NIBS (credit image/Pixabay/ Ryan McGuire)As vendors and security teams recover from Black Hat and Defcon, news continues to be thin. Holidays, however, aren’t stopping cyberattacks. Workday is the latest high-profile company to admit it was breached. It has told customers that the breach was not on its software but was a third-party breach. Researchers have pointed to the ShinyHunters group, which tricks people into connecting malicious OAuth apps to Salesforce. This gives them access to CRM data, which is stolen and used for extortion.

Dragos

Dragos Inc. has announced the appointment of Eric Cross as Chief Revenue Officer (CRO). Cross will lead all global go-to-market functions, including sales, customer success, partner and channel ecosystems, and marketing, as the company continues to deliver on its mission to safeguard industrial and critical infrastructure.

FBI

The FBI IC3 team are warning of an increased threat from Russia’s FSB Center 16. It has detected Russian FSB cyber actors exploiting Simple Network Management Protocol (SNMP) and end-of-life networking devices running an unpatched vulnerability (CVE-2018-0171) in Cisco Smart Install (SMI) to broadly target entities in the United States and globally.

noyb

The Austrian Federal Administrative Court (BVwG) has confirmed an earlier decision by the Austrian Data Protection Authority (DSB) that the Austrian newspaper DerStandard violated the GDPR when introducing “Pay or Okay”. The DSB and the Court both held that users must be able to selectively consent or object to each processing purpose. This case will now likely hit the Austrian Supreme Administrative Court – and potentially the Court of Justice.

Xalient

Xalient has published a blog titled, “Manufacturing’s Hidden Cyber Threat: The Growing Danger of Unsecured Machine Identities”. It looks at the rise of unmanaged identities across manufacturing from sensors through to PLCs and other devices. The challenge it addresses in the blog is that these machine identities are often unsecured. This is not a new problem but this is still an article worth reading as the problem is getting worse.

Security news from the week beginning 11 August 2025

Previous articleWorkday partners with DailyPay for On-Demand Pay
Next articleNews from the week beginning 18th August 2025
Ian Murphy
Ian Murphy is an enterprise technology journalist, podcaster, editor and industry analyst with more than 40 years' experience covering enterprise IT, cybersecurity, networking, cloud and artificial intelligence. His career combines hands-on technology experience with long-term industry analysis and journalism. In the 1980s, Ian authored an industry report on expert systems, an early application of artificial intelligence, and founded an IT training company delivering accredited training on enterprise software. He later became a Microsoft Certified Trainer, helping professionals understand and apply business technologies. Alongside his work as a freelance journalist and analyst, Ian developed software, deployed enterprise networks and managed software and technical support teams. That practical experience informs his writing, providing insight into not only what technologies promise, but how they are implemented and used in real enterprise environments. Ian has written thousands of articles, produced industry research, hosted podcasts and interviewed technology leaders across enterprise software, infrastructure, cybersecurity and AI. His work focuses on helping CIOs, IT leaders and technology professionals understand the opportunities, challenges and real-world impact of emerging technologies.

LEAVE A REPLY

Please enter your comment!
Please enter your name here