The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

British Prime Minister Andy Burnham has reappointed Liz Lloyd as the UK's cybersecurity minister, signaling continuity in national cyber policy despite a significant governmental restructuring that abolished the department previously overseeing the brief. Lloyd, who has led on cyber issues since September 2025, will retain her role while holding junior posts at both the Department for Digital, Culture, Media and Sport (DCMS) and the renamed Department for Business, Innovation, Science and Trade (DBIST).
The reappointment is notable as it goes against the trend of Burnham's initial cabinet selections, which largely removed allies of his predecessor, Keir Starmer. Lloyd, a close associate of Starmer and his former director of policy delivery, sits in the House of Lords as Baroness Lloyd of Effra. Her continued tenure is expected to prevent delays to the Cyber Security and Resilience Bill, which she is currently steering through the House of Lords. The bill, which cleared its second reading with cross-party support earlier this month, is scheduled for line-by-line scrutiny in September.
The Cyber Security and Resilience Bill aims to update regulations from 2018, expanding their scope to include more organizations and granting ministers powers to amend rules and issue directives to companies on national security grounds. Specifically, it brings data centers and managed service providers under regulatory purview and establishes incident reporting deadlines for operators of essential services such as energy, water, and healthcare. Lloyd was also the minister responsible when the government scaled back proposed cybersecurity protections for telecoms networks, measures initially developed in response to the Salt Typhoon espionage campaign, following industry lobbying regarding cost and practicality.
Burnham's government, formed after Starmer's resignation and a Labour Party leadership election, immediately dissolved the Department for Science, Innovation and Technology (DSIT), which had managed cyber policy since 2023. DSIT's functions have been divided: cyber policy and government digital services moved to DCMS, science to DBIST, and artificial intelligence policy along with the AI Security Institute to the Cabinet Office. This marks the first time AI security work has been separated from the broader cyber brief.
Industry observers have expressed concerns that this fragmentation could undermine the integrated approach to data, digital capabilities, and AI that was considered DSIT's primary strength. The placement of cyber policy within DCMS means it will share a department with politically sensitive cultural portfolios, including Online Safety and the renewal of the BBC Charter. While DCMS permanent secretary Susannah Storey is noted for her extensive experience in cyber issues, ministerial support is still deemed crucial for staff.
Lloyd had previously promised a National Cyber Action Plan, the government's strategy for defending the economy against state-backed and criminal hacking, for publication this summer. Its release, initially expected in early July, was delayed due to Starmer's resignation. A government spokesperson affirmed the importance of cybersecurity, stating that robust actions are being taken to protect the UK and improve resilience, with the Cyber Security and Resilience Bill designed to boost national cyber defenses. The spokesperson added that the redistribution of DSIT's functions recognizes technology as foundational to all future industry, culture, and public service delivery, rather than a separate economic facet.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed