South Korea plans to discipline public-agency heads for basic cyber lapses after 247 public-sector breaches since 2021 led to no head being disciplined. The penalties are headed into the rules now, while the staff incentives and the security budget are still being worked out.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives50
- Confidence55
Detectify found 86% to 97% of open critical and high flaws on 1,293 customers' internet-facing systems had been exposed for more than 90 days. Its scanner confirmed each with a working attack request, so these are known, reachable flaws left to age.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives60
- Confidence55
DC's Department of Health Care Finance says two public summary reports exposed underlying records on 399,086 people. The data sat behind pages built to show enrollment counts and was reachable from 2023 until July 2026, when the agency found and pulled the reports.
Perspective Coverage
3 publishers
- Builder
- Builder 15%
- Operator
- Operator 78%
- Investor
- Investor 7%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence70
Kai Wegner has ruled out paying, which leaves a seven-day clock running on 5.79 terabytes the group says it holds. Two Berlin department networks were already offline for days, and the city still cannot say what was in the files.
Perspective Coverage
4 publishers
- Builder
- Builder 19%
- Operator
- Operator 70%
- Investor
- Investor 11%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+28
- Incentives60
- Confidence62
The UK Civil Service says standards and assurance did not produce compliance across roughly 465 separate public bodies, so the centre is building services instead and reserving hard authority for systemic risks.
Reality
- Evidence45
- Adoption55
- Hype gap+12
- Incentives65
- Confidence50
ENISA counted 8,257 EU incidents in 2025 and found that denial of service against public-facing services supplies most of the volume, while its warning about compromised technology suppliers rests on one named Swedish case.
Reality
- Evidence60
- Adoption55
- Hype gap+25
- Incentives55
- Confidence58
CISA has published the after-action report for an incident its own tooling missed. A researcher who continuously scans public code repositories spotted admin and build credentials and told a reporter.
Reality
- Evidence64
- Adoption56
- Hype gap+14
- Incentives74
- Confidence62
Comparitech's half-year tally shows government ransomware growing again, with the newest crew on the board, The Gentlemen, out-filing Qilin and spreading its targeting well beyond the United States.
Publishers:comparitech.com
Reality
- Evidence50
- Adoption60
- Hype gap+20
- Incentives62
- Confidence55
France's DGFiP confirmed tax and property data exposure for 678,000 filers while GitLab fixed an unauthenticated project-deletion bug. Both arrived with figures a team can act on.
Reality
- Evidence48
- Adoption42
- Hype gap+12
- Incentives44
- Confidence52
An archive of payment receipts going back to 2008 at Latvia's CSDD exposed 1.2 million people and 200,000 businesses, and cost the agency's supervisory board its jobs.
Reality
- Evidence58
- Adoption66
- Hype gap+8
- Incentives74
- Confidence60