preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

devops digital-security ci-cd supply-chain vulnerability-management patch-management cve self-hosted europe

Your CI/CD Pipeline Is Only as Secure as Artifactory's Front Door, and It Was Just Left Open

JFrog patched CVE-2026-82329, a 9.8-severity authentication bypass in default Artifactory configurations, on August 28. Days later watchTowr confirmed active exploitation: attackers minting themselves administrator tokens with no credentials at all, on self-hosted instances that sit at the centre of the software supply chain.

digital-security devops data-breach gdpr api-security secrets-management aviation europe uk

8.7 Million Records Leaked Because an API Key Sat in the Frontend Code

Manchester Airports Group confirmed on August 27 that extortion group FulcrumSec accessed customer data across Manchester, London Stansted and East Midlands airports by lifting Iterable API credentials that were sitting in plain sight inside client-side JavaScript. FulcrumSec claims 86GB of exfiltrated data covering roughly 8.7 million customers, making it the largest known breach of a British airport operator, and the entry point required no exploit at all, just a browser’s developer tools.

digital-security devops patch-management vulnerability-management papercut print-management europe education government

PaperCut's First Patch Didn't Hold. Here's What That Means for Your Patch Tuesday

PaperCut shipped a second emergency patch on August 28, one day after its first fix, when watchTowr researchers found multiple ways to bypass it. The underlying chain, CVE-2026-81578 (8.8) and CVE-2026-82078 (9.4), lets an unauthenticated attacker reach PaperCut NG/MF’s web management interface and achieve remote code execution, and Huntress had already spotted active exploitation starting August 26, before any patch existed.

digital-security devops cisa-kev patch-management vulnerability-management legacy-systems linux sql-server europe nis2

CISA Just Confirmed Active Exploitation of a Bug From 2015. Yes, 2015.

CISA’s August 26 batch of six additions to its Known Exploited Vulnerabilities catalogue includes two Red Hat flaws from 2015, a SQL Server bug from 2019, and an Ajax.NET Professional deserialization issue from 2021, alongside the freshly disclosed Citrix NetScaler CVE-2026-8452. Federal agencies had until August 29 to patch the SQL Server and NetScaler bugs, and until September 9 for the rest. The batch is a reminder that attackers don’t need a zero-day when a decade-old unpatched system is still sitting on the network.

digital-security shinyhunters phishing social-engineering vishing microsoft365 data-breach gdpr europe

One Phone Call Got a French IP Giant's Sales Data Onto a Leak Site

Questel SAS, a French intellectual property management firm that handles patent and trademark portfolios for corporations and law firms, confirmed on August 13 that ShinyHunters accessed part of its Microsoft 365 environment through a single voice phishing call. The attacker talked their way into a Sales SharePoint site, not a technical exploit, and the extortion group has since added two more companies, Alcon and Lumenis, to the same leak site with the same tactic.

digital-security devops citrix netscaler cve vpn remote-access cisa-kev patch-management europe

Citrix Called This NetScaler Bug a Denial-of-Service Issue. Attackers Are Using It to Get Root.

CVE-2026-8452, a memory overflow in NetScaler ADC and Gateway appliances running VPN or AAA virtual servers, was patched as a denial-of-service fix but has now been confirmed as an unauthenticated path to remote code execution as root. CISA added it to its Known Exploited Vulnerabilities catalogue on August 26 with a federal remediation deadline of August 29, and defenders have already found webshells planted on compromised appliances. More than 22,000 NetScaler ADC instances and nearly 1,800 Gateway instances remain internet-exposed with unknown patch status.

devops digital-security gitea git self-hosted cve cisa-kev supply-chain patch-management europe

Gitea's Self-Registration Feature Just Became an Attacker's Front Door

CVE-2026-60004 lets anyone who can create an account on a Gitea instance execute arbitrary shell commands as the Gitea service account, by submitting a malicious patch through the diffpatch API endpoint. Because Gitea ships with self-registration enabled by default, an attacker needs no prior credentials at all, just the ability to sign up. CISA has confirmed active exploitation, including a cryptocurrency-miner-style payload, and Shadowserver counts more than 8,300 internet-facing Gitea instances still unpatched against the fix in version 1.27.1.

digital-security apt28 espionage phishing europe government malware email-deliverability social-engineering

Russia's Fancy Bear Group Built a Backdoor That Hides Inside a Free Developer Tool

Researchers have disclosed HOOKEDGE, a previously undocumented Windows backdoor attributed with moderate confidence to the Russian state-sponsored group APT28, used in a diplomatic-themed phishing campaign against government and diplomatic organisations in Romania, Spain and Turkiye between September 2025 and April 2026. Delivered through macro-enabled Word documents, HOOKEDGE routes its command-and-control and data exfiltration through webhook.site, a legitimate free service developers use for testing webhooks, letting malicious traffic blend into ordinary web activity that most security tools have no reason to block.

digital-security ransomware europe government public-sector incident-response rhysida

A Ransomware Gang Just Put Berlin's Government Data Up for Auction, Weeks Before an Election

The Rhysida ransomware group claims to have stolen 5.79 terabytes of Berlin state agency data, including 46,500 contracts, emails, phone numbers and passwords, and is auctioning it starting at 30 bitcoin after the city refused to pay. The attack lands less than a month before Berlin’s September 20 election, and it is the latest in a long run of Rhysida attacks on European government and public-sector targets.

digital-security devops self-hosted europe cisa-kev vulnerability-management webdav

A Three-Year-Old ownCloud Bug Just Got Used to Steal Nuclear Research Files

CISA has added CVE-2023-49105, a critical WebDAV authentication bypass in the German-built ownCloud file-sync platform, to its Known Exploited Vulnerabilities catalog after attackers used it to exfiltrate files from a nuclear research body. The flaw has been public and patchable since early 2024, and CISA’s deadline for federal remediation is August 30, 2026, tomorrow. Any organisation self-hosting ownCloud for the data sovereignty it offers needs to confirm it is not still running an unpatched core.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!