preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

security digital-security europe ransomware gdpr compliance supply-chain finance

Deutsche Bank Lands on a Ransomware Leak Site Because a German Marketing Vendor Got Breached

The Unsafe ransomware group listed Deutsche Bank on its dark web leak site, publishing what it claims are employee database extracts, password hashes, and physical addresses. Deutsche Bank says its own network was never touched, the actual point of entry was a third-party company running a marketing and incentive platform for its sales partners. The distinction matters legally, but it matters far less to the employees whose data is now circulating, and it is precisely the scenario the EU’s DORA regulation was written to prevent.

devops security digital-security cve ci-cd supply-chain europe patch-management

JetBrains Patches a 9.6-Severity IntelliJ Flaw and Two TeamCity Bugs the Same Week: Patch Your Dev Tooling, Not Just Your Servers

JetBrains disclosed three vulnerabilities on July 10, a critical 9.6-severity code execution flaw in IntelliJ IDEA triggered through project workspace handling, plus an arbitrary file access bug and a stored XSS flaw in TeamCity’s Perforce integration and cloud profile page. None of these live on a server you patch during a maintenance window, they live on developer laptops and CI infrastructure, which is exactly the class of asset most patch programmes still overlook.

security digital-security devops supply-chain europe incident-response enterprise-software

Progress Tells Every ShareFile Storage Zone Controller Customer to Shut Down Now, Cause Undisclosed

Progress Software emailed ShareFile customers on July 10 instructing them to immediately power down their on-premises Storage Zone Controller servers over what it called a credible external security threat, then disabled cloud access to those accounts as a precaution. The company has not said whether a new zero-day is involved, only months after two chainable flaws in the same product allowed unauthenticated remote code execution. Any organisation running Storage Zone Controller, in Europe or anywhere else, needs to treat this as urgent until Progress says otherwise.

security digital-security devops azure cloud supply-chain europe enterprise secrets-management

Accenture Confirms Breach After Hacker Lists 35GB of Its Azure DevOps Source Code and Cloud Keys for Sale

A threat actor known as 888 claims to have exfiltrated 35GB of data from an Accenture Azure DevOps repository, including source code, RSA and SSH keys, Azure personal access tokens, and storage account keys. Accenture confirmed the incident on July 7 and says it has remediated the source, but has not detailed the exfiltration scope. With Accenture running technology delivery for a huge share of Europe’s largest enterprises, the incident is a reminder that the credentials sitting inside your repositories are often worth more to an attacker than the code itself.

privacy digital-security security europe gdpr compliance regulation messaging

EU 'Chat Control' Message-Scanning Law Passes Even Though More MEPs Voted Against It

The European Parliament voted 314 to 276 against extending the EU’s voluntary chat-scanning regime on July 9, yet the measure passed anyway because second-reading rules require an absolute majority of all 720 MEPs to block it, not just a majority of those voting. Parliament simultaneously adopted an amendment exempting end-to-end encrypted services, but that carve-out now needs Council sign-off by roughly October 9 to become binding. For any business handling EU user communications, the compliance and platform-choice questions just got more urgent, not less.

devops security digital-security supply-chain npm aws fintech europe ci-cd

Fake Paysafe, Skrill, and Neteller SDKs Flooded npm and PyPI in a Single Coordinated Attack

Socket discovered 17 malicious npm and PyPI packages published simultaneously on July 7, impersonating SDKs for UK-headquartered payment brands Paysafe, Skrill, and Neteller. The packages return convincing fake success responses while quietly exfiltrating API keys, AWS credentials, GitHub tokens, and npm tokens to attacker infrastructure hosted on AWS. Any developer integrating payment SDKs from public registries without verifying the publisher just got a very concrete reason to check.

azure cloud devops finops cost-optimisation databricks ai europe

Azure Databricks Started Billing Genie Per User This Week, and Broad Rollouts Are About to Feel It

As of July 8, 2026, Azure Databricks bills Genie usage beyond a 150 DBU per-user monthly allowance on a pay-as-you-go basis. Teams that enabled Genie for wide user access without setting usage controls will start seeing per-user LLM charges accumulate immediately, and service principals get no free allowance at all. It is a small pricing change on paper that can produce a real line item for organisations that treated Genie as a flat-cost feature rather than a metered one.

security devops ai-agents cve patch-management europe supply-chain

CISA's Exploited Vulnerabilities List Gets Its First AI Agent Platform, With a Two-Day Patch Window

CISA added four actively exploited flaws to its Known Exploited Vulnerabilities catalog this week, including CVE-2026-55255 in Langflow, the first AI agent orchestration platform ever to appear on the list. Alongside a maximum-severity Adobe ColdFusion path traversal bug and two Joomla page builder flaws, federal agencies have been told to patch by July 10. Organisations running AI agent tooling in production should treat this as the moment that category of software officially became a routine attack target.

devops security supply-chain npm ci-cd developer-tools open-source europe

npm v12 Stops Running Install Scripts by Default This Month, Closing a Door Attackers Used All Year

npm v12 ships this month with the most significant security redesign in the package manager’s 16-year history: install scripts, Git dependencies, and remote tarball sources will no longer run automatically. The change is a direct response to a year of supply chain attacks that used postinstall hooks to steal credentials from developer machines and CI/CD pipelines. Teams that have not acted on the warnings already present in npm 11.16.0 will find builds failing silently the moment v12 lands.

security devops vulnerability rmm msp supply-chain oidc europe

A Single Forged Token Turns SimpleHelp Into a Backdoor Across Every Client an MSP Manages

CVE-2026-48558, a maximum-severity CVSS 10.0 authentication bypass in SimpleHelp’s remote support software, lets an unauthenticated attacker forge an OIDC token and create a fully privileged technician account. CISA added it to its Known Exploited Vulnerabilities catalog with a 2 July 2026 remediation deadline, and attackers are already using it to install Djinn Stealer and TaskWeaver malware. Because SimpleHelp sits inside the MSP supply chain, one compromised instance can cascade into every managed client behind it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!