top of page

2025-09-20 - Three cybersecurity stories you should not have missed this week

1) Aviation check-ins disrupted across Europe (shared platforms = shared outages)


A cyber incident impacting Collins Aerospace’s MUSE check-in platform triggered delays and cancellations at Heathrow, Brussels, Berlin and more—forcing manual workarounds and exposing aviation’s dependency on third-party SaaS. Confirmed reports and live updates below.


Sources:


Do now: Inventory mission-critical third-party platforms, run a 24-hour “SaaS-down” tabletop, and validate manual throughput assumptions.


2) Jaguar Land Rover: prolonged factory shutdown (the long tail of a breach)


Production disruptions at JLR continued this week, with deepening supply-chain impact and mounting costs—an object lesson in how quickly “IT incidents” become business outages. Roundups below.


Sources:


Do now: Re-verify RTO/RPO with MSPs and key suppliers; pre-stage financial/ops contingencies for multi-week outages; ensure comms cadence to distributors.


3) Chrome ships another in-the-wild zero-day fix (patch velocity is strategy)

Google patched CVE-2025-10585, the sixth actively exploited Chrome zero-day this year—again targeting the V8 engine. If you’re letting browsers lag, you’re volunteering to be the low-hanging fruit.


Sources:


Do now: Enforce auto-update; set “current minus 1” compliance; block outdated Chromium builds from SSO; verify version drift in device compliance.

Comments


CONTACT ME

Thanks for submitting!

  • Black LinkedIn Icon
  • Black Facebook Icon
  • AdobeStock_626841028_Editorial_Use_Only
  • Bluesky_logo_(black)
  • Threads
  • Black Instagram Icon

© 2000-2026 By Alan Wallace

bottom of page