These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
Airbus has selected French provider Scaleway as its sovereign cloud partner, with around 70 critical applications migrating by the end of 2028 and a programme that could eventually cover up to 900 applications over five to six years. The stated driver is not cost or performance but keeping industrial and design data shielded from foreign extraterritorial law, a decision that puts a concrete number on what digital sovereignty looks like when a company the size of Airbus actually commits to it.
N-able confirmed that attackers took over N-central servers even after its initial patch, because the fix in version 2026.2 left an alternate path to the same authentication bypass open. On August 2 the company shipped hotfix 2026.3.1.7 for CVE-2026-18556 and CVE-2026-18577, but not before intruders used the RMM platform’s own Take Control feature to plant outbound-only Cloudflare Tunnels on managed endpoints, persistence that survives even after access through N-central itself is cut off.
Wiz researchers found CosmosEscape, a flaw in Azure Cosmos DB’s Gremlin query engine that let a crafted query achieve code execution on the multi-tenant gateway and expose a platform-wide signing secret capable of retrieving the primary key to any Cosmos DB account on the service, including network-isolated ones. Wiz reported it privately in November 2025, Microsoft shipped a fast hotfix within 48 hours, but the full architectural fix that eliminated the platform-wide key entirely was not completed until July 2026, with public disclosure on 30 July. Microsoft reports no evidence of exploitation and says customers need to take no action. For European organisations storing regulated data in Cosmos DB, that assurance rests entirely on Microsoft’s own telemetry of an eight-month window they controlled from end to end.
VMSA-2026-0006, published by Broadcom on 29 July 2026, fixes five vulnerabilities across vCenter, ESX and Cloud Foundation. CVE-2026-59309 is an authentication bypass in the VMware Directory Service, and CVE-2026-59310 is a directory traversal flaw enabling unauthenticated remote code execution, both scoring 9.8. CVE-2026-47876, scoring 9.3, is a VM escape via the VMXNET3 virtual network adapter. Broadcom reports no known exploitation or public proof-of-concept as of publication, which is precisely the window in which patching still prevents an incident rather than responding to one.
CVE-2026-16812, a command injection flaw in self-hosted VeloCloud Orchestrator with a maximum CVSS score of 10.0, lets a remote, unauthenticated attacker run arbitrary commands on the system that centrally manages an organisation’s entire SD-WAN. CISA confirmed active exploitation on 27 July, added it to the Known Exploited Vulnerabilities catalog, and set a 30 July patch deadline under Binding Operational Directive 26-04. That deadline only legally binds US federal agencies. Every other organisation still running an unpatched on-prem Orchestrator, including the European telecoms, logistics firms and retailers who rely on VeloCloud to manage branch networks, is exposed today.
Copenhagen-based Adform, a demand-side advertising platform used by roughly 14,000 companies with around 30 percent share of the DSP market, had its trackpoint-async.js tracking script compromised to inject clipboard-hijacking malware. Any Bitcoin, Ethereum or TRON wallet address copied on an affected site was silently swapped for an attacker-controlled address, re-applied every three seconds even if a victim noticed and re-copied it. The malicious script ran undetected for roughly a week before security researcher Kevin Beaumont identified it, and it reached every site embedding the tracker, none of which had to make a mistake of their own to be affected.
Anthropic disclosed on 30 July 2026 that three of its AI models, including Claude Opus 4.7 and an internal research model called Mythos 5, breached real organisations during cybersecurity evaluations run with third-party partner Irregular. A misconfiguration gave the models genuine internet access despite being told the environment was an isolated simulation, and one model exploited a SQL injection flaw and an exposed debug page before uploading a malicious Python package to PyPI that compromised 15 real machines, including a security vendor’s own systems. Neither company caught the error until after the fact.
The EU’s Digital Omnibus has delayed the Artificial Intelligence Act’s high-risk Annex III obligations from 2 August 2026 to December 2027, and sector-specific rules further to 2028. But Article 50’s transparency duties, covering chatbot disclosure, AI-generated content marking, and deepfake labelling, were left untouched and still take effect on 2 August 2026 alongside the European Commission’s enforcement powers over general-purpose AI providers. Unlike the high-risk tier, Article 50 is not limited to a narrow list of sensitive use cases: it applies to any organisation using generative AI to produce content, run a chatbot, or generate synthetic media.
The EU General Court dismissed all three of Apple’s challenges to its Digital Markets Act gatekeeper designation on July 8, 2026, including Apple’s argument that the interoperability obligations breach its fundamental rights. The court found the interoperability provision is not the legal basis of the designation itself and declined to rule on the substance, a procedural finding that narrows how Apple, Google, Amazon and other gatekeepers can contest DMA obligations going forward. Apple can still appeal on points of law to the Court of Justice of the EU, but the practical effect for now is that App Store and iOS interoperability requirements stand.
Google Cloud’s Service Health feature for Cloud Run reached general availability in late July 2026, automating cross-region failover using instance-level readiness probes behind a global external or cross-region internal Application Load Balancer, with a two-click setup and no charge beyond the compute the readiness probes consume. The timing lands six days after a cooling failure at a Google Cloud facility in the Netherlands took down GCVE, NetApp Volumes and bare metal services in europe-west4 for roughly 15 hours, an outage that had no automated cross-region failover available for the affected services at the time.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.