preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

ci-cd devops security supply-chain github github-actions infrastructure

'Cordyceps' CI/CD Flaw: Any GitHub Account Can Hijack Pipelines at Microsoft, Google, and Apache

Security researchers at Novee Security have disclosed a systemic class of CI/CD vulnerabilities codenamed Cordyceps that allows any unauthenticated user with a free GitHub account to hijack workflows, steal credentials, and poison software supply chains. More than 300 high-impact repositories have been confirmed fully exploitable, including those belonging to Microsoft Azure Sentinel and Python’s Black formatter, which serves 130 million installs per month. AI coding agents are accelerating the spread by reproducing the same insecure patterns at scale.

cisco security cve ssrf enterprise infrastructure vulnerability patching

Cisco Unified Communications Manager Under Active Attack: CVE-2026-20230 Webshell Campaign Begins Three Weeks After Patch

Three weeks after Cisco released patches for CVE-2026-20230, a critical server-side request forgery vulnerability in Unified Communications Manager, automated exploitation campaigns are dropping webshells on unpatched systems via Tor exit nodes. The attack chain requires no authentication and ends with a persistent command-execution shell on the underlying operating system. Any organisation running Cisco UCM without the June 3 patch applied is currently exposed.

github devops security cve rce supply-chain ci-cd infrastructure

CVE-2026-3854: One Git Push Gives Attackers Full Control of GitHub Enterprise Server, 88% of Instances Still Unpatched

A critical command injection vulnerability in GitHub Enterprise Server allows any authenticated user to execute arbitrary code on backend infrastructure with nothing more than a single git push. Discovered by Wiz Research in March 2026 and patched on GitHub.com the same day, the self-hosted Enterprise Server fix was released in April – yet nearly nine in ten instances remain unpatched two months after public disclosure, leaving private repositories and internal secrets exposed.

gdpr privacy security compliance europe data-breach phishing nis2

GDPR Fines Surpass €7.1 Billion as ICO Penalises Water Utility for a Phishing Breach That Went Undetected for 20 Months

Cumulative GDPR enforcement since 2018 has crossed €7.1 billion, with European data protection authorities now processing 443 breach notifications per day – a 22 percent year-on-year increase. The UK Information Commissioner’s Office recently fined South Staffordshire Water £963,900 after a 2020 phishing attack was left undetected for nearly two years, allowing attackers to exfiltrate 4.1 terabytes of data on 633,887 customers and employees, which was subsequently published on the dark web.

oauth supply-chain salesforce crm saas-security security cloud europe

Dormant OAuth Token Gave Icarus Hackers Access to Salesforce CRM Data Across Dozens of Organisations

A supply chain attack against market intelligence platform Klue allowed the Icarus threat group to steal customer OAuth tokens and tunnel directly into connected Salesforce and Gong environments. The initial foothold came from a single dormant credential left over from an abandoned prototype integration. Affected organisations include Huntress, Recorded Future, and Tanium, with CRM data including sales communications, pricing, and competitive intelligence exfiltrated and used for extortion.

email deliverability dmarc dkim spf compliance email-security europe

Gmail, Yahoo, and Microsoft Are Now Hard-Rejecting Non-Compliant Bulk Mail: What European Senders Must Fix

Google, Yahoo, and Microsoft have all moved from filtering to permanent rejection of bulk email that fails SPF, DKIM, and DMARC authentication. Microsoft returns a 550 5.7.515 error that sends non-compliant messages to the void, not the spam folder. For European organisations sending transactional email, marketing campaigns, or automated notifications, this means misconfigured DNS records are now causing silent delivery failures rather than inbox noise.

nginx security devops cve rce web-server infrastructure patching

F5 Patches Critical NGINX Vulnerabilities: HTTP/3 Flaw CVE-2026-42530 Enables Unauthenticated Remote Code Execution

F5 has issued out-of-band security patches for two critical vulnerabilities in NGINX Open Source, NGINX Plus, and related products. CVE-2026-42530, rated CVSS 9.2, is a use-after-free flaw in the HTTP/3 QUIC module that allows an unauthenticated remote attacker to achieve code execution or denial of service. Any NGINX deployment with HTTP/3 enabled is exposed and should patch or mitigate immediately.

hetzner cloud infrastructure devops cost-optimisation europe

Hetzner's June 2026 Price Shock: CPX and CCX Instances Rise by Up to 176 Percent

Hetzner raised cloud prices for CPX and CCX instance families by up to 176 percent on 15 June 2026, the fourth pricing action in five months. The root cause is AI-driven DRAM demand pushing memory prices up by roughly 171 percent year on year. For European businesses relying on Hetzner’s RAM-heavy tiers, the cost equation has changed significantly and a cloud strategy review is now overdue.

devsecops devops ci-cd supply-chain vulnerabilities github-actions security dependencies

Datadog DevSecOps 2026: 87 Percent of Organisations Running Known Exploitable Vulnerabilities in Production

Datadog’s State of DevSecOps 2026 report analysed hundreds of thousands of production services and found that 87 percent of organisations are running at least one service with a known, exploitable vulnerability. Dependency lag has grown to a median of 278 days behind the latest major version, and 71 percent of GitHub Actions workflows leave third-party actions completely unpinned, creating a direct and underappreciated supply chain attack surface in CI/CD pipelines.

aws azure eu digital-markets-act cloud sovereignty compliance regulation europe

EU Expected to Issue DMA Gatekeeper Preliminary Findings Against AWS and Azure as Soon as Next Week

The European Commission is set to deliver preliminary findings as early as the week of 22 June 2026, formally designating Amazon Web Services and Microsoft Azure as gatekeepers under the Digital Markets Act. A designation would impose interoperability requirements, data portability obligations, and anti-self-preferencing rules on both platforms, with fines of up to 10 percent of global turnover for non-compliance. European organisations running workloads on either provider face a landscape that is about to change in material ways.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!