This Week's Cyber Radar
This week showed how much risk sits in the places organisations rarely look: small sites, old sign-up data and software everyone trusts. Here's what happened this week, and what it means for you.
1. Iran-linked attack halts UK power plant
A small reserve power plant in the UK was shut down for four days following a cyber attack linked to Iran, and the incident has been reported to the NCSC. The site sat below the legal threshold at which operators must report cyber activity, so it drew little attention at the time. Notably, the UK has around 300 of these small peaker plants, which look insignificant individually but together form a growing part of the grid.
Read the source →2. Manchester Airports Group confirms data theft
Manchester Airports Group confirmed that a quantity of customer data was stolen and currently believes 8.7 million customers are affected. Most of those records are email addresses collected at Wi-Fi sign-up, taken from a database hosted by a third party, and no bank or payment details were involved. However, the group temporarily withdrew its Manage My Booking service as a precaution, which shows how quickly a data incident becomes a service issue.
Read the source →3. UK bill targets risky technology suppliers
Proposed amendments to the Cyber Security and Resilience Bill would allow ministers to intervene when essential service providers plan to buy technology from suppliers linked to hostile states. The government put the potential cost of a major attack on electricity networks in London and the southeast at up to £442bn over five years. In short, supplier choice is moving from a procurement decision to a matter of national security oversight.
Read the source →4. PaperCut zero-day forces second emergency patch
Print management supplier PaperCut confirmed active attacks against its NG and MF products and released an emergency patch, then issued a second one after researchers found multiple ways around the first. The two flaws are rated 9.4 and 8.8 out of 10 and can be chained to bypass authentication and run code on exposed servers. Therefore, organisations that patched early still need to apply the latest release and restrict access to management interfaces.
Read the source →5. Social engineering breaches major investment firm
Investment manager Apollo Global Management disclosed that attackers used social engineering to reach certain cloud platforms and remained inside for four days in July. The exposed information included names, dates of birth, addresses and Social Security numbers, and those affected are being offered 24 months of monitoring. However, the method was simple: phone calls posing as colleagues or IT support, followed by convincing login pages that captured credentials and one-time codes.
Read the source →Cyber pressure keeps rising. Clear thinking is what keeps it manageable.
Explore the full stories, sources and practical guidance on the RightCue knowledge hub.
Full story details & sources →Knowledge Hub
To see how we work with clients, ensuring data privacy compliance for their specific industries read our useful articles, guides and customer success stories





