These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
CVE-2026-63077, a maximum-severity unauthenticated remote code execution flaw in JetBrains TeamCity On-Premises, is under active exploitation and reached CISA’s Known Exploited Vulnerabilities catalog on 5 August with a remediation deadline of 8 August, one of the shortest windows CISA has set all year. A flaw in TeamCity’s agent polling protocol lets an attacker with no credentials at all run operating system commands with the privileges of the build server itself, exposing every credential and every pipeline it touches. Any European engineering team running TeamCity On-Premises, and JetBrains counts a large share of them among its customers, needs to know whether today’s deadline already passed them by.
Tencent Zhuque Lab disclosed SCTPhantom, CVE-2026-64564, a use-after-free bug in the Linux kernel’s SCTP networking code that dates back to changes made in 2007 and lets a local attacker escalate to root and escape a container to compromise the underlying host. Researchers confirmed working root exploits against kernel builds used by Debian 13, Ubuntu 24.04, Rocky Linux 9, and RHEL 9, the same distributions running much of Europe’s containerised cloud infrastructure. Fixed kernels shipped 3 August, and any organisation running multi-tenant containers on affected distributions should be checking their patch status now, not after the next audit.
Palo Alto Networks’ Unit 42 disclosed three attacks, collectively named Pass-ta-key, that let ordinary malware running on a Windows machine sign into a victim’s passkey-protected accounts through Google Password Manager, with no fingerprint, PIN or on-screen prompt required. The most severe variant, Golden Pass-ta-key, extracts the master key that encrypts every passkey synced to a Google account, meaning a single infected device can compromise every service the user protected with a passkey. For organisations that adopted passkeys as their answer to phishing and to NIS2 or PSD2 strong authentication requirements, this is a reminder that the device itself is still the weak link.
CISA added CVE-2026-9198, a critical unauthenticated remote code execution flaw in IBM’s Langflow, to its Known Exploited Vulnerabilities catalog after confirming active attacks. Two API endpoints, one that mints administrator tokens for any caller and one that executes arbitrary Python, chain together to give an attacker full control of a default installation. IBM patched it on 17 July, but public proof-of-concept exploits are already circulating, and Langflow is exactly the kind of low-code AI tool European teams have been standing up on internal servers without putting through a formal security review.
The Dutch Cyberbeveiligingswet, the Netherlands’ transposition of the EU NIS2 Directive, enters into force on 15 August 2026 with no grace period. More than 8,000 organisations in critical and important sectors must register with the National Cyber Security Centre, implement risk-based security measures and ensure board-level oversight of cybersecurity from that date, while the European Commission has separately referred Ireland, Spain, France and the Netherlands’ fellow laggards to the Court of Justice of the EU for missing NIS2 transposition entirely. For any organisation with Dutch operations that has treated NIS2 as a 2025 problem already handled, this is the week to check that assumption.
Attackers compromised the maintainer account behind keyv and its sibling caching packages, tools with a combined 2 billion monthly installs, and used it to push a credential-stealing worm across at least 444 packages on August 4. The payload hunts for npm tokens, GitHub CLI tokens, AWS and Vault credentials, and Kubernetes configs, then republishes itself through any maintainer account it steals along the way, and it plants a trap that fires the moment a defender tries to rotate the stolen tokens. If your CI pipeline installed a Node dependency this week, you likely have exposure whether or not your own code touched keyv directly.
A newly documented campaign is running automated authentication bypass attempts against cPanel and WHM servers using CVE-2026-41940, a flaw cPanel patched in April after roughly two months of undetected zero-day exploitation, and researchers have now traced nine chained CVEs to 107 successful breaches including 16 root-level cPanel takeovers. The vulnerability carries a CVSS score of 9.8, requires no valid credentials, and hit an estimated 1.5 million servers before the patch landed, a huge share of which run on hosting providers and MSPs serving European small and mid-sized businesses that never manage their own patching.
Hackers accessed Liechtenstein’s register of beneficial owners on the night of 29 to 30 July, copying data on roughly 31,000 companies, foundations and trusts before authorities detected the intrusion and took the system offline. The register exists because EU anti-money laundering directives required member states to centralise exactly this kind of ownership data, and that same centralisation is what made it a single high-value target. Similar registers run across every EU and EEA state, and this incident is a preview of what a breach looks like when it lands on one of them.
CISA added CVE-2026-34486 to its Known Exploited Vulnerabilities catalog on August 4, confirming active exploitation of a regression that Apache introduced while patching a different Tomcat flaw in April. The April fix for a padding oracle bug in EncryptInterceptor, the component that is supposed to encrypt traffic between Tomcat cluster nodes, left a path that bypasses encryption entirely on 9.0.116. Teams that patched in April believing they had closed the issue may be running cluster traffic in the clear.
Payload ransomware claimed Hans & Jos. Kronenberg GmbH, a Bergisch Gladbach manufacturer of door locks, switches and control panels for the elevator industry, on August 3, saying it exfiltrated 54GB of internal data with a publication deadline of six to seven days. Kronenberg’s own customers are elevator installers and building operators who never evaluated the company as a supplier, they inherited the risk through a component in someone else’s equipment, which is exactly the kind of indirect exposure NIS2’s supply chain provisions were written to address.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.