These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
AWS Continuum, unveiled at the AWS Summit in New York and now in gated preview, is a security service that discovers, prioritises, validates, and remediates code vulnerabilities autonomously, starting in a human-in-the-loop learn mode before teams can graduate it to automated enforcement. It leans on the new AWS Context knowledge graph to reason about what is actually exploitable in a given environment. For teams already struggling to keep up with vulnerability backlogs, it is a preview of where cloud security tooling is heading, and a preview of the governance questions that come with it.
CVE-2026-20896, a CVSS 9.8 flaw in Gitea’s official Docker images, let anyone who could reach the container’s HTTP port impersonate an administrator with a single X-WEBAUTH-USER header. Gitea patched it in version 1.26.3 on 20 June 2026, but threat actors were already probing for it by early July. This is the second major Gitea vulnerability disclosed in as many months, and it lands squarely on the self-hosted Git servers many European teams run to keep code off US-based platforms.
CVE-2026-43503, dubbed DirtyClone, lets any unprivileged local user on a wide range of Linux distributions gain root by exploiting how the kernel clones socket buffer fragments. The exploit bypasses on-disk integrity monitoring entirely, and JFrog’s proof-of-concept is already public.
Microsoft’s July 1 2026 pricing update raises most commercial Microsoft 365 and Office 365 plans by 8 to 17 percent in USD terms, on top of a separate pricing-precision change applied to EEA currency billing. Combined with February’s temporary euro price cut, the net impact on European invoices is uneven and easy to miss.
With the June 30 audit deadline now behind them, national regulators across the EU are moving on NIS2 enforcement, but not through fines yet. Germany’s BSI issued 47 formal notices in the last quarter, France’s ANSSI sent 23 remediation orders to energy and transport entities, and Italy’s ACN is still chasing thousands of unregistered entities. The pattern mirrors 2018 GDPR enforcement closely enough to predict what comes next.
Security researchers have documented Avalon, a modular malware framework delivered through legal-document phishing lures that specifically hunts down and disables Veeam, Acronis, vCenter, Hyper-V and other backup and recovery infrastructure before detonating its CrownX ransomware payload. The framework includes tailored evasion for nine major EDR products and shows signs of AI-assisted development.
As of July 1, 2026, Microsoft no longer allows new purchases or renewals of Azure Reserved VM Instances across a long list of legacy VM series, including Dv2, Ev3 and the entire Av2, Bv1, F and G families. Existing reservations run out their term as normal, but once one expires it cannot be renewed, and the workload quietly reverts to pay-as-you-go pricing that can run up to 72 percent higher.
DigitalOcean has moved OpenID Connect single sign-on for its Managed Kubernetes service (DOKS) to general availability, letting clusters authenticate through Okta, Keycloak, Auth0, authentik or JumpCloud instead of long-lived tokens. Each cluster gets its own independent policy, and deactivating a user in the identity provider now revokes cluster access immediately.
GitHub has put workflow execution protections into public preview across Enterprise, organisation, and repository settings, letting administrators define exactly which actors and which events are allowed to trigger a GitHub Actions run. The feature arrives after a string of 2026 incidents, including the Cordyceps pipeline hijack and a critical GitHub Enterprise Server RCE, that all traced back to the same root problem: almost anything could kick off a workflow with write access to your secrets.
The Bashe ransomware group has publicly claimed a breach of Flazio, an Italian SaaS website-building platform, threatening to leak stolen data unless it is paid. Because Flazio hosts and manages websites on behalf of thousands of small and medium businesses, a confirmed breach does not stay contained to one vendor. It becomes a downstream incident for every customer whose site, data, and reputation sat on that platform.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.