Cybersecurity researchers have uncovered vulnerable code embedded in several legacy Python packages, raising concerns about potential supply chain attacks against the Python Package Index (PyPI). The issue stems from a domain takeover risk linked to outdated bootstrap scripts used by the build automation tool zc.buildout. According to ReversingLabs, these scripts still reference a long-abandoned domain, python-distribute[.]org, which is now available for purchase.
The Monetary Authority of Singapore (MAS) has released new AI Risk Management Guidelines, placing responsibility on bank board members and senior management to oversee risks arising from AI deployment.
The Bank of England has fined UK payments operator Vocalink £11.9 million for failing to meet a February 2022 deadline to address weaknesses in its risk management and governance framework.
Source: Cytora
Cytora has announced the latest version of its digital risk processing platform. Cytora Platform 3.0 enhances the capabilities of the platform by harnessing agentic AI in a fully explainable way.
The New York State Department of Financial Services (NYDFS) has released updated cybersecurity guidance outlining how financial services firms should manage risks associated with third-party service providers (TPSPs).
Cryptocurrency may be nearing the point where it poses a systemic risk to the global financial system, according to Klaas Knot, outgoing chair of the Financial Stability Board (FSB). Speaking in Spain, Knot acknowledged that despite previous disruptions in the crypto space—including bankruptcies, liquidity issues, and fraud—the FSB had not considered the sector a systemic threat until now.
Despite increasing efforts to adopt artificial intelligence (AI), many firms remain in the early stages of implementation, hindered by significant gaps in workforce training and regulatory readiness.
CEO confidence in the global economy has hit a five-year low, according to the KPMG 2025 Global CEO Outlook, as corporate leaders focus strategic investments in AI, talent and risk resilience to sustain and fuel future growth.The annual survey of more than 1,300 global leaders reveals a cautious outlook among CEOs, driven by persistent geopolitical tensions and economic uncertainty.
A critical vulnerability, CVE-2025-31324, in SAP’s NetWeaver platform, specifically within the Visual Composer’s Metadata Uploader component, is under active exploitation.
Cybersecurity researchers have uncovered a new threat to software supply chains that spans multiple programming ecosystems, including PyPI, npm, Ruby Gems, NuGet, Dart Pub, and Rust Crates. These entry points, which are typically used by developers to execute specific commands or load plugins, can be exploited by attackers to introduce malicious code.
Cybersecurity researchers have discovered two severe authentication bypass vulnerabilities in Wondershare RepairIt, an AI-powered data repair and photo editing application.
Source: LexisNexis
LexisNexis Risk Solutions, part of RELX, closed its acquisition of IDVerse, a provider of AI-powered document authentication and fraud detection solutions.
Source: FullCircl
FullCircl, a UK-based RegTech which is uniquely placed at the intersection where revenue meets regulation, has announced a new partnership with LSEG Risk Intelligence.