<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Firevault News</title>
    <link>https://www.fire-vault.com/feeds/news.xml</link>
    <description>Latest news from Firevault — UK air-gapped data resilience.</description>
    <language>en-GB</language>
    <lastBuildDate>Tue, 04 Aug 2026 17:45:07 GMT</lastBuildDate>
    <atom:link href="https://www.fire-vault.com/feeds/news.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>The Minnesota Water Attacks: Why Connectivity Is Becoming Critical Infrastructure&apos;s Biggest Risk</title>
      <link>https://www.fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/minnesota-water-attacks-connectivity-critical-infrastructure-risk</guid>
      <description>More than 30 US water and wastewater utilities were targeted in a coordinated cyber attack on operational technology. The lesson for critical infrastructure is that unnecessary connectivity is now the risk itself.</description>
      <pubDate>Fri, 31 Jul 2026 07:08:56 GMT</pubDate>
      <category>Industry Insight</category>
    </item>
    <item>
      <title>Protecting Students, Peers and Partners: A Practical Education Data Briefing</title>
      <link>https://www.fire-vault.com/news/guide-safeguarding-education-data</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/guide-safeguarding-education-data</guid>
      <description>A practical, forward-looking briefing to help schools, colleges and universities protect students, staff and partner data after the Department for Education breach.</description>
      <pubDate>Wed, 29 Jul 2026 19:48:49 GMT</pubDate>
      <category>Guides</category>
    </item>
    <item>
      <title>Cyber Attackers Take 607,000 Records From the Department for Education</title>
      <link>https://www.fire-vault.com/news/dfe-cyber-attack-607000-records-2026</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/dfe-cyber-attack-607000-records-2026</guid>
      <description>Around 607,000 records were taken in a cyber attack on the Department for Education in England, affecting the Turing Scheme portal and the departmental help desk. The incident lands in a sector where more than half of schools reported an attack or breach in the past year.</description>
      <pubDate>Wed, 29 Jul 2026 19:47:51 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>Rogue AI Agents: A Firevault Commentary on the Hugging Face Incident</title>
      <link>https://www.fire-vault.com/news/rogue-ai-agents-hugging-face-opinion-2026</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/rogue-ai-agents-hugging-face-opinion-2026</guid>
      <description>Firevault commentary on the first fully autonomous AI hack. Our take on what boards should do, informed by Joe Tidy&apos;s BBC reporting.</description>
      <pubDate>Wed, 29 Jul 2026 11:18:29 GMT</pubDate>
      <category>Industry Insight</category>
    </item>
    <item>
      <title>Zero-Copy Cloud is Not the End of Lock-In. It is the Start of a New One</title>
      <link>https://www.fire-vault.com/news/zero-copy-cloud-lock-in-opinion-2026</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/zero-copy-cloud-lock-in-opinion-2026</guid>
      <description>SAP and Google Cloud have made data migration quietly optional. The data stays put. The operating judgment built above it does not. That is the lock-in the architecture diagram will never show.</description>
      <pubDate>Wed, 29 Jul 2026 10:29:12 GMT</pubDate>
      <category>Opinion</category>
    </item>
    <item>
      <title>22-Year-Old IPMI Flaw in Server BMCs Exposes 24,000 Machines to Password Theft</title>
      <link>https://www.fire-vault.com/news/ipmi-bmc-flaw-exposes-24000-servers-2026</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/ipmi-bmc-flaw-exposes-24000-servers-2026</guid>
      <description>A 22-year-old authentication weakness in IPMI 2.0 is leaking password hashes from more than 24,000 internet-exposed Baseboard Management Controllers, giving attackers near-physical control of servers beneath the operating system.</description>
      <pubDate>Wed, 29 Jul 2026 10:23:27 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>Ernst &amp; Young Breach Claimed by ShinyHunters: Supply-Chain Attack Hits Big Four Firm</title>
      <link>https://www.fire-vault.com/news/ernst-young-shinyhunters-supply-chain-breach-2026</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/ernst-young-shinyhunters-supply-chain-breach-2026</guid>
      <description>The ShinyHunters extortion gang has claimed responsibility for the Ernst &amp; Young breach, saying stolen third-party credentials opened the door to EY&apos;s Jira, GitHub and Azure environments, and to client tax documents.</description>
      <pubDate>Mon, 27 Jul 2026 12:00:00 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>Alarm Raised: UK Healthcare Sees Tenfold Rise in Cyber-Attacks in Early 2026</title>
      <link>https://www.fire-vault.com/news/uk-healthcare-tenfold-rise-cyber-attacks-2026</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/uk-healthcare-tenfold-rise-cyber-attacks-2026</guid>
      <description>SonicWall recorded 264,000 attack events across UK healthcare in the first five months of 2026, nearly ten times the total for all of 2025. Legacy Java middleware, unpatched patient portals and internet-exposed load balancers are being stress-tested to breaking point.</description>
      <pubDate>Sun, 26 Jul 2026 19:14:27 GMT</pubDate>
      <category>Insight</category>
    </item>
    <item>
      <title>Tribeca Film Festival Data Leak Exposes Celebrity Contact Details</title>
      <link>https://www.fire-vault.com/news/tribeca-film-festival-celebrity-contacts-leak-2026</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/tribeca-film-festival-celebrity-contacts-leak-2026</guid>
      <description>Cybersecurity researcher Jeremiah Fowler says three unprotected Tribeca-linked databases exposed a folder of celebrity contact details, including phone numbers and email addresses for Angelina Jolie, Robert De Niro and Martin Scorsese.</description>
      <pubDate>Sun, 26 Jul 2026 18:00:00 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>Firevault Awarded Cyber Essentials and Cyber Essentials Plus Certification</title>
      <link>https://www.fire-vault.com/news/firevault-cyber-essentials-plus-certified</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/firevault-cyber-essentials-plus-certified</guid>
      <description>Firevault has been awarded Cyber Essentials and Cyber Essentials Plus certification, the UK Government-backed scheme run by the NCSC, following an independent technical audit of its systems and controls.</description>
      <pubDate>Sun, 26 Jul 2026 10:00:00 GMT</pubDate>
      <category>News</category>
    </item>
    <item>
      <title>LAUNDRY BEAR: UK and Allies Expose Russian State-Supported Zero-Click Email Attack on Zimbra</title>
      <link>https://www.fire-vault.com/news/laundry-bear-zimbra-zero-click-2026</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/laundry-bear-zimbra-zero-click-2026</guid>
      <description>The NCSC and 15 partner agencies have exposed LAUNDRY BEAR, a Russian state-supported group using a zero-click exploit called &quot;beehive&quot; to silently steal email from Western organisations running Zimbra Collaboration Suite. The user only needs to open a message. No click, no attachment, no warning.</description>
      <pubDate>Fri, 24 Jul 2026 09:00:00 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>The worst-kept secret in AI: every frontier model has gone rogue</title>
      <link>https://www.fire-vault.com/news/frontier-ai-models-go-rogue-aisi-2026</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/frontier-ai-models-go-rogue-aisi-2026</guid>
      <description>The AISI Frontier AI Trends Report and OpenAI&apos;s live sandbox escape have finally put numbers behind what researchers, regulators and lab leaders have been saying for two years. Frontier models can be jailbroken, agents can escape, and containment is an open engineering problem. A Firevault synthesis of the evidence, the industry chorus, and what UK policy should now require.</description>
      <pubDate>Fri, 24 Jul 2026 07:28:43 GMT</pubDate>
      <category>Insight</category>
    </item>
    <item>
      <title>OpenAI Agent Escapes Sandbox, Breaches Hugging Face in &quot;Unprecedented&quot; Autonomous Cyber-Attack</title>
      <link>https://www.fire-vault.com/news/openai-agent-escapes-sandbox-hugging-face-breach-2026</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/openai-agent-escapes-sandbox-hugging-face-breach-2026</guid>
      <description>OpenAI has confirmed one of its advanced agents broke out of a controlled security-test sandbox, discovered a vulnerability on its own, and used it to gain access to internal systems at Hugging Face. It may be the first publicly disclosed autonomous AI-on-AI breach.</description>
      <pubDate>Thu, 23 Jul 2026 19:45:01 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>Origin Energy Confirms Customer Data Breach: 4.8 Million Retail Customers on Notice</title>
      <link>https://www.fire-vault.com/news/origin-energy-customer-data-breach-2026</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/origin-energy-customer-data-breach-2026</guid>
      <description>Origin Energy, Australia&apos;s largest energy retailer, has confirmed unauthorised access and disclosure of customer data. Names, addresses, dates of birth, phone numbers, account information and partial card and bank details may be exposed.</description>
      <pubDate>Thu, 23 Jul 2026 06:00:00 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>Coca-Cola Halts fairlife US Production After Ransomware Hits Dairy Systems</title>
      <link>https://www.fire-vault.com/news/coca-cola-fairlife-ransomware-halts-us-production-2026</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/coca-cola-fairlife-ransomware-halts-us-production-2026</guid>
      <description>A ransomware event at fairlife, Coca-Cola&apos;s billion-dollar dairy subsidiary, forced the company to suspend all United States production on 16 July 2026. The incident shows how a single IT breach can stop physical manufacturing lines and disrupt consumer supply chains.</description>
      <pubDate>Mon, 20 Jul 2026 16:37:01 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>Seven Million Driver Records, Halted Taxis and Agentic Ransomware: What This Week Tells Us About Data Exposure</title>
      <link>https://www.fire-vault.com/news/assuranceamerica-jade-puffer-ss7-week-in-hacks</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/assuranceamerica-jade-puffer-ss7-week-in-hacks</guid>
      <description>A single week in July 2026 brought a seven million record insurance breach in the United States, a malware shutdown at Japan&apos;s largest taxi operator, mobile network spying against US military personnel, and the first documented agentic ransomware operation. The common thread is data that lived where attackers could reach it.</description>
      <pubDate>Mon, 20 Jul 2026 16:31:42 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>Lidl Warns Customers After Third-Party IT Provider Breach</title>
      <link>https://www.fire-vault.com/news/lidl-third-party-it-provider-data-breach</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/lidl-third-party-it-provider-data-breach</guid>
      <description>Lidl has warned online shoppers in Germany, Belgium and the Netherlands that names, phone numbers, email addresses and dates of birth were stolen from a third-party IT provider. The breach is a fresh reminder that supplier risk is customer risk.</description>
      <pubDate>Tue, 14 Jul 2026 21:50:59 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>Urgent Briefing and Advice: Protecting Personal Data for High-Profile Figures in the Public Eye</title>
      <link>https://www.fire-vault.com/news/urgent-guide-protecting-personal-data-high-profile-public-eye</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/urgent-guide-protecting-personal-data-high-profile-public-eye</guid>
      <description>Practical steps for serving and former politicians, councillors, campaigners, journalists, executives, broadcasters and anyone in the public eye, covering email security, device hygiene, threat handling and offline secure storage.</description>
      <pubDate>Tue, 14 Jul 2026 19:25:32 GMT</pubDate>
      <category>Guides</category>
    </item>
    <item>
      <title>JLR Cyber Attack Rated Category 3: £1.9bn UK Impact, Says Cyber Monitoring Centre</title>
      <link>https://www.fire-vault.com/news/jlr-cyber-attack-cmc-category-3-19bn-uk-impact</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/jlr-cyber-attack-cmc-category-3-19bn-uk-impact</guid>
      <description>The Cyber Monitoring Centre has categorised the Jaguar Land Rover cyber incident as a Category 3 systemic event, estimating a £1.9 billion UK financial impact and disruption to more than 5,000 organisations. It is described as the most economically damaging cyber event ever to hit the UK.</description>
      <pubDate>Sat, 11 Jul 2026 11:26:43 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>FBI Warns of Malicious TDS Attacks Bypassing Firewalls</title>
      <link>https://www.fire-vault.com/news/fbi-warns-malicious-traffic-distribution-systems-ransomware</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/fbi-warns-malicious-traffic-distribution-systems-ransomware</guid>
      <description>FBI PSA I-061826-PSA warns of cyber criminals using Traffic Distribution Systems to deliver ransomware. Mark Fermor on the offline defence.</description>
      <pubDate>Fri, 10 Jul 2026 06:56:32 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>Ohio Dialysis Provider Breach Hits 8,000 Patients</title>
      <link>https://www.fire-vault.com/news/centers-for-dialysis-care-breach-exposes-8000-patients</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/centers-for-dialysis-care-breach-exposes-8000-patients</guid>
      <description>Centers for Dialysis Care in Cleveland has confirmed a network breach exposing 8,000 patients and staff. Mark Fermor on why offline storage stops this cold.</description>
      <pubDate>Fri, 10 Jul 2026 06:28:35 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>NHS Chief Condemns Patient Record Snooping</title>
      <link>https://www.fire-vault.com/news/nhs-chief-condemns-staff-curiosity-after-major-patient-privacy-breaches</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/nhs-chief-condemns-staff-curiosity-after-major-patient-privacy-breaches</guid>
      <description>Sir Jim Mackey has warned 40 NHS workers who accessed a child&apos;s medical records. Mark Fermor explains how air-gapped storage prevents insider snooping.</description>
      <pubDate>Fri, 10 Jul 2026 05:09:29 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>Accenture Confirms Breach as Hacker Advertises 35GB of Source Code and Keys</title>
      <link>https://www.fire-vault.com/news/accenture-confirms-breach-hacker-35gb-source-code</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/accenture-confirms-breach-hacker-35gb-source-code</guid>
      <description>Accenture has confirmed a security incident after a threat actor known as &quot;888&quot; advertised 35GB of stolen source code, RSA and SSH keys, Azure access tokens and configuration files on a cybercrime forum. The consultancy says the source is remediated and operations are unaffected, but the leak underlines how quickly developer secrets become an attacker&apos;s launchpad.</description>
      <pubDate>Thu, 09 Jul 2026 11:36:09 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>NCSC warns UK organisations over global Fortinet firewall and VPN credential leak</title>
      <link>https://www.fire-vault.com/news/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/ncsc-warns-uk-organisations-fortinet-firewall-vpn-credential-leak</guid>
      <description>The National Cyber Security Centre has issued an alert after a threat actor leaked a database of credentials harvested from brute-force and credential-stuffing attacks against internet-facing Fortinet firewalls and VPN gateways. UK organisations using FortiGate or Fortinet VPN portals are urged to investigate exposure and apply mitigations immediately.</description>
      <pubDate>Wed, 08 Jul 2026 17:15:23 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>Russian hackers steal UK government logins: why offline vaults change the equation</title>
      <link>https://www.fire-vault.com/news/russian-hackers-steal-uk-government-logins-offline-vaults</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/russian-hackers-steal-uk-government-logins-offline-vaults</guid>
      <description>The Telegraph reports that Russian-linked hackers have harvested UK government login credentials and traded them on dark-web forums. The incident is a reminder that credentials, however well protected in the cloud, remain the single point of failure that offline data vaults are designed to remove.</description>
      <pubDate>Tue, 07 Jul 2026 07:51:36 GMT</pubDate>
      <category>News</category>
    </item>
    <item>
      <title>FBI FLASH: TeamPCP Hits Software Supply Chain, Steals Cloud Keys</title>
      <link>https://www.fire-vault.com/news/fbi-flash-teampcp-software-supply-chain-attacks</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/fbi-flash-teampcp-software-supply-chain-attacks</guid>
      <description>FBI FLASH warns that TeamPCP is compromising widely used developer and security tools to steal cloud tokens, SSH keys and Kubernetes secrets. What UK organisations must isolate now.</description>
      <pubDate>Sun, 05 Jul 2026 10:19:25 GMT</pubDate>
      <category>Breaking</category>
    </item>
    <item>
      <title>Russia&apos;s NoName Hacks Quebec Water Plant | Utility Response</title>
      <link>https://www.fire-vault.com/news/russian-noname-hack-quebec-water-treatment-plant</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/russian-noname-hack-quebec-water-treatment-plant</guid>
      <description>Russia-linked NoName breached a Quebec water treatment plant&apos;s SCADA. What UK and Canadian water utilities must isolate, air-gap and audit now.</description>
      <pubDate>Sun, 05 Jul 2026 09:49:53 GMT</pubDate>
      <category>Breaking</category>
    </item>
    <item>
      <title>Employment Documentation Is a Breach Readiness Control</title>
      <link>https://www.fire-vault.com/news/employment-documentation-breach-readiness</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/employment-documentation-breach-readiness</guid>
      <description>Breach readiness does not start with the alert. It starts in the employment contract, the staff handbook and the policies that tell people what they are responsible for. Mark Fermor on why vague duties become the firm&apos;s problem.</description>
      <pubDate>Sat, 04 Jul 2026 12:30:00 GMT</pubDate>
      <category>Insight</category>
    </item>
    <item>
      <title>Nissan / PeopleSoft Breach: When HR Is Also Your Financial Data Repository</title>
      <link>https://www.fire-vault.com/news/nissan-oracle-peoplesoft-shinyhunters-commentary</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/nissan-oracle-peoplesoft-shinyhunters-commentary</guid>
      <description>Nissan Americas has confirmed employee SSNs, banking and tax data were exposed through the Oracle PeopleSoft zero-day (CVE-2026-35273) campaign linked to ShinyHunters. Mark Fermor on why HR systems keep becoming citizen-scale breaches.</description>
      <pubDate>Sat, 04 Jul 2026 11:00:00 GMT</pubDate>
      <category>Commentary</category>
    </item>
    <item>
      <title>Tata / Apple Leak Shows Why Supply-Chain Data Belongs Off the Wire</title>
      <link>https://www.fire-vault.com/news/tata-apple-iphone-18-supply-chain-leak-commentary</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/tata-apple-iphone-18-supply-chain-leak-commentary</guid>
      <description>World Leaks has posted iPhone 18 Pro supplier maps and drop-test photos taken from Apple&apos;s Indian manufacturer Tata Electronics. Mark Fermor on why the answer is architectural, not contractual.</description>
      <pubDate>Sat, 04 Jul 2026 10:00:00 GMT</pubDate>
      <category>Commentary</category>
    </item>
    <item>
      <title>Conwy Council Breaches Show the Insider Threat Regulators Keep Underestimating</title>
      <link>https://www.fire-vault.com/news/conwy-council-insider-data-breach-commentary</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/conwy-council-insider-data-breach-commentary</guid>
      <description>Three separate disciplinary outcomes in one department in twelve months. Mark Fermor on why the Conwy County Council data breaches are a structural warning to every UK local authority, not a one-off.</description>
      <pubDate>Sat, 04 Jul 2026 09:00:00 GMT</pubDate>
      <category>Commentary</category>
    </item>
    <item>
      <title>FortiBleed Proves the IP-Connected Perimeter is Indefensible</title>
      <link>https://www.fire-vault.com/news/fortibleed-inc-lynx-ransomware-commentary</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/fortibleed-inc-lynx-ransomware-commentary</guid>
      <description>SOCRadar has now tied the FortiBleed credential-harvesting operation directly to INC and Lynx ransomware deployments. Mark Fermor on why physical severance is the only durable answer.</description>
      <pubDate>Fri, 03 Jul 2026 09:00:00 GMT</pubDate>
      <category>Commentary</category>
    </item>
    <item>
      <title>Firevault backs CBN CyberSummit as UK cyber leaders meet at Bird &amp; Bird</title>
      <link>https://www.fire-vault.com/news/firevault-sponsors-cbn-cybersummit-2026</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/firevault-sponsors-cbn-cybersummit-2026</guid>
      <description>Firevault backed the first CBN CyberSummit at Bird and Bird, joining Baroness Liz Lloyd, Alison Griffiths MP and CNI leaders on the future of UK cyber resilience.</description>
      <pubDate>Tue, 23 Jun 2026 09:00:00 GMT</pubDate>
      <category>Announcement</category>
    </item>
    <item>
      <title>Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery</title>
      <link>https://www.fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery</guid>
      <description>Two Scattered Spider members have admitted the £39m TfL hack. Mark Fermor on identity blast radius and why offline recovery is the deciding layer.</description>
      <pubDate>Mon, 22 Jun 2026 15:26:35 GMT</pubDate>
      <category>Threat Analysis</category>
    </item>
    <item>
      <title>Iranian state hackers targeting OT: why offline golden copies decide the recovery</title>
      <link>https://www.fire-vault.com/news/iran-ot-ics-targeting-offline-golden-copies-cni</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/iran-ot-ics-targeting-offline-golden-copies-cni</guid>
      <description>A new Congressional Research Service report names Iran alongside China, Russia and North Korea as a leading cyber adversary, with operations now reaching deep into industrial control systems. The recovery problem is no longer about backups. It is about whether your golden copies are reachable by the attacker.</description>
      <pubDate>Sun, 21 Jun 2026 18:59:08 GMT</pubDate>
      <category>Insight</category>
    </item>
    <item>
      <title>UK critical infrastructure hit by 200 cyber incidents in a year, NCSC warns</title>
      <link>https://www.fire-vault.com/news/ncsc-uk-critical-infrastructure-incidents-double</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/ncsc-uk-critical-infrastructure-incidents-double</guid>
      <description>NCSC chief Richard Horne says the UK faced more than 200 nationally significant cyber incidents against critical infrastructure in a year, with about three-quarters tied to state actors.</description>
      <pubDate>Sat, 20 Jun 2026 05:14:36 GMT</pubDate>
      <category>Threat Analysis</category>
    </item>
    <item>
      <title>24 billion credentials exposed in record infostealer leak</title>
      <link>https://www.fire-vault.com/news/24-billion-credentials-infostealer-leak</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/24-billion-credentials-infostealer-leak</guid>
      <description>Cybernews researchers found an 8.3 TB Elasticsearch cluster holding 24 billion records, including plaintext passwords and login URLs harvested from infostealer logs.</description>
      <pubDate>Fri, 19 Jun 2026 20:49:36 GMT</pubDate>
      <category>Threat Analysis</category>
    </item>
    <item>
      <title>FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials</title>
      <link>https://www.fire-vault.com/news/fortibleed-74000-fortinet-firewalls-credentials-exposed</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/fortibleed-74000-fortinet-firewalls-credentials-exposed</guid>
      <description>Researchers say a Russian-speaking crew cracked nearly half the internet&apos;s Fortinet firewalls, exposing plaintext logins for Oracle, Chevron, Lenovo, FedEx, a NATO defence contractor and Fortinet itself.</description>
      <pubDate>Thu, 18 Jun 2026 09:03:31 GMT</pubDate>
      <category>Threat Analysis</category>
    </item>
    <item>
      <title>CBN CyberSummit 2026: Baroness Liz Lloyd and Senior CNI Leaders to Address UK Cyber Resilience</title>
      <link>https://www.fire-vault.com/news/cbn-cybersummit-2026-baroness-liz-lloyd-cni-leaders</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/cbn-cybersummit-2026-baroness-liz-lloyd-cni-leaders</guid>
      <description>The Cybersecurity Business Network has unveiled the full agenda for its inaugural CyberSummit on 23 June 2026, with Baroness Liz Lloyd headlining a CNI-focused line-up. Firevault joins as a sponsor.</description>
      <pubDate>Sun, 14 Jun 2026 15:29:27 GMT</pubDate>
      <category>Industry</category>
    </item>
    <item>
      <title>South Korea fines Coupang $400m over data breach affecting 37.5 million customers</title>
      <link>https://www.fire-vault.com/news/south-korea-fines-coupang-400m-data-breach-37m-customers</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/south-korea-fines-coupang-400m-data-breach-37m-customers</guid>
      <description>South Korea has issued its largest-ever data breach fine, penalising e-commerce giant Coupang more than $400m after the personal data of 37.5 million customers, more than half the country&apos;s population, was exposed.</description>
      <pubDate>Sun, 14 Jun 2026 15:21:39 GMT</pubDate>
      <category>News (Threat Analysis)</category>
    </item>
    <item>
      <title>Great Marlow School partially closed after cyber attack</title>
      <link>https://www.fire-vault.com/news/great-marlow-school-cyber-attack-partial-closure</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/great-marlow-school-cyber-attack-partial-closure</guid>
      <description>A malware incident has shut down ICT systems at Great Marlow School in Buckinghamshire, cancelling lessons and silencing parent communications. Here is what it tells us.</description>
      <pubDate>Sun, 14 Jun 2026 15:18:42 GMT</pubDate>
      <category>News</category>
    </item>
    <item>
      <title>Essex NHS hospitals: 2,380 patient records compromised in Synnovis cyber attack</title>
      <link>https://www.fire-vault.com/news/essex-nhs-hospitals-synnovis-breach-2380-records</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/essex-nhs-hospitals-synnovis-breach-2380-records</guid>
      <description>Mid and South Essex NHS Foundation Trust has confirmed around 2,380 patient test records were stolen via third-party diagnostics provider Synnovis, as the fallout from the June 2024 Qilin ransomware attack continues to widen.</description>
      <pubDate>Mon, 08 Jun 2026 22:37:29 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
    <item>
      <title>Disconnect to Protect: Why the AI Era Is Forcing a Rethink of Cyber Resilience</title>
      <link>https://www.fire-vault.com/news/disconnect-to-protect-ai-era</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/disconnect-to-protect-ai-era</guid>
      <description>Inside the AI Security Institute, the NYT reports red-teamers cracking OpenAI&apos;s newest model in six hours and finding safety gaps in every leading system. Autonomous cyber capability is now doubling every 4.7 months. Why selective physical disconnection is becoming the only honest answer.</description>
      <pubDate>Tue, 26 May 2026 19:33:28 GMT</pubDate>
      <category>Insight</category>
    </item>
    <item>
      <title>How 4.1TB of breached data cost South Staffordshire Water £963,900</title>
      <link>https://www.fire-vault.com/news/south-staffordshire-water-ico-fine-963900-data-breach-2026</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/south-staffordshire-water-ico-fine-963900-data-breach-2026</guid>
      <description>The ICO has fined South Staffordshire Water £963,900 after a phishing email went undetected for 20 months, leading to 4.1 TB of personal data appearing on the dark web. Why physical disconnection breaks this chain.</description>
      <pubDate>Mon, 11 May 2026 09:00:00 GMT</pubDate>
      <category>Cyber Attack</category>
    </item>
    <item>
      <title>CI Fortify from CISA recommends that the operators of critical infrastructure must prepare themselves for forced isolation and quick recovery</title>
      <link>https://www.fire-vault.com/news/cisa-ci-fortify-isolation-recovery-firevault</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/cisa-ci-fortify-isolation-recovery-firevault</guid>
      <description>Insights from Mark Fermor on OT, ICS, and the underlying storage layer.</description>
      <pubDate>Thu, 07 May 2026 09:38:59 GMT</pubDate>
      <category>Industry Insight</category>
    </item>
    <item>
      <title>500,000 Volunteers Breached Through Authorised Access: A Controlled Access Buyer&apos;s Guide</title>
      <link>https://www.fire-vault.com/news/controlled-access-buyers-guide-offline-secure-storage</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/controlled-access-buyers-guide-offline-secure-storage</guid>
      <description>In April 2026, approved researchers exfiltrated the health records, genetic data, and medical histories of 500,000 UK Biobank volunteers through authorised access channels, then listed the data for sale on Alibaba. The breach was not caused by a hack. It was caused by a model that assumes licence agreements can prevent data theft. This guide covers why that model fails and what physical controls replace it.</description>
      <pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate>
      <category>Guides</category>
    </item>
    <item>
      <title>What Operational Technology Data Should Be Kept Offline?</title>
      <link>https://www.fire-vault.com/news/offline-secure-storage-operational-technology</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/offline-secure-storage-operational-technology</guid>
      <description>Which operational technology files create the greatest consequence when compromised, why connected backups still leave them exposed, and how offline custody supports safe recovery.</description>
      <pubDate>Thu, 23 Apr 2026 00:00:00 GMT</pubDate>
      <category>Insight</category>
    </item>
    <item>
      <title>Peppa Pig and Transformers owner Hasbro hit by cyber-attack</title>
      <link>https://www.fire-vault.com/news/hasbro-cyber-attack-peppa-pig-transformers-2026</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/hasbro-cyber-attack-peppa-pig-transformers-2026</guid>
      <description>Toy and entertainment giant Hasbro, owner of Peppa Pig, Transformers and Monopoly, has confirmed unauthorised access to its network. The breach was discovered on 28 March 2026 and could delay product deliveries for several weeks.</description>
      <pubDate>Wed, 01 Apr 2026 12:00:00 GMT</pubDate>
      <category>Cyber Attack</category>
    </item>
    <item>
      <title>World Backup Day 2026: Backups Are Not Enough</title>
      <link>https://www.fire-vault.com/news/world-backup-day-2026-why-backups-alone-are-not-enough</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/world-backup-day-2026-why-backups-alone-are-not-enough</guid>
      <description>Every 31 March, World Backup Day reminds organisations to protect their data. But in 2026, the real question is not whether you back up. It is whether your backups can survive the attack that is coming for them.</description>
      <pubDate>Tue, 31 Mar 2026 09:00:00 GMT</pubDate>
      <category>Opinion</category>
    </item>
    <item>
      <title>European Commission Breach: 350GB from Cloud</title>
      <link>https://www.fire-vault.com/news/european-commission-aws-cloud-data-breach-350gb</link>
      <guid isPermaLink="true">https://www.fire-vault.com/news/european-commission-aws-cloud-data-breach-350gb</guid>
      <description>The European Commission is investigating the theft of over 350GB of data from its Europa.eu cloud infrastructure hosted on AWS. The attacker plans to leak the data publicly rather than extort the institution, highlighting why sovereign data must be physically disconnected from cloud platforms.</description>
      <pubDate>Mon, 30 Mar 2026 19:37:59 GMT</pubDate>
      <category>Breach Analysis</category>
    </item>
  </channel>
</rss>