These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
Apple’s Hide My Email, the iCloud+ feature that generates disposable aliases so a real address never has to be shared, leaked the real address behind an alias through mail server logs whenever a message to that alias bounced. Researchers reported it in mid-2025, Apple declared it fixed in March and again in June, and both times the flaw still worked. A patch shipped on July 3, and AppleInsider reproduced the same leak again on July 17. It is a clean case study in why a vendor’s fixed claim is not the same thing as a fix, and why any system that touches personal data needs its own logging and error-handling paths checked for exactly this kind of leak.
Stadler Rail confirmed that the Everest ransomware group breached a data-exchange platform it shared with a supplier, using stolen login credentials rather than any flaw in Stadler’s own network, and stole technical documents belonging to that supplier. Everest demanded roughly CHF 10 million, about $12.3 million, and Stadler refused to pay, stating its internal IT, production lines, and trains in service worldwide were unaffected. The case is a clean illustration of why NIS2’s third-party risk provisions target the connections between critical infrastructure operators and their suppliers, not just the operators themselves.
n8n, the open-source workflow automation platform many European teams self-host specifically to keep data out of US-owned SaaS platforms, patched CVE-2026-25049, a critical expression sandbox escape with a CVSS score as high as 9.9 that lets an authenticated user with workflow-edit rights run arbitrary system commands on the host. It is a bypass of the fix for a nearly identical flaw, CVE-2025-68613, patched only in December. Fixed versions are 1.123.17 and 2.5.2, and the fact that this is a repeat bypass matters more than the single patch.
CISA’s remediation deadline for CVE-2026-56155, an actively exploited privilege escalation flaw in Microsoft Active Directory Federation Services, falls today. AD FS underpins federated single sign-on for a large share of hybrid-identity European enterprises, and researchers have described this flaw paired with a remote code execution bug as forming a ransomware delivery chain: compromise one networked host, pivot to the AD FS server, escalate to administrator, and forge authentication tokens for the entire federated estate. Microsoft patched it on July 14, giving affected organisations two weeks.
The European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the EU on 8 July for failing to fully transpose the NIS2 Directive into national law, nearly two years after the October 2024 deadline. The referral triggers daily financial penalties against those governments, but it does nothing to relax the obligations already sitting on the roughly 1,500 essential and important entities the directive covers. If your national transposition law has not landed yet, that is not a reason to wait, it is a reason to build to the directive itself.
Microsoft has agreed to spend billions of dollars renting AI computing capacity from Mistral’s European data centres, announced 21 July, in a deal that lets Azure customers run workloads on French-based infrastructure and adds Mistral’s Medium 3.5 and OCR 4 models to Azure AI Foundry. Mistral is separately committing 4 billion euros to its own European buildout. For regulated industries that have spent two years asking whether Azure can ever be a sovereignty-compatible choice, this is the closest either company has come to a direct answer.
The European Supervisory Authorities’ first annual overview of major ICT incidents under DORA, drawn from 3,383 incidents reported across the EU financial sector in 2025, found that cybersecurity attacks caused only 10 percent of them. System failures and third-party providers were behind far more, with close to a third of major incidents traced back to an ICT supplier, another financial entity, or infrastructure the firm did not directly control. Supervisors have signalled enforcement against reporting failures begins in the current supervisory cycle, and the data itself is now a roadmap for where that scrutiny will land first.
CVE-2026-8933, a CVSS 7.8 local privilege escalation flaw in Ubuntu’s snap-confine, lets an unprivileged local user exploit a race condition during sandbox setup to gain full root access on default installations of Ubuntu Desktop 24.04, 25.10 and 26.04. The flaw exists precisely because Canonical hardened snap-confine last year, replacing a set-uid-root binary with a set-capabilities model, and the transition introduced the very race condition it was meant to close.
Craneware, an Edinburgh-headquartered billing and financial performance software provider whose Trisus Chargemaster platform underpins pricing and billing for more than 2,000 US hospitals and close to 10,000 clinics and pharmacies, confirmed on 20 July that attackers accessed and exfiltrated a subset of its data environment, including employee, customer and partner records. The company has notified the UK’s Information Commissioner’s Office and the FBI, a reminder that a single European vendor’s security posture can carry risk for an entire sector on another continent.
Security researcher Yuhang Wu of depthfirst published working exploit code on 24 July for a GitLab remote code execution chain that GitLab patched six weeks earlier, on 10 June, without ever flagging it as a security fix. Any authenticated user who can push to a self-managed GitLab instance running an unpatched version can commit two crafted Jupyter notebooks and end up running commands as the git user, no admin rights or CI access required.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.