These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
A supply chain attack disclosed this week compromised five npm packages in the AsyncAPI generator namespace without the attacker ever stealing an npm token. Instead, a misconfigured pull_request_target workflow let attacker-controlled code run inside AsyncAPI’s own CI pipeline, which then published trojanized packages carrying a Miasma RAT descendant with legitimate OIDC provenance attached.
Check Point’s Cloud Firewall and Rubrik Security Cloud have both launched on the AWS European Sovereign Cloud, the physically and logically separate AWS infrastructure operated entirely by EU residents from its first region in Brandenburg, Germany. For banks, utilities, healthcare providers, and public sector bodies weighing data residency against hyperscaler capability, the two launches close a real gap: familiar security and resilience tooling that stays inside the sovereignty boundary.
The EU Digital Omnibus package proposes a single entry point where organisations report a cyber incident once and the system routes it to every relevant authority, replacing today’s separate GDPR, NIS2, DORA, eIDAS, and CER notification processes on different timelines and templates. A new Article 23a NIS2 would establish the mechanism, GDPR’s breach deadline would move to 96 hours, and the whole regime would apply 18 to 24 months after the legislation enters into force.
CISA has added CVE-2026-46817, a CVSS 9.8 privilege management flaw in Oracle E-Business Suite’s Payments File Transmission component, to its Known Exploited Vulnerabilities catalogue after confirming active attacks. No authentication is required, exploitation happens over plain HTTP, and successful attacks give outsiders control of Oracle Payments and the financial workflows behind it. European organisations running EBS for finance or ERP should treat this as an active incident, not a routine patch.
AWS has made Security Hub’s Microsoft Azure monitoring generally available, letting it discover Azure virtual machines, container images, function apps, and identities, then evaluate them for misconfigurations, internet exposure, and vulnerabilities alongside AWS findings in a single console. For European organisations running workloads across both clouds, a genuine reason to standardise on one security operations view instead of stitching together two vendor consoles has just appeared.
CVE-2026-43499, nicknamed GhostLock, is a use-after-free bug in the Linux kernel’s futex and real-time mutex code that has shipped by default in almost every mainstream distribution since 2011. A newly published exploit gives any local user full root access with roughly 97 percent reliability, and the same flaw lets a compromised container break out to the host. Every organisation running Linux servers or containers needs to check patch status now, not on the next maintenance window.
The European Commission has preliminarily found that Instagram and Facebook breach the Digital Services Act through addictive design features including infinite scroll, autoplay, push notifications, and personalised recommender systems. Meta faces a fine of up to 6 percent of its global turnover, and any platform built on similar engagement mechanics should treat this as a signal to review its own design choices before a regulator does it for them.
SonicWall has confirmed active, chained exploitation of two zero-day vulnerabilities in its SMA 1000 series remote access appliances since 22 June, a maximum-severity unauthenticated SSRF combined with a post-authentication command injection flaw. US federal agencies face a binding 17 July deadline to patch or disconnect affected devices, and any organisation using SMA 1000 for remote access should treat this as an active incident, not a routine patch.
Scality and OVHcloud have expanded their partnership into a joint sovereign storage platform combining GPU-direct object storage with OVHcloud’s on-premises and bare metal infrastructure. Aimed at healthcare, financial services, defense, and public sector organisations, it addresses GDPR, DORA, and NIS2 compliance by keeping AI training data and MLOps pipelines entirely within EU-controlled environments.
Germany’s Data Protection Conference has adopted a ten-point position paper pushing to shift privacy-by-design obligations onto the manufacturers and providers of standard IT products, following the model already set by the Cyber Resilience Act and AI Act. If it gains traction at EU level, the compliance burden currently carried entirely by the businesses deploying software could start shifting further upstream, to the vendors who build it.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.