Another European government department has taken a hit. If you think that is somebody elseβs problem, think harder. The Dutch Finance Ministry breach is a warning shot for every UK organisation that still believes attackers only care about the big glamorous targets.
If you have a QNAP router humming away in a cupboard and nobody has looked at it in months, this story is for you. QNAP has patched critical QuRouter flaws, and the bigger issue is not just the bugs. It is the number of businesses that forget the edge device exists until it bites them.
Todayβs hot cyber security story is not subtle. Citrix has patched a critical NetScaler flaw, NHS England has already put out an alert, and any UK organisation using vulnerable NetScaler kit needs to move now. If your remote access stack includes NetScaler, this is your wake up call.
A trusted security tool got turned into a thief. That is the part people keep missing. The Trivy supply chain attack is not just a developer story. It is a board level lesson in what happens when your pipeline trusts tags, tokens and wishful thinking.