These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
DigitalOcean opened public preview of Spot GPU Droplets, offering NVIDIA HGX B300 and AMD Instinct MI350X and MI355X capacity at a rate locked below on-demand pricing for the life of the instance, aimed at short-lived batch training, inference and rendering workloads. The preview is live only in DigitalOcean’s US datacenters, with no European region included at launch. For European teams already running GPU workloads on DigitalOcean or evaluating it against Hetzner, AWS and sovereign cloud alternatives, the gap is worth planning around rather than waiting out.
Attackers hijacked a maintainer account on crates.io and published poisoned releases of arrayref, internment and append-only-vec on August 20, each pointing to a typosquatted dependency whose build script downloaded and ran a payload the moment a project compiled. The Rust Security Response Team pulled the malicious versions within 86 to 107 minutes, but arrayref alone has 245 million all time downloads and 403 crates listing it as a direct dependency, meaning the exposure window did not need to be long to matter. No application code had to run, and no developer had to click anything, compiling was enough.
AWS added a fourth Availability Zone, eu-west-2d, to its Europe (London) Region on 19 August, bringing new EC2 Trainium and P6 accelerated instance capacity alongside general purpose compute at standard London pricing. The stated driver is demand for AI and ML capacity, but the practical value for most UK and European customers is the extra fault isolation boundary it creates for architectures still built on the region’s original three zones. Capacity announcements like this only pay off for organisations that actually redesign around the new zone rather than simply noting it exists.
Microsoft disclosed CVE-2026-69836, a maximum-severity deserialization flaw in Entra ID that let an unauthenticated attacker execute code with no user interaction and no privileges required, and confirmed it was already being exploited before the fix shipped. The vulnerability was mitigated server-side, so no customer patch exists to install, but Microsoft has not said who exploited it, when, or how widely. For any European organisation whose sign-ins, Conditional Access and app registrations run through Entra ID, that silence is the whole problem.
CERT Polska issued Alert 145/2026 warning that CVE-2026-73570, an unauthenticated OS command injection flaw in Zimbra Collaboration Suite’s SNMP notification handling, is under active exploitation. Shadowserver counts more than 12,100 exposed Zimbra servers online, with the largest single regional concentration in Europe. A fix has existed since version 10.1.20 shipped on 20 July, more than a month before the exploitation warning, which means every vulnerable server still online is running on borrowed time rather than missing information.
CISA, the NSA, the FBI, the Department of Energy and the EPA issued a joint advisory confirming, for the first time in a government cybersecurity bulletin, that threat actors are using AI-generated scripts to attack internet-exposed Siemens S7 Series PLCs. Attackers scan with tools like Censys and ZoomEye to find controllers with the S7comm port open, then use AI to generate Python scripts that read and rewrite the logic controlling physical industrial processes. Siemens S7 controllers run water, energy and manufacturing sites across Europe as much as the US, and the barrier to writing a working exploit just dropped for everyone.
Citrix has patched CVE-2026-19490, a critical authentication bypass in NetScaler ADC and NetScaler Gateway that lets an unauthenticated remote attacker slip past login controls on appliances configured for SSL VPN, ICA Proxy, CVPN, RDP Proxy, or as an AAA virtual server. With a CVSS v4.0 score of 9.3 and NetScaler’s long history of being mass-exploited within days of disclosure, security researchers and even NHS England have told organisations to patch on an emergency basis rather than wait for a routine maintenance window.
Varonis Threat Labs disclosed CoSnitch, a critical Microsoft Copilot Personal flaw that let a single clicked link silently exfiltrate data from a victim’s connected accounts. Microsoft patched it on August 18, 2026, almost eight months after being told, and the discovery method was as notable as the bug itself: researchers prompted Copilot to explain why the attack would not work, and its own answers mapped out the undocumented parameter that made it work. It is the third Copilot vulnerability Varonis has found this year.
Mandiant has disclosed details of its Agentic Vulnerability Discovery Harness, an internal tool that chains specialised AI agents together to hunt for exploitable flaws in source code. In one incident response case involving stolen corporate repositories, AVDH surfaced more than 100 critical, verified vulnerabilities in two days, a task that would take a manual review team weeks. Across ten months of use on tens of millions of lines of code, it has already produced twelve assigned CVEs. The lesson for any organisation running its own code is uncomfortable, whatever a well-resourced attacker can now do to code they steal, they can do fast.
CISA, the FBI and the US Department of Health and Human Services have issued an updated joint advisory on Medusa ransomware, confirming the group has breached more than 500 critical infrastructure organisations since it first appeared in 2021. Medusa runs a double-extortion model with a 48-hour ransom deadline and recruits initial access brokers on criminal forums for between 100 and 1 million dollars a network. Separate 2026 tracking data shows Medusa accounts for 9 percent of all reported UK ransomware victims, against 2 percent worldwide, making this an advisory European incident response teams should read closely, not skim.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.