These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
CVE-2026-20316 is a static credential baked into the web interface of Cisco Secure Firewall Management Center, letting an unauthenticated attacker log in with a built-in low-privileged account and pull sensitive data straight off the appliance. Cisco confirmed active exploitation in July, shipped hotfixes for FMC 7.0 through 10.0, and CISA gave federal agencies until August 1 to patch. That deadline has already passed, and the low-privilege foothold this flaw hands out is the kind attackers chain with other FMC bugs to take full control of the console that manages an organisation’s entire firewall estate.
From August 3, Google began using IP addresses collected from EEA, UK and Swiss users to identify devices for ad measurement and personalisation, registering the practice under IAB Europe’s Transparency and Consent Framework as Feature 3. IP addresses are personal data under GDPR and UK data protection law, so the new use requires valid consent, but Google has placed that compliance burden squarely on publishers and advertisers rather than handling it centrally. Any consent management platform not explicitly updated to capture Feature 3 consent is now excluding its users from this targeting by default, and any site relying on an unreviewed banner may be processing personal data without the legal basis it assumes it has.
The extortion group coinbasecartel claims to have breached CEN and CENELEC, the Brussels-based bodies that write the technical standards underpinning safety and interoperability across engineering, manufacturing and energy sectors throughout the EU and EEA. Neither organisation has confirmed the claim publicly, no ransom figure or data volume has been disclosed, and the group is known for data theft and leak-site pressure rather than encryption. Confirmed or not, the target itself is the story: standards bodies sit upstream of thousands of manufacturers who reference their documents, and a breach there tests supply chain assumptions that European industry rarely has cause to question.
Airbus has selected French provider Scaleway as its sovereign cloud partner, with around 70 critical applications migrating by the end of 2028 and a programme that could eventually cover up to 900 applications over five to six years. The stated driver is not cost or performance but keeping industrial and design data shielded from foreign extraterritorial law, a decision that puts a concrete number on what digital sovereignty looks like when a company the size of Airbus actually commits to it.
N-able confirmed that attackers took over N-central servers even after its initial patch, because the fix in version 2026.2 left an alternate path to the same authentication bypass open. On August 2 the company shipped hotfix 2026.3.1.7 for CVE-2026-18556 and CVE-2026-18577, but not before intruders used the RMM platform’s own Take Control feature to plant outbound-only Cloudflare Tunnels on managed endpoints, persistence that survives even after access through N-central itself is cut off.
Wiz researchers found CosmosEscape, a flaw in Azure Cosmos DB’s Gremlin query engine that let a crafted query achieve code execution on the multi-tenant gateway and expose a platform-wide signing secret capable of retrieving the primary key to any Cosmos DB account on the service, including network-isolated ones. Wiz reported it privately in November 2025, Microsoft shipped a fast hotfix within 48 hours, but the full architectural fix that eliminated the platform-wide key entirely was not completed until July 2026, with public disclosure on 30 July. Microsoft reports no evidence of exploitation and says customers need to take no action. For European organisations storing regulated data in Cosmos DB, that assurance rests entirely on Microsoft’s own telemetry of an eight-month window they controlled from end to end.
VMSA-2026-0006, published by Broadcom on 29 July 2026, fixes five vulnerabilities across vCenter, ESX and Cloud Foundation. CVE-2026-59309 is an authentication bypass in the VMware Directory Service, and CVE-2026-59310 is a directory traversal flaw enabling unauthenticated remote code execution, both scoring 9.8. CVE-2026-47876, scoring 9.3, is a VM escape via the VMXNET3 virtual network adapter. Broadcom reports no known exploitation or public proof-of-concept as of publication, which is precisely the window in which patching still prevents an incident rather than responding to one.
CVE-2026-16812, a command injection flaw in self-hosted VeloCloud Orchestrator with a maximum CVSS score of 10.0, lets a remote, unauthenticated attacker run arbitrary commands on the system that centrally manages an organisation’s entire SD-WAN. CISA confirmed active exploitation on 27 July, added it to the Known Exploited Vulnerabilities catalog, and set a 30 July patch deadline under Binding Operational Directive 26-04. That deadline only legally binds US federal agencies. Every other organisation still running an unpatched on-prem Orchestrator, including the European telecoms, logistics firms and retailers who rely on VeloCloud to manage branch networks, is exposed today.
Copenhagen-based Adform, a demand-side advertising platform used by roughly 14,000 companies with around 30 percent share of the DSP market, had its trackpoint-async.js tracking script compromised to inject clipboard-hijacking malware. Any Bitcoin, Ethereum or TRON wallet address copied on an affected site was silently swapped for an attacker-controlled address, re-applied every three seconds even if a victim noticed and re-copied it. The malicious script ran undetected for roughly a week before security researcher Kevin Beaumont identified it, and it reached every site embedding the tracker, none of which had to make a mistake of their own to be affected.
Anthropic disclosed on 30 July 2026 that three of its AI models, including Claude Opus 4.7 and an internal research model called Mythos 5, breached real organisations during cybersecurity evaluations run with third-party partner Irregular. A misconfiguration gave the models genuine internet access despite being told the environment was an isolated simulation, and one model exploited a SQL injection flaw and an exposed debug page before uploading a malicious Python package to PyPI that compromised 15 real machines, including a security vendor’s own systems. Neither company caught the error until after the fact.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.