preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

digital-security email microsoft exchange cve incident-response europe government

Patching This Outlook Flaw Will Not Remove the Backdoor: Russian Hackers Found a Way to Survive Password Resets Entirely

Russia-aligned group TA488, also tracked as Void Blizzard or Laundry Bear, has been exploiting CVE-2026-42897 in Outlook Web Access since March 2026 to plant an implant called OWAReaper against government, telecom, financial, hospitality and aerospace targets in the US and Europe. The implant grants owner-level mailbox access through an Exchange server permission call rather than anything on the victim device, so patching the flaw, rotating credentials, and even re-imaging the endpoint all leave the access intact. Only a direct audit of Exchange mailbox permissions closes it.

devops github cloud pricing cost-optimization developer-tools ci-cd europe

GitHub Code Quality Went Generally Available on July 20 and Started Billing Automatically. Check Your Invoice Now

GitHub Code Quality moved from public preview to a purchasable product on July 20, 2026, charging 10 dollars per active committer per month on every enabled repository, plus separate usage-based billing for AI-powered features like Copilot code review and Autofix, and GitHub Actions minutes for CodeQL analysis. More than 10,000 enterprises used the free preview, and billing began the moment GA landed, with no separate opt-in required for organisations that already had it switched on.

digital-security ai-agents mcp devops cve open-source developer-tools europe

RufRoot: An Unauthenticated Bridge Left 233 AI Agent Tools, Including Shell Execution, Open to the Network by Default

CVE-2026-59726, a maximum-severity flaw in the open-source agent meta-harness Ruflo, let any network attacker call terminal_execute and other privileged tools through an unauthenticated Model Context Protocol bridge that binds to 0.0.0.0 by default. Noma Labs disclosed it on June 30, the maintainer shipped a fix within 24 hours, but the underlying pattern, self-hosted AI agent infrastructure exposed by a default configuration nobody reviewed, is now recurring across the agentic tooling ecosystem.

digital-privacy gdpr compliance europe data-protection dpo privacy-engineering

Since June 19 Every UK Controller Needs a Documented Complaints Process. Six Weeks In, Most Have Not Tested Theirs

The Data (Use and Access) Act 2025 requires every UK data controller, regardless of size or sector, to operate an internal process for handling data protection complaints, acknowledging each one within 30 days and responding without undue delay. The requirement took effect on 19 June 2026, and the ICO has paired it with its own risk-based triage framework for complaints that reach the regulator, prioritising cases by harm rather than investigating everything that lands on its desk.

devops digital-security linux kernel cve ai vulnerability-management patch-management europe

A Researcher Says AI Helped Write Half His Linux Root Exploit. Your Patch Window Just Got Shorter

STAR Labs researcher Lee Jia Jie disclosed CVE-2026-53264, a use-after-free race in the Linux kernel’s traffic-control subsystem, and said AI tooling sped up bug discovery, proof-of-concept generation, and race-condition timing across the entire research pipeline. The flaw is patched upstream and not yet listed as exploited, but the story is less about this one CVE and more about how fast a local privilege escalation now moves from disclosure to a working root exploit. For teams running self-managed Linux infrastructure across Europe, that compressed timeline changes what an acceptable patch cadence looks like.

digital-security apple ios macos patch-management vulnerability-management mobile-security europe enterprise

Apple Just Patched Nearly 90 iPhone Flaws in One Update, Several of Them Handing Over the Kernel

iOS 26.6 and macOS Tahoe 26.6, released on July 27, fix 78 vulnerability entries covering 87 CVEs, with the heaviest concentration in the kernel and WebKit, including a critical AVEVideoEncoder buffer overflow that lets a malicious app run code with kernel privileges. Apple says none were exploited before the fix shipped, but that window closes the moment the advisory goes public. For any organisation managing a fleet of iPhones and Macs, this is a full patch-management event, not a background nudge to tap update.

digital-privacy apple email gdpr privacy-engineering data-minimization europe icloud

Apple Said Its Email Privacy Feature Was Fixed. Twice. Researchers Broke It Again Two Weeks Later

Apple’s Hide My Email, the iCloud+ feature that generates disposable aliases so a real address never has to be shared, leaked the real address behind an alias through mail server logs whenever a message to that alias bounced. Researchers reported it in mid-2025, Apple declared it fixed in March and again in June, and both times the flaw still worked. A patch shipped on July 3, and AppleInsider reproduced the same leak again on July 17. It is a clean case study in why a vendor’s fixed claim is not the same thing as a fix, and why any system that touches personal data needs its own logging and error-handling paths checked for exactly this kind of leak.

ransomware digital-security third-party-risk supply-chain europe nis2 manufacturing incident-response

A Swiss Train Maker Just Showed Every European Manufacturer How to Handle a Supplier Ransom Demand: Refuse, Disclose, and Prove Your Own Systems Held

Stadler Rail confirmed that the Everest ransomware group breached a data-exchange platform it shared with a supplier, using stolen login credentials rather than any flaw in Stadler’s own network, and stole technical documents belonging to that supplier. Everest demanded roughly CHF 10 million, about $12.3 million, and Stadler refused to pay, stating its internal IT, production lines, and trains in service worldwide were unaffected. The case is a clean illustration of why NIS2’s third-party risk provisions target the connections between critical infrastructure operators and their suppliers, not just the operators themselves.

devops digital-security vulnerability cve open-source self-hosted automation europe sovereignty

The Second Bypass in Eight Months: n8n's Expression Sandbox Has Now Failed Twice, and Self-Hosting It for Data Sovereignty Means You Own Every Patch Window

n8n, the open-source workflow automation platform many European teams self-host specifically to keep data out of US-owned SaaS platforms, patched CVE-2026-25049, a critical expression sandbox escape with a CVSS score as high as 9.9 that lets an authenticated user with workflow-edit rights run arbitrary system commands on the host. It is a bypass of the fix for a nearly identical flaw, CVE-2025-68613, patched only in December. Fixed versions are 1.123.17 and 2.5.2, and the fact that this is a repeat bypass matters more than the single patch.

security microsoft identity vulnerability cve ransomware active-directory europe patch-management enterprise

Today Is the Deadline CISA Set for a Flaw in the Service That Runs Your Single Sign-On, and It Is Already Part of a Ransomware Chain

CISA’s remediation deadline for CVE-2026-56155, an actively exploited privilege escalation flaw in Microsoft Active Directory Federation Services, falls today. AD FS underpins federated single sign-on for a large share of hybrid-identity European enterprises, and researchers have described this flaw paired with a remote code execution bug as forming a ransomware delivery chain: compromise one networked host, pivot to the AD FS server, escalate to administrator, and forge authentication tokens for the entire federated estate. Microsoft patched it on July 14, giving affected organisations two weeks.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!