preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

digital-security email-deliverability phishing microsoft-365 mfa identity-access-management aitm europe social-engineering

Your Staff Passed the MFA Prompt. The Attacker Was Already Inside.

Mirage2FA, a phishing-as-a-service kit active since 2024, has surged to compromise thousands of Microsoft 365 accounts across 3,500-plus organisations in the US and EU as of August 2026. Its adversary-in-the-middle proxy relays the password and one-time code straight to Microsoft in real time, then keeps the resulting session cookie, which means a password reset alone does not remove the attacker. Technology, manufacturing, and MSSPs are the hardest-hit sectors.

digital-security devops cve cisa-kev vpn network-security windows patch-management europe

A Four-Month-Old Windows VPN Patch Just Became Urgent, CISA Confirms Active Exploitation

CISA added CVE-2026-33824, a CVSS 9.8 unauthenticated remote code execution flaw in Windows IKE Service Extensions, to its Known Exploited Vulnerabilities catalog on August 18, four months after Microsoft patched it in April. Palo Alto Networks Unit 42 observed a Chinese-speaking threat actor manually sending reverse-shell callbacks to three IKE VPN endpoints, hands-on-keyboard activity against selected VPN concentrators rather than opportunistic scanning, a pattern that points toward espionage staging and initial access brokering rather than smash-and-grab ransomware.

email deliverability dmarc digital-security nis2 compliance europe

Countries With Mandatory DMARC Cut Phishing Success From 69% to 14%, Most of Europe Still Hasn't Enforced It

ENISA’s Threat Landscape data shows phishing accounts for roughly 60 percent of initial intrusions across the EU, and countries that made DMARC enforcement mandatory saw phishing success rates fall from 69 percent to 14 percent, while countries without a mandate stayed high. NIS2 now treats email authentication as a supervised control rather than a best practice, with fines reaching 10 million euros or 2 percent of global turnover for essential and important entities, and Germany’s national NIS2 law took effect on December 6, 2025. Despite that, most organizations still have a DMARC record without ever moving it to enforcement, which is where the actual protection lives.

security sap vulnerability cve enterprise patch-management ecommerce europe

SAP Commerce Cloud's Perfect-10 Vulnerability Went From Patch to Exploitation in Three Days

SAP patched CVE-2026-58231, a maximum-severity CVSS 10.0 unauthenticated remote code execution flaw in SAP Commerce Cloud, on August 11. By August 14, honeypots run by security researcher Defused Cyber were already recording exploitation attempts, despite no public proof-of-concept existing at the time. SAP Commerce Cloud underpins large-scale B2B and B2C sales operations at companies including Mercedes-Benz, Shell and BP, and the flaw lets an unauthenticated attacker abuse a default authentication client to run arbitrary code on internet-facing instances.

devops hetzner cloud outage disaster-recovery europe infrastructure

Hetzner's Storage Cluster Needed Manual Recovery, a Reminder That Object Storage Is Not a Backup Strategy

Two consecutive hardware failures in Hetzner’s NBG object storage cluster overwhelmed automatic redundancy for a subset of data, forcing Hetzner to take roughly a third of the cluster offline for manual restoration to avoid permanent loss. The incident began August 25 and Hetzner targeted a fix by August 26 at 11:00 CEST, with affected buckets inaccessible in the meantime. For any team treating a single object storage provider as its only copy of critical data, this is the scenario that redundancy promises are supposed to prevent, and sometimes cannot.

digital-security oracle cve vulnerability-management cisa-kev europe incident-response

The Oracle Patch You Installed in January Didn't Stop What CISA Found in August

CISA added CVE-2026-21962, a maximum severity CVSS 10.0 flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog on August 24, giving federal agencies just 72 hours to remediate. Oracle shipped the fix back in January 2026, but researchers now say exploitation began around the same time, with attack patterns detected by CloudSEK in early February and reports of a China-linked actor using it against government targets since. A patch applied on schedule does not tell you whether an attacker already got in before you applied it.

devops cicd github reliability infrastructure vulnerability-management europe

GitHub Actions Has Failed 13 Times in 17 Days. Your Pipeline Needs a Plan B

GitHub Actions has logged 13 separate incidents across nine different days in the first 17 days of August 2026, including a 10-hour outage on August 6 that failed 71 percent of workflow runs at peak, and a nearly 8-hour platform-wide incident on August 17 that alone consumed close to a year’s worth of Actions’ allowable downtime budget. Ninety-day uptime for Actions now sits at 99.33 percent, an order of magnitude worse than the 99.99 percent GitHub maintains for core Git operations. For teams whose deploys, tests and release gates run entirely through Actions, the pattern is now frequent enough to plan around rather than treat as a one-off.

devops digital-security gitlab cve cicd vulnerability-management europe software-supply-chain

GitLab's Emergency Patch Was Nine Days Old Before Attackers Started Using the Bug It Fixed

GitLab shipped an out-of-band patch on August 17 for CVE-2026-19478, a CVSS 9.4 unauthenticated code injection flaw in its GraphQL API that lets a remote attacker modify or delete public projects and user data with no login required. Public reporting confirmed active exploitation from August 20. Every self-managed GitLab Community and Enterprise Edition instance from 18.2 through 19.2 that has not yet applied 18.11.11, 19.0.8, 19.1.6 or 19.2.4 is exposed to an attack that needs nothing more than network access to the instance.

digital-security digital-privacy gdpr data-breach europe vulnerability-management public-sector

Two-Thirds of a Country's Population Just Got Breached Through One Internet-Facing System

Latvia’s Road Traffic Safety Directorate (CSDD) confirmed that a cyberattack over the weekend of August 8-9 exposed payment records for more than 1.2 million people and 200,000 organisations, dating back to 2008. CERT.LV traced the intrusion to a vulnerability in a CSDD system reachable from the internet. Officials have since resigned, a criminal investigation is underway, and the president has asked whether the breach amounts to a threat against critical state infrastructure. For any organisation running a public-facing system holding registry-scale personal data, this is what an unpatched exposure looks like at the far end of the consequence scale.

digital-security devops ai cve citrix n8n supply-chain europe vulnerability-management

A Hacker Asked Claude and OpenAI to Run His Attacks. They Said No. DeepSeek Said Yes.

Palo Alto Networks’ Unit 42 uncovered a Chinese-speaking threat actor, tracked as knaithe, who wired DeepSeek into an open-source tool called Hermes Agent and let it scan, research and exploit targets almost entirely on its own, hitting over 460 organisations across eight CVEs including Citrix NetScaler, Langflow and n8n. Unit 42 confirmed the actor tried the same setup with Claude and OpenAI models first, and both providers’ safety controls blocked the attempt. The operation was only discovered because the actor misconfigured Hermes Agent and exposed the entire operational workspace, credentials and target lists included.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!