preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

security windows microsoft zero-day vulnerability devops endpoint

RoguePlanet Zero-Day: Windows Defender Race Condition Grants SYSTEM Access on Fully Patched Machines

A security researcher known as Nightmare Eclipse published a new Windows Defender zero-day exploit named RoguePlanet just hours after Microsoft’s June 2026 Patch Tuesday, granting SYSTEM-level privileges on fully patched Windows 10 and 11. The disclosure is the third in three consecutive months and arrives without a patch available, leaving all Windows environments with Microsoft Defender enabled currently exposed.

security devops splunk cve enterprise vulnerability monitoring

Splunk CVE-2026-20253: CVSS 9.8 Unauthenticated Arbitrary File Write Demands Immediate Patching

Splunk has released emergency patches for CVE-2026-20253, a critical vulnerability in Splunk Enterprise rated CVSS 9.8, that allows any network-reachable attacker to create or truncate arbitrary files without authentication through an exposed PostgreSQL sidecar service endpoint. Internet-facing Splunk deployments are at immediate risk of full system compromise, and the fix requires upgrading to versions 10.4.0, 10.2.4, or 10.0.7 or later.

security devops ai mcp supply-chain ci-cd developer-tools

Agentjacking: How a Fake Sentry Error Report Can Hijack Your AI Coding Agent

Tenet Security’s Threat Labs have published research demonstrating a novel attack class called Agentjacking, in which attackers inject malicious instructions into Sentry error event payloads to trick AI coding agents into executing attacker-controlled code on developer machines. Tested against Claude Code, Cursor, and other top coding agents, the technique achieved an 85 percent exploitation success rate and bypassed EDR, WAF, IAM controls, and firewalls entirely because every step of the attack chain uses authorised actions.

ai compliance eu gdpr regulation europe enterprise risk

Seven Weeks to EU AI Act Compliance: What High-Risk AI Systems Must Deliver by 2 August

The remaining provisions of the EU Artificial Intelligence Act take effect on 2 August 2026, requiring high-risk AI systems under Annex III to be conformity-assessed, registered in the EU database, and operational with risk management, data governance, logging, and human oversight controls in place. The penalty structure exceeds the GDPR’s, reaching up to 35 million euros or 7 percent of global annual turnover. This deadline arrives as Europe marks the GDPR’s tenth anniversary, a reminder of how enforcement frameworks evolve from aspirational to operational.

security oracle vulnerability cve zero-day enterprise education data-breach

ShinyHunters Exploited Oracle PeopleSoft as a Zero-Day for Two Weeks Before Oracle Issued an Advisory

CVE-2026-35273, a CVSS 9.8 unauthenticated remote code execution vulnerability in Oracle PeopleSoft PeopleTools, was actively exploited in the wild between May 27 and June 9, two weeks before Oracle published its out-of-band security advisory on June 10. Mandiant and Google Threat Intelligence Group have attributed the campaign to ShinyHunters (UNC6240), who breached more than 100 organisations, the majority of them universities and higher education institutions.

security europol ransomware cryptocurrency law-enforcement europe cybercrime

Europol and FBI Dismantle AudiA6, the Crypto Laundering Pipeline Behind 336 Million Euros in Ransomware Proceeds

On 10 June 2026, a joint operation led by Europol and the US Department of Justice dismantled AudiA6, a cryptocurrency laundering service that had processed over 336 million euros in illicit funds since 2021. Two administrators were arrested in Georgia, 25 domains and more than 30 servers were seized, and the takedown severed a primary financial channel used by ransomware groups to convert extortion payments into clean funds. The operators also ran Dark2Web, a dark web forum connecting cybercriminals across Europe and beyond.

hetzner cloud devops infrastructure pricing europe cost-optimisation

Hetzner Raises Prices Again on 15 June: What European DevOps Teams Should Do Now

Hetzner is implementing its third round of price increases this year on 15 June 2026, affecting new orders for dedicated servers and cloud plans across all its locations. With component costs for RAM, SSDs, and GPUs remaining volatile, the increases follow earlier adjustments in April that pushed cloud prices up by 30 to 37 percent in Germany and Finland. The change will not affect existing contracts, but any team planning infrastructure expansion or new deployments needs to factor it in now.

security europe enisa nis2 critical-infrastructure transport compliance incident-response

ENISA's Cyber Europe 2026 Exercise Tests EU's Ability to Defend Rail and Maritime Infrastructure

On 10 and 11 June 2026, ENISA ran the 8th edition of the Cyber Europe exercise, simulating escalating cyberattacks against the EU’s interconnected rail and maritime transport networks. For the first time, the EU Cybersecurity Reserve was activated as part of the scenario, testing the cross-border incident response mechanisms that the EU is building ahead of tighter NIS2 enforcement across transport sector operators.

security france government data-breach digital-privacy europe identity

France's Sovereign Messenger Tchap Breached via Hijacked Government Account

France’s government messaging platform Tchap, built on Matrix to keep civil servant communications off foreign infrastructure, was compromised on 7 June 2026 through a hijacked account in its education environment. An attacker claims to have obtained over 73,000 user accounts, 643,000 messages, and files marked with a French restricted-distribution classification, though the full extent of the breach is still under investigation.

security sap netweaver vulnerability cve enterprise patch europe

SAP's June 2026 Patch Day Fixes Four Critical Flaws Including a 9.9-Severity SAML Bypass in NetWeaver

SAP’s June 2026 Security Patch Day addressed 15 vulnerabilities, four of them rated critical. The most severe, CVE-2026-44748 with a CVSS score of 9.9, allows an authenticated attacker to bypass SAML authentication in SAP NetWeaver AS ABAP by manipulating XML signatures. A second critical flaw, CVE-2026-27671 with CVSS 9.8, allows unauthenticated remote code execution via a memory corruption bug in the ABAP kernel.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!