Daily Recap, UK unveils a new national cyber action plan to close public-sector gaps and strengthen defenses across government, while the US signals broad diplomatic shifts by exiting global cyber coalitions and dozens of international treaties. In industry and innovation, CrowdStrike will buy identity-security firm SGNL for $740 million to expand identity threat coverage, Blackbird.AI raises 28 million to grow its narrative-intelligence platform and analytics, and OpenAI launches ChatGPT Health with isolated, encrypted controls for sensitive health data to support HIPAA-style protections. #UKCyberPlan #USExit #CrowdStrike #SGNL #BlackbirdAI #OpenAIHealth #AgenticAI #ChromeExtensions #jsPDF #n8n #CiscoISE #MFA #Taiwan #China #Iberia #Prosura #MicrosoftExchangeOnline #GoBruteforcer #RustFS
Policy & International
- UK unveils a new national cyber action plan to close public-sector gaps and strengthen defenses across government β UK Cyber Plan, UK Cyber Plan
- US orders exits from global cyber and hybrid-threat coalitions, pulling back from multilateral cybersecurity cooperation β US Exit Orders
- US announces withdrawals from dozens of international treaties and organizations, signaling broad diplomatic shifts with cyber implications β US Withdrawals
Industry & Funding
- CrowdStrike will buy identity-security firm SGNL for $740 million in cash to expand identity threat coverage β CrowdStrike Buy
- Blackbird.AI raises $28 million to grow its narrative-intelligence platform and analytics offerings β Blackbird Raise
- OpenAI launches ChatGPT Health with isolated, encrypted controls for sensitive health data to support HIPAA-style protections β OpenAI Health
AI & Privacy
- Security researchers urge rethinking defenses for agentic AI, warning of new attack surfaces from autonomous models β Agentic AI
- Multiple Chrome extensions with 900,000 downloads were found stealing AI chat content, exposing user conversations and data to third parties β Chrome Extensions
- Opinion pieces and analysis examine influence dynamics in security commentary and the evolving trust model for open source projects β Security Voices, Trusted OSS
Vulnerabilities & Exploits
- A critical jsPDF flaw that lets attackers exfiltrate secrets via crafted PDFs has been disclosed and patched β researchers and vendors urge urgent updates β jsPDF Flaw, jsPDF Flaw
- n8n webhook vulnerability CVE-2026-21858 allows unauthenticated file access and RCE, exposing instances to takeover β apply vendor fixes immediately β n8n Takeover, n8n Takeover
- Cisco ISE flaws with public PoC/exploit code prompted emergency patches and warnings after active exploitation was reported β Cisco ISE, Cisco ISE
- CISA flags actively exploited bugs in Microsoft Office and tags a max-severity flaw in HPE OneView, with vendors and admins urged to patch now β Actively Exploited, HPE OneView
- Threat roundup highlights a wide set of issues including a RustFS flaw, Iranian operations, WebUI RCEs and cloud leaks β investigators warn of ongoing multi-front campaigns β ThreatsDay Bulletin
- New wave of GoBruteforcer attacks targeting crypto and blockchain projects is underway; custodians should harden credentials and node access β GoBruteforcer Wave
Incidents & Outages
- Australian insurer Prosura confirms a cyber incident and has taken online services offline while investigating customer impact β Prosura Incident
- Spanish airline Iberia says recent breach claims relate to a November incident as it investigates data-exposure allegations β Iberia Breach
- Microsoft Exchange Online outage disrupted mailbox access via IMAP4, blocking some users from legacy mail clients during an incident window β Microsoft Outage
- Analysis shows dozens of major breaches were enabled by info-stealers and the absence of MFA, underscoring the need for stronger identity controls β Infostealer Breaches
- Microsoft announces enforcement of MFA for Microsoft 365 admin center signβins to reduce account takeover risk for administrators β M365 MFA
NationβState & Threat Metrics
- Taiwan is reportedly hit with about 2.6 million cyberattacks daily attributed to operations from China, highlighting persistent nation-state pressure on critical infrastructure β Taiwan Attacks