preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

digital-security devops microsoft windows windows-defender cve vulnerability-management patch-management zero-day europe

Microsoft's July Fix for a Windows Defender Bug Did Not Actually Fix It

A new proof of concept called ShieldBreak, tracked as CVE-2026-69414, bypasses the patch Microsoft shipped in July for RoguePlanet, an earlier Windows Defender privilege escalation flaw. Where RoguePlanet was an unreliable race condition, ShieldBreak reportedly gets a local attacker to SYSTEM with a 100 percent success rate on Windows 11 25H2 and Windows Server 2025. Microsoft has assigned a CVSS score of 7.8 and flagged exploitation as more likely, but has not published a fix, a workaround, or a list of affected builds.

digital-security digital-privacy gdpr cve data-breach identity-access-management europe france

France's Tax Authority Just Confirmed a Breach That Started With One Set of Stolen Login Credentials

France’s Direction Generale des Finances Publiques disclosed on August 14 that an attacker used stolen or impersonated credentials belonging to a DGFiP employee and an authorised third party to access tax and property records on 678,000 individuals and businesses, after a threat actor calling itself ZeroBytes listed the data for sale on a hacking forum on August 12. The intrusion ran undetected through June and July before DGFiP disabled the affected accounts and notified CNIL, France’s data protection authority. No exotic exploit was needed, just credentials that worked.

digital-security cve zero-day phishing social-engineering supply-chain europe defence

North Korean Hackers Are Recruiting Your Aerospace Engineers, and the Job Offer Comes With a Zero-Day

Check Point Research has uncovered a new wave of Operation Dream Job, a long-running Lazarus Group campaign that impersonates recruiters and privacy technology company Enveil to target defence, aerospace and aviation organisations, with documented compromises at companies headquartered in France and Germany. Targets are told to download SecurityPDF, a trojanized PDF viewer that checks documents for a hidden marker and, when found, decrypts and launches a Windows zero-day exploit chain that installs a new variant of the FudModule rootkit. Microsoft patched the underlying flaw, CVE-2026-68820, on August 11, roughly two months after Lazarus began using it.

devops digital-security azure cloud identity-access-management infostealer data-breach europe

Vodafone, McDonald's and TCS Were Just Hit by the Same Attack, and It Was Not an Azure Vulnerability

A threat actor using the handle TheHatman is selling millions of employee records allegedly pulled from the Azure and Entra tenants of Fortune 500 organisations including Vodafone, McDonald’s, TCS, HCL Technologies and IHG, with the McDonald’s dataset alone running past 1.7 million records. Researchers at Hudson Rock have traced the access to compromised credentials tied to infostealer malware infections on employee machines at several of the affected companies, not a flaw in Azure itself. For any organisation running its identity infrastructure on Azure AD or Entra ID, the exposure was sitting on an endpoint, not in Microsoft’s cloud.

devops digital-security ai mlops cve vulnerability-management europe cisa-kev

CISA Just Put a Two-Year-Old AI Framework Bug on Its Must-Patch List. If Your Data Science Team Runs Ray, That Is Not a Coincidence

CISA added CVE-2025-62593, a code injection flaw in the Ray AI compute framework, to its Known Exploited Vulnerabilities catalog on August 17, 2026, citing evidence of active exploitation. The bug lets an attacker combine a trivial User-Agent header bypass with a DNS rebinding attack so that simply visiting a malicious webpage in Firefox or Safari can hand a remote attacker code execution on a developer’s local Ray instance, no exposed dashboard required. It follows the 2024 ShadowRay campaign, which found thousands of Ray clusters compromised for crypto mining and credential theft after being left open to the internet with no authentication at all.

digital-security apple macos cve patch-management vulnerability-management europe netherlands

Dutch Cybersecurity Officials Are Warning About a Mac Bug That Hands Out Root Access for Free

The Dutch National Cyber Security Centrum has warned that CVE-2026-65400, an authentication bypass in macOS Screen Sharing that Apple patched on August 6, is being actively exploited against Macs with the service reachable from the internet. CISA rescored the flaw from 7.1 to a critical 9.8 after every reported case ended the same way: an unauthenticated attacker walks straight to root access and installs a Monero cryptocurrency miner. A public proof-of-concept exploit is now circulating, and any Mac still running an unpatched OS with port 5900 open is exposed.

aws cloud devops resilience europe germany infrastructure incident-management direct-connect

A Water Leak in One Frankfurt Data Centre Took Down AWS Connectivity for Every Customer Who Skipped Redundancy

A facility infrastructure issue at Equinix’s FR5 site in Frankfurt on August 15, 2026, degraded AWS Direct Connect for customers whose connections terminated solely at that location, with unverified reports pointing to a cooling failure caused by a water leak. Customers running multi-site or redundant Direct Connect configurations were unaffected; those who were not had to fail over to VPN or sit with packet loss until AWS restored the underlying network equipment. It is a narrow, contained incident, and that is exactly what makes it a useful test case for European organisations that treat a single cloud region, or a single physical facility within it, as sufficient.

digital-security devops microsoft windows cve dns vulnerability-management patch-management europe active-directory

The Patch Tuesday Bug Everyone Is Talking About Is Not the One You Should Patch First

Coverage of Microsoft’s August 2026 Patch Tuesday has focused on CVE-2026-68820, the Windows privilege escalation flaw North Korea’s Lazarus Group exploited before a fix existed. Sitting in the same 421-bug release is CVE-2026-62878, a maximum-severity, CVSS 9.8 stack-based buffer overflow in Windows DNS Server that Zero Day Initiative researchers flagged as wormable and reachable, unauthenticated, on virtually every Windows Server domain network from an internal or external position. It has not been confirmed exploited in the wild yet. Given how easy it is to trigger and how central DNS is to every Active Directory environment, that is a narrow window, not a reason to wait.

cloud ovhcloud europe digital-sovereignty devops defence ai-infrastructure secnumcloud

OVHcloud Opens a Dedicated Defence Cloud Unit for European Militaries, Backed by a Gartner Nod No Other EU Vendor Got

OVHcloud used the InCyber Forum 2026 to announce it is accelerating a dedicated defence unit for European militaries, recruiting armed forces and defence industry experts cleared to work on ‘secret’ classified projects, built on France’s SecNumCloud qualification. The announcement lands in the same month OVHcloud was named the only European vendor to reach Challenger status in Gartner’s July 2026 Magic Quadrant for Cloud AI Infrastructure, a recognition it is tying directly to digital sovereignty, price transparency and open technologies. For European organisations still assuming a sovereign cloud alternative to AWS, Azure and Google Cloud is not yet mature enough for serious workloads, this is evidence that assumption needs revisiting.

ransomware digital-security europe devops incident-response supply-chain double-extortion thegentlemen

TheGentlemen Ransomware Overtook Qilin as the World's Busiest Extortion Gang, and Its Encryptor Spreads on Its Own

TheGentlemen, a ransomware-as-a-service operation launched just a year ago by a former Qilin affiliate, posted 300 victims in Q2 2026 to become the most active ransomware group on record, after a 588 percent surge in Q1. Microsoft’s analysis of its Go-based encryptor found it self-propagates across a network once inside, reducing how much an attacker has to do by hand after the initial break-in. Two more victims, an Italian recycling firm and a Swiss property management company, were added to its leak site on 13 and 14 August, a reminder that this group is not only chasing headline targets.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!