driving ethical and sustainable AI adoption in Korea.

Praeferre joins Cyber Runway CNI to strengthen cyber resilience across UK critical national infrastructure
Praeferre joins Cyber Runway CNI to strengthen cyber resilience, security and innovation across the UK’s critical national infrastructure.

Praeferre Wins World Smart City Prize 2025: Advancing Responsible AI for Smarter & Safer Cities
Praeferre wins the World Smart City Prize 2025, advancing responsible AI to build smarter, safer and more sustainable cities worldwide.

Understanding Data Governance: A Key to Unlocking Business Potential
Learn how data governance helps organisations manage data effectively, improve compliance, build trust and unlock long-term business value.

Praeferre at RSA Conference USA 2025: Shaping the Future of Cybersecurity
Discover Praeferre at RSA Conference USA 2025, shaping the future of cybersecurity with trusted, innovative and responsible security solutions.

Driving Responsible AI in Global Banking: UK–India Collaboration for a Fair AI Future
Explore how UK–India collaboration is shaping responsible AI in global banking, promoting fairness, trust, compliance and sustainable innovation.

Strengthening Telecom Security: Praeferre Joins UK–India Future Telecom Collaboration
Praeferre joins the UK–India Future Telecom Collaboration to enhance telecom security, innovation and trusted digital infrastructure.

Transforming Telecoms: How Centralised Compliance is Reinventing Data Privacy for Telcos
Discover how centralised compliance is transforming data privacy in telecoms, helping telcos ensure security, trust and regulatory adherence.

A Guide on The Data Protection and Digital Information Bill in the United Kingdom
Learn what the UK Data Protection and Digital Information Bill means, its key changes, who it affects, and how organisations can prepare.

Understanding the Core Principles of GDPR
Learn the core principles of GDPR, including lawfulness, transparency, data rights and accountability, to ensure compliant protection.

Understanding the CCPA (California Consumer Privacy Act)
Learn what the California Consumer Privacy Act is, who it applies to, and how businesses can comply with CCPA requirements effectively.

Essential Guide to Information Security Management: Safeguarding Digital Assets in a Cyber World
Learn how information security management protects digital assets, mitigates cyber risks, ensures compliance, and strengthens organisational resilience.

Understanding the Fundamental Difference Between Data Privacy and Data Protection
Understand the difference between data privacy and data protection, why both matter, and how organisations can ensure compliance and trust today

Praeferre Showcased in Japan During the UK–Japan 5G Trade Mission
Praeferre was showcased in Japan during the UK–Japan 5G Trade Mission, highlighting innovation, collaboration and global leadership in technology.
No articles match your search
Try a different keyword, or clear the category filter.
Get one email a month, no spam
Compliance insights worth reading, sent straight to your inbox.