preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

devops aws cloud security automation ai-agents europe

AWS Wants to Fix Your Vulnerabilities Before Your Team Finishes Triaging Them

AWS Continuum, unveiled at the AWS Summit in New York and now in gated preview, is a security service that discovers, prioritises, validates, and remediates code vulnerabilities autonomously, starting in a human-in-the-loop learn mode before teams can graduate it to automated enforcement. It leans on the new AWS Context knowledge graph to reason about what is actually exploitable in a given environment. For teams already struggling to keep up with vulnerability backlogs, it is a preview of where cloud security tooling is heading, and a preview of the governance questions that come with it.

security devops vulnerability gitea docker self-hosted supply-chain europe

One Forged HTTP Header Gives Full Admin on Gitea Docker Images, and Scanning Started Within Two Weeks

CVE-2026-20896, a CVSS 9.8 flaw in Gitea’s official Docker images, let anyone who could reach the container’s HTTP port impersonate an administrator with a single X-WEBAUTH-USER header. Gitea patched it in version 1.26.3 on 20 June 2026, but threat actors were already probing for it by early July. This is the second major Gitea vulnerability disclosed in as many months, and it lands squarely on the self-hosted Git servers many European teams run to keep code off US-based platforms.

azure microsoft365 cloud pricing devops europe cost-optimization

Microsoft 365 Prices Rise Again on July 1: What European Businesses Need to Budget For

Microsoft’s July 1 2026 pricing update raises most commercial Microsoft 365 and Office 365 plans by 8 to 17 percent in USD terms, on top of a separate pricing-precision change applied to EEA currency billing. Combined with February’s temporary euro price cut, the net impact on European invoices is uneven and easy to miss.

security digital-security nis2 compliance europe gdpr critical-infrastructure enterprise

NIS2 Enforcement Has Started, and It Looks Exactly Like Early GDPR: Warnings First, Fines Later

With the June 30 audit deadline now behind them, national regulators across the EU are moving on NIS2 enforcement, but not through fines yet. Germany’s BSI issued 47 formal notices in the last quarter, France’s ANSSI sent 23 remediation orders to energy and transport entities, and Italy’s ACN is still chasing thousands of unregistered entities. The pattern mirrors 2018 GDPR enforcement closely enough to predict what comes next.

security ransomware malware backup business-continuity phishing digital-security devops enterprise

Avalon Malware Framework Deliberately Disables Backups Before Deploying CrownX Ransomware

Security researchers have documented Avalon, a modular malware framework delivered through legal-document phishing lures that specifically hunts down and disables Veeam, Acronis, vCenter, Hyper-V and other backup and recovery infrastructure before detonating its CrownX ransomware payload. The framework includes tailored evasion for nine major EDR products and shows signs of AI-assisted development.

azure cloud devops cost-optimisation finops microsoft infrastructure europe

Azure Quietly Retired Reserved VM Instances on Legacy Series: Here Is What Happens If You Do Nothing

As of July 1, 2026, Microsoft no longer allows new purchases or renewals of Azure Reserved VM Instances across a long list of legacy VM series, including Dv2, Ev3 and the entire Av2, Bv1, F and G families. Existing reservations run out their term as normal, but once one expires it cannot be renewed, and the workload quietly reverts to pay-as-you-go pricing that can run up to 72 percent higher.

digital-ocean devops kubernetes cloud security digital-security identity infrastructure

DigitalOcean Kubernetes Finally Drops Static Tokens for Real Single Sign-On

DigitalOcean has moved OpenID Connect single sign-on for its Managed Kubernetes service (DOKS) to general availability, letting clusters authenticate through Okta, Keycloak, Auth0, authentik or JumpCloud instead of long-lived tokens. Each cluster gets its own independent policy, and deactivating a user in the identity provider now revokes cluster access immediately.

devops security github github-actions ci-cd supply-chain digital-security europe

GitHub Finally Lets You Say Who Is Allowed to Trigger a Workflow, After a Year of CI/CD Attacks

GitHub has put workflow execution protections into public preview across Enterprise, organisation, and repository settings, letting administrators define exactly which actors and which events are allowed to trigger a GitHub Actions run. The feature arrives after a string of 2026 incidents, including the Cordyceps pipeline hijack and a critical GitHub Enterprise Server RCE, that all traced back to the same root problem: almost anything could kick off a workflow with write access to your secrets.

ransomware digital-security security europe saas italy supply-chain data-breach

Ransomware Group Bashe Claims Italian Website Builder Flazio, Putting Thousands of Customer Sites at Risk

The Bashe ransomware group has publicly claimed a breach of Flazio, an Italian SaaS website-building platform, threatening to leak stolen data unless it is paid. Because Flazio hosts and manages websites on behalf of thousands of small and medium businesses, a confirmed breach does not stay contained to one vendor. It becomes a downstream incident for every customer whose site, data, and reputation sat on that platform.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!