These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
Securonix is tracking an active campaign it calls SMOKE#SCREEN that lures victims with convincing fake update pages for Zoom, Adobe products and business document viewers, then installs ConnectWise ScreenConnect, a legitimate, digitally signed remote monitoring and management tool, as a persistent backdoor. Because the payload is genuine commercial software rather than custom malware, it frequently passes signature-based defences and blends into the traffic patterns IT teams already expect. The campaign has expanded beyond Windows to a fake macOS installer, and its use of legitimate RMM software as the final payload puts it in the same category of attack that has repeatedly hit European MSPs and their downstream clients this year.
Manifold Security found 77 ’evil twin’ extensions uploaded to the Open VSX marketplace between 26 July and 1 August 2026, each impersonating a real publisher, including AMD, Azure, Salesforce OSS and even the marketplace’s own namespace. Nineteen of them went beyond basic fingerprinting to exfiltrate Git repository names, branch details and CI system identifiers to a shared external domain. Open VSX removed the packages by 3 August, five months after the Eclipse Foundation, which maintains the registry, announced mandatory pre-publish security checks in response to the GlassWorm worm attack. The checks did not stop this campaign, and anyone who installed one of the 77 extensions still has it on disk until they remove it manually.
The European Commission’s November 2025 Digital Omnibus proposal included Article 88b, a mechanism that would have let browsers transmit a single machine-readable consent signal to every website a user visits, replacing the per-site cookie banner entirely. In its position paper of 18 June 2026, the Council removed Article 88b from the text after Germany, France and Poland pushed for its deletion, reportedly following lobbying against the change. Article 88a, which does survive and moves cookie rules from the ePrivacy Directive into the GDPR itself, narrows the consent-free exemptions and mandates a single-click reject button, but legal analysis from firms including Osborne Clarke concludes banner fatigue is not going away. The European Parliament has not yet taken its own position, so the final shape of the rules is still open.
CVE-2026-70426, rated critical with a CVSS score of 9.8, lets an attacker who can execute code on a Jenkins build agent bypass the JEP-200 deserialization filter and run arbitrary code on the controller itself, the single most trusted machine in a CI/CD pipeline. Jenkins disclosed the flaw and shipped fixed Remoting versions on 5 August 2026, affecting Jenkins 2.575 and earlier and LTS 2.568.1 and earlier. Jenkins remains the most widely deployed CI/CD platform in European engineering organisations, and a compromised controller means every credential, every signing key, and every downstream deployment it touches is in scope.
CVE-2026-17059 let any Keycloak admin account that could view a role also see the personal data of every user assigned to it, including names, email addresses and account status, regardless of whether that admin’s permissions were meant to stop there. Escape’s research team reported the broken object-level authorisation flaw on 18 July 2026, Red Hat published the CVE on 24 July, and Keycloak shipped the fix in version 26.7.0 on 28 July, a single line adding the per-user visibility check the endpoint had always been missing. Keycloak underpins identity and access management across a large share of European public-sector and enterprise deployments, and this is precisely the kind of access-control gap GDPR’s security-of-processing obligations expect organisations to catch before a researcher does.
Security researchers at Novee presented findings at Black Hat USA showing that Anthropic’s Claude Code, Google’s Gemini CLI, and OpenAI’s Codex could all be driven to remote code execution on their vendors’ own CI runners by a single GitHub issue filed by an account with no repository access at all. The bugs, now fixed, lived not in the AI models but in the surrounding harness, the permissions, sandboxing, and tool-execution code every team relies on when it wires an AI coding agent into GitHub Actions. Any European team running these agents in their default configuration was exposed to the same class of attack against its own pipeline secrets.
CVE-2026-63077, a maximum-severity unauthenticated remote code execution flaw in JetBrains TeamCity On-Premises, is under active exploitation and reached CISA’s Known Exploited Vulnerabilities catalog on 5 August with a remediation deadline of 8 August, one of the shortest windows CISA has set all year. A flaw in TeamCity’s agent polling protocol lets an attacker with no credentials at all run operating system commands with the privileges of the build server itself, exposing every credential and every pipeline it touches. Any European engineering team running TeamCity On-Premises, and JetBrains counts a large share of them among its customers, needs to know whether today’s deadline already passed them by.
Tencent Zhuque Lab disclosed SCTPhantom, CVE-2026-64564, a use-after-free bug in the Linux kernel’s SCTP networking code that dates back to changes made in 2007 and lets a local attacker escalate to root and escape a container to compromise the underlying host. Researchers confirmed working root exploits against kernel builds used by Debian 13, Ubuntu 24.04, Rocky Linux 9, and RHEL 9, the same distributions running much of Europe’s containerised cloud infrastructure. Fixed kernels shipped 3 August, and any organisation running multi-tenant containers on affected distributions should be checking their patch status now, not after the next audit.
Palo Alto Networks’ Unit 42 disclosed three attacks, collectively named Pass-ta-key, that let ordinary malware running on a Windows machine sign into a victim’s passkey-protected accounts through Google Password Manager, with no fingerprint, PIN or on-screen prompt required. The most severe variant, Golden Pass-ta-key, extracts the master key that encrypts every passkey synced to a Google account, meaning a single infected device can compromise every service the user protected with a passkey. For organisations that adopted passkeys as their answer to phishing and to NIS2 or PSD2 strong authentication requirements, this is a reminder that the device itself is still the weak link.
CISA added CVE-2026-9198, a critical unauthenticated remote code execution flaw in IBM’s Langflow, to its Known Exploited Vulnerabilities catalog after confirming active attacks. Two API endpoints, one that mints administrator tokens for any caller and one that executes arbitrary Python, chain together to give an attacker full control of a default installation. IBM patched it on 17 July, but public proof-of-concept exploits are already circulating, and Langflow is exactly the kind of low-code AI tool European teams have been standing up on internal servers without putting through a formal security review.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.