preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

digital-security cve cisco email-security cisa-kev kev patch-management vulnerability-management europe

One Crafted Email Gets Root on Your Cisco Mail Gateway. The Patch Deadline Is Tomorrow.

CVE-2026-76461 is a CVSS 9.8 flaw in Cisco Secure Email Gateway’s email-parsing engine that lets an attacker execute commands as root simply by sending a specially crafted message through the appliance, no credentials or clicks required. Cisco disclosed and patched it on September 14 after confirming active exploitation, and CISA’s federal remediation deadline is September 17, tomorrow.

digital-security wordpress web-development cve patch-management cms plugin-security europe small-business

A Single Event Comment Can Now Take Over a WordPress Site Running The Events Calendar

Wordfence disclosed CVE-2026-78006 on September 12, a CVSS 9.8 unauthenticated PHP object injection flaw in The Events Calendar, a WordPress plugin with over 600,000 active installs. An attacker who posts a crafted comment on any event page, no login required, can trigger arbitrary code execution before comment moderation even runs. StellarWP shipped the fix in version 6.17.4.1 on September 10, alongside a second, unrelated unauthenticated RCE (CVSS 8.1) in the same release. Proof-of-concept exploit code is already public.

digital-security iot cve botnet mirai ddos vulnerability-management network-security europe small-business

There Is No Patch for This DVR Bug, and Mirai Botnets Are Already Using It

CVE-2026-87827, a maximum-severity CVSS 10.0 flaw in KGUARD DVR firmware dated 2016 and earlier, exposes an unauthenticated system command execution service on every network interface, letting a remote attacker fully compromise the device with no credentials at all. The Mirai_ptea (Rimasuta) and Mirai_aurora botnet variants are already exploiting it in the wild to recruit devices for malware propagation and DDoS. KGUARD’s fix, present in firmware from 2017 onward, only restricts the service to localhost; there is no update for the affected legacy models, which remain sold and in service across small offices and retail sites.

digital-security devops cve msp remote-monitoring connectwise screenconnect cisa-kev vulnerability-management patch-management europe

A ScreenConnect Session Guest Could Run Files on Your Machine Without Asking, and Today Is the Patch Deadline

ConnectWise disclosed CVE-2026-84869, a CVSS 9.9 flaw that let the guest side of an active ScreenConnect remote support or access session transfer and execute files on the host machine without the host’s confirmation, including elevated actions. ConnectWise shipped ScreenConnect 26.6.5 on September 8, CISA confirmed active exploitation and added the flaw to its Known Exploited Vulnerabilities catalog on September 11, and set September 14, today, as the deadline for US federal agencies to remediate. ScreenConnect is one of the most widely deployed remote support tools among European MSPs and IT teams.

digital-security digital-privacy email-deliverability fintech data-breach gdpr social-engineering compliance europe uk

Revolut Handed Over Passports and Bitcoin Histories Because an Email Came From the Right Domain

Revolut confirmed a data breach after an unauthorized party used an email account inside a real government agency’s domain to submit fraudulent requests for customer information. Because the messages carried valid domain authentication, Revolut treated them as genuine and disclosed KYC documents, identity-verification selfies, account statements and Bitcoin-related transaction histories for a limited, apparently high-net-worth, set of customers. Revolut says systems and funds were unaffected and has notified law enforcement and regulators, but the incident is a case study in a specific failure mode: trusting the sender’s domain instead of verifying the request itself.

digital-security devops microsoft windows windows-defender cve vulnerability-management patch-management zero-day europe

Microsoft's Patch for Its Own Antivirus Flaw Has Now Failed Twice

Two hours after Microsoft shipped its September 2026 Patch Tuesday, the researcher behind two earlier Windows Defender zero-days published a third proof of concept, ShieldCrash, that reads SYSTEM-level files on fully patched Windows 10, Windows 11 and Windows Server machines. Microsoft’s own patch for CVE-2026-69414, the ShieldBreak flaw it fixed only after bypass research forced its hand in August, is the fix ShieldCrash is reported to get around, and there is still no confirmed timeline for closing the gap.

digital-security devops mikrotik routeros networking self-hosted cve cisa-kev vulnerability-management patch-management europe

Your MikroTik Router Can Be Hijacked With No Password, and CERT Polska Says It Is Already Happening

Poland’s national CSIRT coordinated disclosure of a two-step attack chain, dubbed MikroTrick, that lets an attacker take full control of a MikroTik RouterOS device over SSH without ever supplying a valid password. CVE-2026-67276, an SSH public-key check that never validates the exponent, combines with CVE-2026-86060 to hand over root. MikroTik shipped fixes on September 3, CISA added the flaws to its Known Exploited Vulnerabilities catalog on September 10 with a September 13 deadline for US federal agencies, and CERT Polska says exploitation from internet-facing devices was already underway from at least September 2.

digital-security devops cve gitlab cicd cisa-kev vulnerability-management patch-management europe supply-chain

GitLab's Perfect-10 Bug Lets a Stranger Read Any File on Your Server, No Login Required

CVE-2026-85706, a maximum-severity path traversal flaw in GitLab’s repository commits API, went from patch to in-the-wild exploitation attempts in a single day. GitLab fixed it on September 10, CISA added it to its Known Exploited Vulnerabilities catalog on September 11 with a September 14 federal deadline, and researchers estimate more than 20,000 self-managed GitLab instances worldwide are still exposed.

email-deliverability dmarc bimi email compliance devops europe

Your Brand Logo Is Not Showing Up in Inboxes, and the Certificate You Bought Is Not the Problem

New research published today by email testing firm MailGenius finds that BIMI projects, the standard that puts a verified brand logo next to authenticated email, almost always stall on DMARC enforcement rather than on the certificate itself. A Certificate Transparency snapshot of over 20,000 BIMI certificates shows adoption growing fast, but the unglamorous work of getting every sending system to authenticate under a single enforced policy is what most teams underestimate.

devops github ci-cd linux supply-chain developer-tools infrastructure europe

A Quiet Key Expiry Just Started Breaking gh Installs Across Linux CI Pipelines

The PGP key signing GitHub CLI’s Linux APT and RPM packages expired on September 5, 2026. Any pipeline, base image, or server that installs or updates gh from those repositories without trusting the replacement key now fails with a signature verification error, often in the least convenient place: a CI job that has run unchanged for years.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!