These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
The Dutch Cyberbeveiligingswet, the Netherlands’ transposition of the EU NIS2 Directive, enters into force on 15 August 2026 with no grace period. More than 8,000 organisations in critical and important sectors must register with the National Cyber Security Centre, implement risk-based security measures and ensure board-level oversight of cybersecurity from that date, while the European Commission has separately referred Ireland, Spain, France and the Netherlands’ fellow laggards to the Court of Justice of the EU for missing NIS2 transposition entirely. For any organisation with Dutch operations that has treated NIS2 as a 2025 problem already handled, this is the week to check that assumption.
Attackers compromised the maintainer account behind keyv and its sibling caching packages, tools with a combined 2 billion monthly installs, and used it to push a credential-stealing worm across at least 444 packages on August 4. The payload hunts for npm tokens, GitHub CLI tokens, AWS and Vault credentials, and Kubernetes configs, then republishes itself through any maintainer account it steals along the way, and it plants a trap that fires the moment a defender tries to rotate the stolen tokens. If your CI pipeline installed a Node dependency this week, you likely have exposure whether or not your own code touched keyv directly.
A newly documented campaign is running automated authentication bypass attempts against cPanel and WHM servers using CVE-2026-41940, a flaw cPanel patched in April after roughly two months of undetected zero-day exploitation, and researchers have now traced nine chained CVEs to 107 successful breaches including 16 root-level cPanel takeovers. The vulnerability carries a CVSS score of 9.8, requires no valid credentials, and hit an estimated 1.5 million servers before the patch landed, a huge share of which run on hosting providers and MSPs serving European small and mid-sized businesses that never manage their own patching.
Hackers accessed Liechtenstein’s register of beneficial owners on the night of 29 to 30 July, copying data on roughly 31,000 companies, foundations and trusts before authorities detected the intrusion and took the system offline. The register exists because EU anti-money laundering directives required member states to centralise exactly this kind of ownership data, and that same centralisation is what made it a single high-value target. Similar registers run across every EU and EEA state, and this incident is a preview of what a breach looks like when it lands on one of them.
CISA added CVE-2026-34486 to its Known Exploited Vulnerabilities catalog on August 4, confirming active exploitation of a regression that Apache introduced while patching a different Tomcat flaw in April. The April fix for a padding oracle bug in EncryptInterceptor, the component that is supposed to encrypt traffic between Tomcat cluster nodes, left a path that bypasses encryption entirely on 9.0.116. Teams that patched in April believing they had closed the issue may be running cluster traffic in the clear.
Payload ransomware claimed Hans & Jos. Kronenberg GmbH, a Bergisch Gladbach manufacturer of door locks, switches and control panels for the elevator industry, on August 3, saying it exfiltrated 54GB of internal data with a publication deadline of six to seven days. Kronenberg’s own customers are elevator installers and building operators who never evaluated the company as a supplier, they inherited the risk through a component in someone else’s equipment, which is exactly the kind of indirect exposure NIS2’s supply chain provisions were written to address.
INC Ransomware has become the dominant actor exploiting last month’s SonicWall SMA 1000 zero-days, and researchers say the group is not just breaking in, it is systematically harvesting credentials, active sessions and TOTP seeds before moving on. That means patching the appliance closes the original hole but does nothing about accounts and multi-factor tokens that were already copied while it was open, a distinction that matters for every organisation that treated this as a routine patch-and-move-on advisory.
CVE-2026-20316 is a static credential baked into the web interface of Cisco Secure Firewall Management Center, letting an unauthenticated attacker log in with a built-in low-privileged account and pull sensitive data straight off the appliance. Cisco confirmed active exploitation in July, shipped hotfixes for FMC 7.0 through 10.0, and CISA gave federal agencies until August 1 to patch. That deadline has already passed, and the low-privilege foothold this flaw hands out is the kind attackers chain with other FMC bugs to take full control of the console that manages an organisation’s entire firewall estate.
From August 3, Google began using IP addresses collected from EEA, UK and Swiss users to identify devices for ad measurement and personalisation, registering the practice under IAB Europe’s Transparency and Consent Framework as Feature 3. IP addresses are personal data under GDPR and UK data protection law, so the new use requires valid consent, but Google has placed that compliance burden squarely on publishers and advertisers rather than handling it centrally. Any consent management platform not explicitly updated to capture Feature 3 consent is now excluding its users from this targeting by default, and any site relying on an unreviewed banner may be processing personal data without the legal basis it assumes it has.
The extortion group coinbasecartel claims to have breached CEN and CENELEC, the Brussels-based bodies that write the technical standards underpinning safety and interoperability across engineering, manufacturing and energy sectors throughout the EU and EEA. Neither organisation has confirmed the claim publicly, no ransom figure or data volume has been disclosed, and the group is known for data theft and leak-site pressure rather than encryption. Confirmed or not, the target itself is the story: standards bodies sit upstream of thousands of manufacturers who reference their documents, and a breach there tests supply chain assumptions that European industry rarely has cause to question.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.