preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

digital-security devops fortinet fortiweb cve vulnerability-management patch-management europe network-security

Your Web Application Firewall Will Log Into Itself for a Stranger If You Have RADIUS Set Up a Specific Way

Fortinet’s 12 August advisory for CVE-2026-26035 describes a maximum-severity flaw in FortiWeb: when an admin account is configured for remote RADIUS authentication with the wildcard option enabled, a non-default but far from rare setup, the appliance will match any username on the RADIUS server against an admin group, letting an unauthenticated remote attacker log into the GUI or CLI with arbitrary credentials. Patched versions are 8.0.3, 7.6.7, 7.4.12 and 7.2.13.

digital-security devops vmware virtualization cve vulnerability-management patch-management on-premises europe germany incident-response

Broadcom Said There Was No Known Exploitation on 29 July. Five Days Later, Attackers Were Inside vCenter Servers in 47 Countries

CVE-2026-59310, a maximum-severity directory traversal flaw in VMware vCenter’s Syslog server patched in VMSA-2026-0006 on 29 July, is now being exploited at scale. Researchers have tracked path traversal activity followed by reverse SSH backdoor deployment across 361 unique vCenter IPs in 47 countries, with Germany, the United States, Turkey, Iran and France the most affected. First contact with attacker infrastructure was recorded on 3 August, five days after Broadcom’s advisory went public and while an unknown share of vCenter estates had not yet applied the fix.

digital-security devops cisco cve cisa-kev vulnerability-management patch-management network-security vpn europe critical-infrastructure

One Crafted HTTP Request Can Now Reboot a Cisco Firewall Mid-VPN Session, and Attackers Are Already Sending It

CVE-2026-20349, an unauthenticated denial-of-service flaw in the Remote Access SSL VPN service on Cisco Secure Firewall ASA and FTD software, was disclosed as already being exploited in the wild when Cisco published its advisory on 11 August 2026. CISA added it to the Known Exploited Vulnerabilities catalog the same day. Any device running IKEv2 Remote Access VPN with client services, SSL VPN or Zero Trust Network Access is affected, and Cisco’s only supported fix is a hotfix or upgraded release, not a configuration workaround.

digital-security devops supply-chain ai ai-agents ci-cd cve cloud europe kubernetes

The Trivy Supply Chain Attack Was Supposed to Be Old News. New Research Just Put a Number on It: 2,500 Organisations, 434,000 CI/CD Pipelines

New analysis published this week by CloudSEK reconstructs the true blast radius of the March 2026 LiteLLM supply chain compromise, which was itself downstream of the TeamPCP attack on the Trivy scanner that also breached the European Commission’s AWS cloud. Two malicious LiteLLM releases, live on PyPI for roughly three hours, are now linked to more than 2,500 affected organisations and 434,000 CI/CD pipeline runs, with an infostealer that harvested AWS, GCP, GitHub and SSH credentials and installed a persistent systemd backdoor. Exposure does not confirm every one of those organisations was breached, but almost five months later the real scope is only now becoming clear.

devops digital-security kubernetes cve vulnerability-management cloud ci-cd patch-management europe open-source

A Low-Privileged Rancher User Could Register Their Own Kubernetes Cluster and Walk Out With Admin Over Every Cluster You Manage

A maximum-impact flaw in Rancher’s impersonation middleware, CVSS 9.1, let any authenticated user with permission to register a downstream cluster trick Rancher into checking authorization against that attacker-controlled cluster while actually executing the request against Rancher’s own privileged management plane. Because registering a downstream cluster is a default, low-privilege capability, the practical bar for full platform takeover was a standard Rancher account and a free k3d cluster on a laptop. Patches are out for all four supported release lines.

devops digital-security microsoft windows cve patch-management zero-day vulnerability-management europe azure

Microsoft Patched 421 Flaws This Week, But the One North Korea Was Already Using for Two Months Is the One That Matters

Microsoft’s August 2026 Patch Tuesday fixes 421 vulnerabilities, including a Windows privilege escalation zero-day that Check Point traces back to Lazarus Group activity starting in early June, weeks before a patch existed. A second publicly disclosed flaw in Windows User Profile Service is expected to see exploitation shortly. With 62 critical bugs and 40 of those remote code execution, most patch teams cannot triage the full list this week, so knowing which two to fix first matters more than the total count.

digital-security third-party-risk supply-chain gdpr data-breach compliance europe incident-response

One Shipping Company Got Breached and Steam, ING and a Football Club Are All Now Writing to Their Customers About It

A cyberattack on logistics giant CEVA between July 29 and August 1 exposed names, addresses, phone numbers and order details of customers belonging to companies that never had a direct breach of their own, including Valve’s Steam hardware store, banking group ING, football club Ajax and eyewear retailer Ace and Tate. Eight European warehouses were disrupted, and every affected brand is now issuing its own GDPR notifications for data it never held the underlying breach of, a textbook case of risk inherited through a shared vendor.

digital-security digital-privacy europe belgium authentication identity-management vulnerability-management supply-chain nis2

A Browser Extension Used by 8 of Belgium's 10 Biggest Banks Would Talk to Any Website That Asked, No Questions

Researcher James Arnott of Bay Area Labs disclosed at DEF CON that Connective, the digital identity extension developed by Nitro Software Belgium and used by over two million people, eight of Belgium’s ten largest banks and 60-plus government agencies, never checked which website was talking to it. Any page or embedded ad could silently read eID and payment card data, and a second flaw allowed drive-by remote code execution without an ID card even present. The vendor took 146 days to ship a full fix, longer than the exposure window many NIS2-regulated institutions would accept from a supplier.

devops digital-security open-source data-breach vulnerability-management patch-management business-intelligence europe self-hosted

A Maximum-Severity Flaw in Your BI Dashboard Just Gave Attackers Admin Access to Every Database It Connects To

Metabase, the open-source business intelligence tool widely self-hosted by European teams for data sovereignty reasons, patched an unauthenticated SQL injection flaw in its password-reset endpoint carrying the maximum CVSS score of 10.0. Attackers exploited it as a zero-day starting around August 3, using it to gain full admin access and pivot into every database connection Metabase held credentials for. Framework and Tally have both confirmed customer data was exposed before the vendor even had a patch out.

digital-security devops europe poland nis2 critical-infrastructure ot-security incident-response energy

Attackers Found a Way Into a Power Plant That No Firewall Rule Was Written to Stop: A Private Mobile Network Nobody Treated as the Internet

CERT Polska’s follow-up report on the December 2025 sabotage of a Polish combined heat and power plant confirms a previously unseen attack path: attackers pivoted from a compromised wind farm VPN device into the region’s private cellular APN, which let any connected device talk to any other, and rode it straight into a second facility’s PLCs. The agency attributes the intrusion to Static Tundra, linked to Russia’s FSB, and is now telling every energy operator using a private APN to stop treating it as trusted infrastructure.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!