This is the first round-up of 2025 and includes a few items from the December 2024 holiday period. Most vendors reduced their press outreach from mid-December, so there was little to report apart from some government releases.
Among the noteworthy news, Venafi published a report highlighting the problem of machine identities. The report, “The Impact of Machine Identities on the State of Cloud Native Security in 2024,” notes that many of these identities are rarely monitored and use default passwords. It concludes that they are a major hole in cybersecurity.
Dragos reported that it saw 394 unique attacks in Q3/2024 targeting manufacturers. These attacks represent 71% of all the ransomware incidents it detected across key industries, making manufacturing the most likely industry to suffer an active attack.
Dragos
Dragos Inc. and the Singapore Armed Forces’ Digital and Intelligence Service (DIS) have signed a Memorandum of Understanding (MOU) to jointly develop advanced cybersecurity capabilities. The two organisations will collaborate on strategic cybersecurity planning and training, and facilitate the two-way sharing of information about cyber threats.
ENCS
The World Bank’s Energy Sector Management Assistance Program (ESMAP) and the European Network for Cybersecurity (ENCS) successfully organized the first Cybersecurity Study Tour in Paris, together with their French partners ENEDIS, RTE and Cybersecurity Campus.
The Cybersecurity Study Tour offered a hands-on learning experience through lectures from ENCS experts and site visits to leading organizations, including ENEDIS, RTE and Campus Cyber. Over 50 participants from 23 different nationalities could deepen their understanding of grid security, Information Technology (IT) / Operational Technology (OT) integration and energy cyber regulation.
noyb
Almost five years after noyb filed a complaint against Netflix, the Dutch data protection authority has fined it €4.75 Million. The fine is due to the company’s failure to adequately respond to users’ access requests under Article 15 GDPR. This meant that Netflix customers were unaware of what it does to their data.
Noyb has filed a GDPR complaint against Ryanair because it now requires customers to create a mandatory account to book tickets and undergo a new verification process. That process will involve invasive biometrics, including a face scan. According to noyb there is no reasonable justification for such a system. This is the second complaint it has filed over this issue.

















