Opening the Email Was Enough. OWAReaper Stayed After the Password Changed.

Laundry Bear exploited Exchange OWA to deploy a browser implant whose mailbox access could survive password changes and endpoint rebuilding.

Laundry Bear exploited Exchange OWA to deploy a browser implant whose mailbox access could survive password changes and endpoint rebuilding.

Google patched an actively exploited V8 memory-corruption flaw reachable through a crafted web page. The fix is not complete until the browser restarts.

A Check Point IKEv1 authentication bypass was exploited for a month before disclosure, with at least one intrusion linked to a Qilin ransomware affiliate.

Luxembourg’s national DSA law turned the Competition Authority’s coordinating role into an enforceable procedure, with information requests, inspections and penalties for intermediary-service providers established in the country. The EU Digital Services Act became generally applicable on 17 February 2024, and…

Belgium’s NIS2 regime combines risk-management and incident-reporting duties with something many national implementations leave less explicit: registration followed by a structured route to independent assurance. The Act of 26 April 2024 establishing a cybersecurity framework for networks and information systems…

Saudi Arabia’s Personal Data Protection Law took effect in September 2023. Its general one-year grace period ended on 14 September 2024, moving compliance from preparation to operation. Saudi Arabia’s PDPL establishes rules for processing personal data and is supported by…
The Dutch Wegiz is a framework for turning selected exchanges of health information from optional digitisation projects into mandatory, standardised and potentially certified processes. The Wet elektronische gegevensuitwisseling in de zorg, known as the Wegiz, entered into force on 1…

Nigeria signed its Data Protection Act into law on 12 June 2023, creating an independent commission and moving national privacy requirements onto a statutory foundation. Nigeria’s digital economy serves a large and rapidly growing population through financial technology, telecommunications, retail,…
Portugal’s Regulation 183/2022 turned familiar security practices—named contacts, a security officer, an asset inventory, an annual report and incident notices—into structured communications with the national cybersecurity authority. Current-status note: Regulation No. 183/2022 governed Portugal’s previous regime through 2 April 2026.…