[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract
[INDIA] RBI, SEBI and IRDAI · Source-code escrow and continuity obligations for critical applications[EU DORA] ICT third-party risk testing required · In force Jan 2025[PRA] SS2/21 UK · Vendor recovery evidence required[MAS] Singapore TRM · Independent vendor recoverability expected[APRA] CPS 230 Australia · Third-party continuity obligations in force[FFIEC] United States · Source-code access and software escrow addressed in third-party contracts[ENTERPRISE] Mission-critical software procurement increasingly requires continuity evidence before contract

CASTLER CYBER WATCH

Cybersecurity news
that matters to your business.

Data breaches, cyberattacks, exploited vulnerabilities and supply-chain failures — what happened, what is actually confirmed, and what it means for the software and vendors you depend on.

Last source check: 4 October 2026

Coverage may be out of date. No successful source check has been recorded in the past 36 hours.

Latest published updates

Newest publications first

Published date

Phishing & malware· Reported· Reported 10 September 2026

Trezor warns of phishing after an email-provider breach

Trezor warned that a third-party email-provider breach was being used to send fraudulent security alerts to customers, according to BleepingComputer. The company said the messages were phishing attempts and that it was investigating. The messages' claimed wallet vulnerability is part of the lure, not a verified finding.

Phishing & malware· Reported· Reported 10 September 2026

Trezor warns of phishing after an email-provider breach

Trezor warned that a third-party email-provider breach was being used to send fraudulent security alerts to customers, according to BleepingComputer. The company said the messages were phishing attempts and that it was investigating. The messages' claimed wallet vulnerability is part of the lure, not a verified finding.

Cyberattacks· Reported· Reported 21 September 2026

GreyNoise reports government data theft via WordPress and Zyxel

GreyNoise reports that attackers used two WordPress vulnerabilities against at least 49 organizations and stole more than 18,000 records from an unnamed Western government. It also reports exploitation and data extraction from 996 Zyxel GS1900 switches in 48 countries. The observations come from the firm's sensors and attacker infrastructure; the government victim remains unnamed and state sponsorship is not established.

Cyberattacks· Reported· Reported 21 September 2026

GreyNoise reports government data theft via WordPress and Zyxel

GreyNoise reports that attackers used two WordPress vulnerabilities against at least 49 organizations and stole more than 18,000 records from an unnamed Western government. It also reports exploitation and data extraction from 996 Zyxel GS1900 switches in 48 countries. The observations come from the firm's sensors and attacker infrastructure; the government victim remains unnamed and state sponsorship is not established.

Published date

Published date

Supply chain· Reported· Reported 9 September 2026

Veradigm reports patient-data exposure through a vendor's credentials

Veradigm says credentials obtained from a third-party vendor were used to access a limited customer-service interface and copy patient information. BleepingComputer reports that the company has not identified the attacker and says operations were not disrupted. A ransomware group's separate claims about the volume of stolen records remain unverified.

Feed headings show when Castler published each update. Each card separately shows the source reporting date, which may differ from when the incident occurred.