preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

compliance eu cyber-resilience-act digital-security regulation europe vulnerability-management devops enisa

The EU Cyber Resilience Act's Reporting Clock Started Today. Most Manufacturers Are Not Ready

From 11 September 2026, manufacturers of any product with digital elements sold in the EU must report actively exploited vulnerabilities within 24 hours through ENISA’s new Single Reporting Platform, which itself only went live today. The obligation and the tool to comply with it launched on the same date, leaving little runway for the testing and dry runs most compliance teams would normally insist on.

digital-security cve vulnerability firewall network cisa-kev malware vulnerability-management europe patch-management

30,000 FortiGate Firewalls Scanned for a Bug Patched Eight Months Ago

Attackers are exploiting CVE-2025-25249, a heap-based buffer overflow in FortiOS and FortiSwitchManager, to plant a custom remote access tool called PivotC2 on internet-exposed FortiGate appliances. Fortinet patched the flaw in January 2026, but researchers have logged scanning against roughly 30,000 IP addresses and confirmed 178 compromised sessions, and CISA only added it to its Known Exploited Vulnerabilities catalog on September 9.

digital-security cve vulnerability firewall network cisa-kev vulnerability-management europe patch-management

A Boot-Time Bug in Cisco's Firewall Manager Gives Attackers Root, No Password Needed

CVE-2026-20079, a CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center, lets an unauthenticated attacker ride a leftover session from system startup into root access on the box that manages an organisation’s firewalls. Cisco has confirmed active exploitation linked to state-sponsored groups and ransomware operators, and CISA added it to its Known Exploited Vulnerabilities catalog on September 9 with a September 12 deadline for US federal agencies.

digital-security cve browser chrome chromium cisa-kev europe patch-management

Google Patched Its Second Chrome Zero-Day in Under a Week

CVE-2026-87491, an out-of-bounds write in Chrome’s V8 engine, was already being exploited in the wild when Google fixed it in Chrome 153.0.8010.36/.37 on September 8, five days after patching a separate actively exploited V8 flaw, CVE-2026-85046. It is the seventh Chrome zero-day of 2026, and CISA added it to its Known Exploited Vulnerabilities catalog on September 9.

digital-security devops microsoft windows patch-management vulnerability-management cve zero-day europe sharepoint

Microsoft Just Shipped Its Largest Patch Tuesday Ever. Two of the 973 Fixes Cannot Wait

Microsoft’s September 2026 Patch Tuesday fixes 973 vulnerabilities, the largest release on record, including two Windows privilege escalation flaws already being exploited in the wild. Neither zero-day gives an attacker remote entry on its own, but combined with almost any foothold they hand over full SYSTEM control, and a list this size means most patch teams cannot triage the rest of the queue this week.

digital-privacy gdpr compliance ai netherlands europe data-protection

Uber Got Fined 825 Million Euros Because No Human Reviewed What the Algorithm Decided

The Dutch data protection authority fined Uber almost 825 million euros for letting a fully automated system suspend and permanently deactivate driver accounts between 2018 and 2022, with no meaningful human review and no clear disclosure to the drivers affected. It is the second-largest GDPR fine ever issued, and the underlying failure, automated decisions without a real human check, is one many European companies deploying AI and fraud-detection tooling still have not fixed.

digital-security e-commerce magento adobe-commerce cve vulnerability-management patch-management europe

A Fully Patched Magento Store Got Backdoored Anyway. Here Is Why

StyleSmuggler (CVE-2026-75650, CVSS 10.0) is an unauthenticated remote code execution flaw hitting every current version of Magento and Adobe Commerce, exploited in the wild since September 4 before Adobe’s emergency hotfix landed on September 7. The first confirmed victim was fully patched against every prior advisory, which means patch history alone no longer proves a European storefront is safe.

digital-security devops cve msp remote-monitoring n-able vulnerability-management patch-management europe

The Remote Monitoring Tool Your IT Provider Trusts Just Had Its Third Zero-Day in Six Weeks

N-able shipped an emergency hotfix on September 5 for CVE-2026-86218, a maximum-severity pre-authentication remote code execution flaw in N-central that was already being exploited before the patch existed. It is the third zero-day disclosed against the platform in six weeks, and N-central sits at the center of how thousands of managed service providers, including many across Europe, monitor and control their clients’ infrastructure.

digital-security cve browser chrome chromium cisa-kev europe patch-management

Google's Sixth Chrome Zero-Day of 2026 Is Already Being Used in Attacks

CVE-2026-85046, a type confusion flaw in Chrome’s V8 JavaScript engine, lets an attacker execute code inside the browser sandbox from a single crafted web page. Google confirmed active exploitation, shipped Chrome 152.0.7977.82 on September 3, and CISA added the bug to its Known Exploited Vulnerabilities catalog the next day with a September 18 remediation deadline for federal systems.

devops cloud azure reliability incident-response ai europe

One Azure Region Failed and Took Three of the World's AI Chatbots With It

A routing failure in Microsoft Azure’s East US infrastructure on September 3 knocked ChatGPT, Claude and Grok offline within the same 90-minute window, since all three lean on Azure compute in that region. Google’s Gemini, running on entirely separate infrastructure, stayed up throughout. Full recovery took nearly five hours, and the incident is a clean case study in what shared cloud dependency actually costs when it fails.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!