These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
Russia-aligned group TA488, also tracked as Void Blizzard or Laundry Bear, has been exploiting CVE-2026-42897 in Outlook Web Access since March 2026 to plant an implant called OWAReaper against government, telecom, financial, hospitality and aerospace targets in the US and Europe. The implant grants owner-level mailbox access through an Exchange server permission call rather than anything on the victim device, so patching the flaw, rotating credentials, and even re-imaging the endpoint all leave the access intact. Only a direct audit of Exchange mailbox permissions closes it.
GitHub Code Quality moved from public preview to a purchasable product on July 20, 2026, charging 10 dollars per active committer per month on every enabled repository, plus separate usage-based billing for AI-powered features like Copilot code review and Autofix, and GitHub Actions minutes for CodeQL analysis. More than 10,000 enterprises used the free preview, and billing began the moment GA landed, with no separate opt-in required for organisations that already had it switched on.
CVE-2026-59726, a maximum-severity flaw in the open-source agent meta-harness Ruflo, let any network attacker call terminal_execute and other privileged tools through an unauthenticated Model Context Protocol bridge that binds to 0.0.0.0 by default. Noma Labs disclosed it on June 30, the maintainer shipped a fix within 24 hours, but the underlying pattern, self-hosted AI agent infrastructure exposed by a default configuration nobody reviewed, is now recurring across the agentic tooling ecosystem.
The Data (Use and Access) Act 2025 requires every UK data controller, regardless of size or sector, to operate an internal process for handling data protection complaints, acknowledging each one within 30 days and responding without undue delay. The requirement took effect on 19 June 2026, and the ICO has paired it with its own risk-based triage framework for complaints that reach the regulator, prioritising cases by harm rather than investigating everything that lands on its desk.
STAR Labs researcher Lee Jia Jie disclosed CVE-2026-53264, a use-after-free race in the Linux kernel’s traffic-control subsystem, and said AI tooling sped up bug discovery, proof-of-concept generation, and race-condition timing across the entire research pipeline. The flaw is patched upstream and not yet listed as exploited, but the story is less about this one CVE and more about how fast a local privilege escalation now moves from disclosure to a working root exploit. For teams running self-managed Linux infrastructure across Europe, that compressed timeline changes what an acceptable patch cadence looks like.
iOS 26.6 and macOS Tahoe 26.6, released on July 27, fix 78 vulnerability entries covering 87 CVEs, with the heaviest concentration in the kernel and WebKit, including a critical AVEVideoEncoder buffer overflow that lets a malicious app run code with kernel privileges. Apple says none were exploited before the fix shipped, but that window closes the moment the advisory goes public. For any organisation managing a fleet of iPhones and Macs, this is a full patch-management event, not a background nudge to tap update.
Apple’s Hide My Email, the iCloud+ feature that generates disposable aliases so a real address never has to be shared, leaked the real address behind an alias through mail server logs whenever a message to that alias bounced. Researchers reported it in mid-2025, Apple declared it fixed in March and again in June, and both times the flaw still worked. A patch shipped on July 3, and AppleInsider reproduced the same leak again on July 17. It is a clean case study in why a vendor’s fixed claim is not the same thing as a fix, and why any system that touches personal data needs its own logging and error-handling paths checked for exactly this kind of leak.
Stadler Rail confirmed that the Everest ransomware group breached a data-exchange platform it shared with a supplier, using stolen login credentials rather than any flaw in Stadler’s own network, and stole technical documents belonging to that supplier. Everest demanded roughly CHF 10 million, about $12.3 million, and Stadler refused to pay, stating its internal IT, production lines, and trains in service worldwide were unaffected. The case is a clean illustration of why NIS2’s third-party risk provisions target the connections between critical infrastructure operators and their suppliers, not just the operators themselves.
n8n, the open-source workflow automation platform many European teams self-host specifically to keep data out of US-owned SaaS platforms, patched CVE-2026-25049, a critical expression sandbox escape with a CVSS score as high as 9.9 that lets an authenticated user with workflow-edit rights run arbitrary system commands on the host. It is a bypass of the fix for a nearly identical flaw, CVE-2025-68613, patched only in December. Fixed versions are 1.123.17 and 2.5.2, and the fact that this is a repeat bypass matters more than the single patch.
CISA’s remediation deadline for CVE-2026-56155, an actively exploited privilege escalation flaw in Microsoft Active Directory Federation Services, falls today. AD FS underpins federated single sign-on for a large share of hybrid-identity European enterprises, and researchers have described this flaw paired with a remote code execution bug as forming a ransomware delivery chain: compromise one networked host, pivot to the AD FS server, escalate to administrator, and forge authentication tokens for the entire federated estate. Microsoft patched it on July 14, giving affected organisations two weeks.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.