
Ofqual statistics show school cyber incidents falling to 27%
New Ofqual data reveals the proportion of UK schools hit by cyber incidents has fallen to 27%, while two-thirds can now recover immediately from attacks.
Incidents on Zero Day Room: Confirmed breaches, finance, health, telecom, government and Post-incident reports and lessons.

New Ofqual data reveals the proportion of UK schools hit by cyber incidents has fallen to 27%, while two-thirds can now recover immediately from attacks.

The Pentagon has confirmed a months-long breach of its Defense Manpower Data Center, exposing unencrypted Social Security numbers and personal details.

The U.S. Treasury sanctioned 10 individuals and companies linked to a Tren de Aragua ATM malware scheme that caused over $40.7 million in losses.

A New Mexico jury found Meta's Facebook liable for over 43 million violations of state consumer protection law.

Kiteworks advised customers worldwide to shut down servers for a six-hour window on Saturday, September 26, based on credible threat intelligence.

The EU Court of Auditors warns that poor information sharing and undefined roles are hindering the bloc's ability to detect and respond to large-scale cyber incidents.

Spain's data protection agency has disclosed the country's first confirmed personal data breach carried out by an agentic AI.

The US Coast Guard and FBI boarded two oil tankers last month after cyberattacks disrupted their voyages. Investigators found evidence of a malicious cyber actor on one vessel, though they have not publicly linked the incidents to Iran.

The Florida Department of Highway Safety and Motor Vehicles confirmed a data breach after credentials were stolen from a Plant City police officer's personal device.

Healthcare distributor McKesson is investigating a data breach claimed by ShinyHunters, which reportedly compromised hundreds of millions of records.

US healthcare provider Nutex Health disclosed a data breach where patient and employee information was stolen.

Hardware wallet maker Trezor disclosed a data breach at its shipping provider ShipMonk, exposing 67,000 U.S. Customers' order data from 2019-2021.

The G7, chaired by France’s ANSSI during its 2026 presidency, issued a September 3 call urging governments and businesses to prioritize post-quantum cryptography.

PostgreSQL has released updates to fix CVE-2026-6471, a vulnerability allowing accounts with the REPLICATION attribute to execute arbitrary code.

Citizen Lab and SHARE Foundation found a Serbian student activist's iPhone was infected with NSO's Pegasus spyware using a zero-click iMessage exploit.

GitHub's Dependabot team, which monitors over 30 million repositories, shares operational lessons from ingesting community threat intelligence at scale.