preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

ai compliance eu gdpr regulation europe enterprise ai-act digital-privacy

The EU AI Act's Big Deadline Got Pushed to 2027. A Smaller One Still Lands Tomorrow, and It Applies to Almost Every Business

The EU’s Digital Omnibus has delayed the Artificial Intelligence Act’s high-risk Annex III obligations from 2 August 2026 to December 2027, and sector-specific rules further to 2028. But Article 50’s transparency duties, covering chatbot disclosure, AI-generated content marking, and deepfake labelling, were left untouched and still take effect on 2 August 2026 alongside the European Commission’s enforcement powers over general-purpose AI providers. Unlike the high-risk tier, Article 50 is not limited to a narrow list of sensitive use cases: it applies to any organisation using generative AI to produce content, run a chatbot, or generate synthetic media.

digital-privacy apple dma compliance europe app-store regulation interoperability

Apple Lost Its Case Against the EU's Interoperability Rules. Here Is What That Means If You Build for iOS

The EU General Court dismissed all three of Apple’s challenges to its Digital Markets Act gatekeeper designation on July 8, 2026, including Apple’s argument that the interoperability obligations breach its fundamental rights. The court found the interoperability provision is not the legal basis of the designation itself and declined to rule on the substance, a procedural finding that narrows how Apple, Google, Amazon and other gatekeepers can contest DMA obligations going forward. Apple can still appeal on points of law to the Court of Justice of the EU, but the practical effect for now is that App Store and iOS interoperability requirements stand.

google-cloud cloud devops resilience outage europe infrastructure kubernetes

Google Just Shipped Automated Failover for Cloud Run, Six Days After a Netherlands Outage Showed Why It Was Needed

Google Cloud’s Service Health feature for Cloud Run reached general availability in late July 2026, automating cross-region failover using instance-level readiness probes behind a global external or cross-region internal Application Load Balancer, with a two-click setup and no charge beyond the compute the readiness probes consume. The timing lands six days after a cooling failure at a Google Cloud facility in the Netherlands took down GCVE, NetApp Volumes and bare metal services in europe-west4 for roughly 15 hours, an outage that had no automated cross-region failover available for the affected services at the time.

digital-security email microsoft exchange cve incident-response europe government

Patching This Outlook Flaw Will Not Remove the Backdoor: Russian Hackers Found a Way to Survive Password Resets Entirely

Russia-aligned group TA488, also tracked as Void Blizzard or Laundry Bear, has been exploiting CVE-2026-42897 in Outlook Web Access since March 2026 to plant an implant called OWAReaper against government, telecom, financial, hospitality and aerospace targets in the US and Europe. The implant grants owner-level mailbox access through an Exchange server permission call rather than anything on the victim device, so patching the flaw, rotating credentials, and even re-imaging the endpoint all leave the access intact. Only a direct audit of Exchange mailbox permissions closes it.

devops github cloud pricing cost-optimization developer-tools ci-cd europe

GitHub Code Quality Went Generally Available on July 20 and Started Billing Automatically. Check Your Invoice Now

GitHub Code Quality moved from public preview to a purchasable product on July 20, 2026, charging 10 dollars per active committer per month on every enabled repository, plus separate usage-based billing for AI-powered features like Copilot code review and Autofix, and GitHub Actions minutes for CodeQL analysis. More than 10,000 enterprises used the free preview, and billing began the moment GA landed, with no separate opt-in required for organisations that already had it switched on.

digital-security ai-agents mcp devops cve open-source developer-tools europe

RufRoot: An Unauthenticated Bridge Left 233 AI Agent Tools, Including Shell Execution, Open to the Network by Default

CVE-2026-59726, a maximum-severity flaw in the open-source agent meta-harness Ruflo, let any network attacker call terminal_execute and other privileged tools through an unauthenticated Model Context Protocol bridge that binds to 0.0.0.0 by default. Noma Labs disclosed it on June 30, the maintainer shipped a fix within 24 hours, but the underlying pattern, self-hosted AI agent infrastructure exposed by a default configuration nobody reviewed, is now recurring across the agentic tooling ecosystem.

digital-privacy gdpr compliance europe data-protection dpo privacy-engineering

Since June 19 Every UK Controller Needs a Documented Complaints Process. Six Weeks In, Most Have Not Tested Theirs

The Data (Use and Access) Act 2025 requires every UK data controller, regardless of size or sector, to operate an internal process for handling data protection complaints, acknowledging each one within 30 days and responding without undue delay. The requirement took effect on 19 June 2026, and the ICO has paired it with its own risk-based triage framework for complaints that reach the regulator, prioritising cases by harm rather than investigating everything that lands on its desk.

devops digital-security linux kernel cve ai vulnerability-management patch-management europe

A Researcher Says AI Helped Write Half His Linux Root Exploit. Your Patch Window Just Got Shorter

STAR Labs researcher Lee Jia Jie disclosed CVE-2026-53264, a use-after-free race in the Linux kernel’s traffic-control subsystem, and said AI tooling sped up bug discovery, proof-of-concept generation, and race-condition timing across the entire research pipeline. The flaw is patched upstream and not yet listed as exploited, but the story is less about this one CVE and more about how fast a local privilege escalation now moves from disclosure to a working root exploit. For teams running self-managed Linux infrastructure across Europe, that compressed timeline changes what an acceptable patch cadence looks like.

digital-security apple ios macos patch-management vulnerability-management mobile-security europe enterprise

Apple Just Patched Nearly 90 iPhone Flaws in One Update, Several of Them Handing Over the Kernel

iOS 26.6 and macOS Tahoe 26.6, released on July 27, fix 78 vulnerability entries covering 87 CVEs, with the heaviest concentration in the kernel and WebKit, including a critical AVEVideoEncoder buffer overflow that lets a malicious app run code with kernel privileges. Apple says none were exploited before the fix shipped, but that window closes the moment the advisory goes public. For any organisation managing a fleet of iPhones and Macs, this is a full patch-management event, not a background nudge to tap update.

digital-privacy apple email gdpr privacy-engineering data-minimization europe icloud

Apple Said Its Email Privacy Feature Was Fixed. Twice. Researchers Broke It Again Two Weeks Later

Apple’s Hide My Email, the iCloud+ feature that generates disposable aliases so a real address never has to be shared, leaked the real address behind an alias through mail server logs whenever a message to that alias bounced. Researchers reported it in mid-2025, Apple declared it fixed in March and again in June, and both times the flaw still worked. A patch shipped on July 3, and AppleInsider reproduced the same leak again on July 17. It is a clean case study in why a vendor’s fixed claim is not the same thing as a fix, and why any system that touches personal data needs its own logging and error-handling paths checked for exactly this kind of leak.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!