preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

digital-privacy apple email gdpr privacy-engineering data-minimization europe icloud

Apple Said Its Email Privacy Feature Was Fixed. Twice. Researchers Broke It Again Two Weeks Later

Apple’s Hide My Email, the iCloud+ feature that generates disposable aliases so a real address never has to be shared, leaked the real address behind an alias through mail server logs whenever a message to that alias bounced. Researchers reported it in mid-2025, Apple declared it fixed in March and again in June, and both times the flaw still worked. A patch shipped on July 3, and AppleInsider reproduced the same leak again on July 17. It is a clean case study in why a vendor’s fixed claim is not the same thing as a fix, and why any system that touches personal data needs its own logging and error-handling paths checked for exactly this kind of leak.

ransomware digital-security third-party-risk supply-chain europe nis2 manufacturing incident-response

A Swiss Train Maker Just Showed Every European Manufacturer How to Handle a Supplier Ransom Demand: Refuse, Disclose, and Prove Your Own Systems Held

Stadler Rail confirmed that the Everest ransomware group breached a data-exchange platform it shared with a supplier, using stolen login credentials rather than any flaw in Stadler’s own network, and stole technical documents belonging to that supplier. Everest demanded roughly CHF 10 million, about $12.3 million, and Stadler refused to pay, stating its internal IT, production lines, and trains in service worldwide were unaffected. The case is a clean illustration of why NIS2’s third-party risk provisions target the connections between critical infrastructure operators and their suppliers, not just the operators themselves.

devops digital-security vulnerability cve open-source self-hosted automation europe sovereignty

The Second Bypass in Eight Months: n8n's Expression Sandbox Has Now Failed Twice, and Self-Hosting It for Data Sovereignty Means You Own Every Patch Window

n8n, the open-source workflow automation platform many European teams self-host specifically to keep data out of US-owned SaaS platforms, patched CVE-2026-25049, a critical expression sandbox escape with a CVSS score as high as 9.9 that lets an authenticated user with workflow-edit rights run arbitrary system commands on the host. It is a bypass of the fix for a nearly identical flaw, CVE-2025-68613, patched only in December. Fixed versions are 1.123.17 and 2.5.2, and the fact that this is a repeat bypass matters more than the single patch.

security microsoft identity vulnerability cve ransomware active-directory europe patch-management enterprise

Today Is the Deadline CISA Set for a Flaw in the Service That Runs Your Single Sign-On, and It Is Already Part of a Ransomware Chain

CISA’s remediation deadline for CVE-2026-56155, an actively exploited privilege escalation flaw in Microsoft Active Directory Federation Services, falls today. AD FS underpins federated single sign-on for a large share of hybrid-identity European enterprises, and researchers have described this flaw paired with a remote code execution bug as forming a ransomware delivery chain: compromise one networked host, pivot to the AD FS server, escalate to administrator, and forge authentication tokens for the entire federated estate. Microsoft patched it on July 14, giving affected organisations two weeks.

nis2 digital-security compliance gdpr europe regulation incident-response

Four EU States Are Now Being Sued Over NIS2. Your Compliance Deadline Has Not Moved

The European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the EU on 8 July for failing to fully transpose the NIS2 Directive into national law, nearly two years after the October 2024 deadline. The referral triggers daily financial penalties against those governments, but it does nothing to relax the obligations already sitting on the roughly 1,500 essential and important entities the directive covers. If your national transposition law has not landed yet, that is not a reason to wait, it is a reason to build to the directive itself.

azure cloud digital-security compliance europe sovereignty ai infrastructure

Microsoft's Multibillion-Dollar Mistral Deal Gives European Enterprises a Second Azure Option

Microsoft has agreed to spend billions of dollars renting AI computing capacity from Mistral’s European data centres, announced 21 July, in a deal that lets Azure customers run workloads on French-based infrastructure and adds Mistral’s Medium 3.5 and OCR 4 models to Azure AI Foundry. Mistral is separately committing 4 billion euros to its own European buildout. For regulated industries that have spent two years asking whether Azure can ever be a sovereignty-compatible choice, this is the closest either company has come to a direct answer.

dora digital-security compliance resilience third-party-risk europe incident-response gdpr

The EU's First DORA Incident Report Just Told 22,000 Financial Firms Where to Actually Spend Their Resilience Budget

The European Supervisory Authorities’ first annual overview of major ICT incidents under DORA, drawn from 3,383 incidents reported across the EU financial sector in 2025, found that cybersecurity attacks caused only 10 percent of them. System failures and third-party providers were behind far more, with close to a third of major incidents traced back to an ICT supplier, another financial entity, or infrastructure the firm did not directly control. Supervisors have signalled enforcement against reporting failures begins in the current supervisory cycle, and the data itself is now a roadmap for where that scrutiny will land first.

digital-security devops linux ubuntu vulnerability-management patch-management developer-tools europe

A Security Hardening Change Gone Wrong Lets Any Local User Become Root on Default Ubuntu Installs

CVE-2026-8933, a CVSS 7.8 local privilege escalation flaw in Ubuntu’s snap-confine, lets an unprivileged local user exploit a race condition during sandbox setup to gain full root access on default installations of Ubuntu Desktop 24.04, 25.10 and 26.04. The flaw exists precisely because Canonical hardened snap-confine last year, replacing a set-uid-root binary with a set-capabilities model, and the transition introduced the very race condition it was meant to close.

digital-security digital-privacy data-breach third-party-risk gdpr supply-chain healthcare europe

An Edinburgh Software Vendor Got Breached. The Blast Radius Reached 2,000 US Hospitals

Craneware, an Edinburgh-headquartered billing and financial performance software provider whose Trisus Chargemaster platform underpins pricing and billing for more than 2,000 US hospitals and close to 10,000 clinics and pharmacies, confirmed on 20 July that attackers accessed and exfiltrated a subset of its data environment, including employee, customer and partner records. The company has notified the UK’s Information Commissioner’s Office and the FBI, a reminder that a single European vendor’s security posture can carry risk for an entire sector on another continent.

devops digital-security gitlab supply-chain ci-cd developer-tools vulnerability-management europe

GitLab Quietly Fixed a Remote Code Execution Chain in June and Called It a Bug Fix. A Working Exploit Landed This Week

Security researcher Yuhang Wu of depthfirst published working exploit code on 24 July for a GitLab remote code execution chain that GitLab patched six weeks earlier, on 10 June, without ever flagging it as a security fix. Any authenticated user who can push to a self-managed GitLab instance running an unpatched version can commit two crafted Jupyter notebooks and end up running commands as the git user, no admin rights or CI access required.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!