A UK government cyber pledge attracted only a handful of major companies despite a ministerial appeal. Notable signatories include Aviva, the London Stock Exchange Group, and Marks & Spencer.

Fewer than 15 of the UK's 350 largest listed companies have signed up to a new voluntary cybersecurity initiative, the Cyber Resilience Pledge, despite an appeal from government ministers. The pledge, launched on Tuesday, aims to encourage businesses to enhance their cyber defenses.
The launch event, held at 10 Downing Street and hosted by Technology Secretary Liz Kendall, announced 70 founding signatories. However, 20 of these are designated strategic government suppliers who were invited to join through a separate Government Cyber Charter. This leaves approximately 50 companies from the broader economy as voluntary participants.
Companies that did commit to the pledge include major firms like Aviva, the London Stock Exchange Group, and Marks & Spencer, the latter having experienced a significant cyberattack last year. Smaller cybersecurity firms, such as C3IA Solutions, Grey Zone Services, and Nexor, also signed on, aligning with their core business offerings.
The Cyber Resilience Pledge asks signatories to implement three key actions: making cybersecurity a responsibility at the board level, registering for the National Cyber Security Centre's (NCSC) free Early Warning service, and adopting a risk-based approach to requiring Cyber Essentials certification within their supply chains. These commitments are voluntary, and no enforcement mechanisms are in place.
The low turnout among FTSE 350 companies has drawn commentary. Jamie MacColl, a senior research fellow at the Royal United Services Institute, expressed surprise at the number of signatories, suggesting that many large companies may already meet equivalent or higher cybersecurity standards through existing certifications.
The government highlighted the financial impact of cyberattacks, stating that the average cost of a significant attack on a UK business is nearly £195,000, with an estimated annual cost to organizations of £14.7 billion, excluding broader economic disruption. This figure is linked to research supporting the Cyber Security and Resilience Bill, which is still under parliamentary debate and not expected to be enforced until 2028.
The Cyber Resilience Pledge was originally intended to follow the unveiling of the UK's National Cyber Action Plan, but that plan's release was delayed. The government indicated that the pledge's effectiveness will be reviewed after a 12-month period, with potential adjustments to its requirements based on the evolving threat landscape.
Some observers suggest this voluntary approach could be a precursor to future regulation. MacColl noted a pattern in UK cyber policy, where voluntary measures often precede legislative action, suggesting that a lack of widespread adoption could provide the government with justification for introducing mandatory requirements.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed