This Week's Cyber Radar
This week's headlines had less to do with new attack methods than with access and dependencies that organisations had stopped examining. Here's what happened this week, and what it means for you.
1. Airport data leaked after ransom refused
Manchester Airports Group refused to pay, and FulcrumSec published around half a terabyte of data covering 8.7 million people who used parking, lounge, Fast Track and Wi-Fi services at Manchester, Stansted and East Midlands airports. The gang claims it got in using administrative keys left in public website code. However, financial data is not thought to be affected, and the practical risk now is a long tail of scams aimed at travellers.
Read the source →2. FCA warns of AI vulnerability bottlenecks
The Financial Conduct Authority has warned that frontier AI models are uncovering vulnerabilities faster than financial firms can assess and remediate them. Its review sets out four questions for firms to work through, from where the bottlenecks sit to whether urgent fixes can be made at pace. Notably, the regulator also flags vulnerability chaining, where several low-rated flaws combine into a route that conventional scanning would miss.
Read the source →3. NHS email concentrated on one supplier
Computer Weekly mapped the public domain records of 213 English NHS trusts and found 165 connected to at least one US hyperscale provider, with 132 routing email and identity through Microsoft 365. Three-quarters sit in a mixed position, depending on UK and US-hosted services at the same time. In short, the concentration looks less like a decision than a drift, and the same pattern is common across private sector estates.
Read the source →4. Legacy login opens Dropbox accounts
Dropbox has told around 5,000 customers that attackers reached their accounts by abusing a legacy Lenovo sign-in integration between 4 and 21 August. None of the affected accounts had two-factor authentication enabled, and files were accessed for fewer than a third of them. Therefore the lesson is less about either company than about the quiet risk sitting in integrations nobody has reviewed.
Read the source →5. French hospital fined over access failures
France's data protection regulator has fined a private hospital in Saint-Etienne 500,000 euros after an attacker took data on more than 727,000 patients and their nominated contacts. External users could reach the patient record system without a virtual private network or multi-factor authentication, and there was no near-real-time monitoring to catch several days of activity. In short, the penalty followed the state of the controls, not the sophistication of the attacker.
Read the source →Clarity about access and dependencies is what makes resilience possible.
Read the full write-ups, sources and practical next steps on the RightCue knowledge hub.
Full story details & sources →Knowledge Hub
To see how we work with clients, ensuring data privacy compliance for their specific industries read our useful articles, guides and customer success stories





