These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional —
let us know and we'll correct or remove it.
The European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the EU on 8 July for failing to fully transpose the NIS2 Directive into national law, nearly two years after the October 2024 deadline. The referral triggers daily financial penalties against those governments, but it does nothing to relax the obligations already sitting on the roughly 1,500 essential and important entities the directive covers. If your national transposition law has not landed yet, that is not a reason to wait, it is a reason to build to the directive itself.
Microsoft has agreed to spend billions of dollars renting AI computing capacity from Mistral’s European data centres, announced 21 July, in a deal that lets Azure customers run workloads on French-based infrastructure and adds Mistral’s Medium 3.5 and OCR 4 models to Azure AI Foundry. Mistral is separately committing 4 billion euros to its own European buildout. For regulated industries that have spent two years asking whether Azure can ever be a sovereignty-compatible choice, this is the closest either company has come to a direct answer.
The European Supervisory Authorities’ first annual overview of major ICT incidents under DORA, drawn from 3,383 incidents reported across the EU financial sector in 2025, found that cybersecurity attacks caused only 10 percent of them. System failures and third-party providers were behind far more, with close to a third of major incidents traced back to an ICT supplier, another financial entity, or infrastructure the firm did not directly control. Supervisors have signalled enforcement against reporting failures begins in the current supervisory cycle, and the data itself is now a roadmap for where that scrutiny will land first.
CVE-2026-8933, a CVSS 7.8 local privilege escalation flaw in Ubuntu’s snap-confine, lets an unprivileged local user exploit a race condition during sandbox setup to gain full root access on default installations of Ubuntu Desktop 24.04, 25.10 and 26.04. The flaw exists precisely because Canonical hardened snap-confine last year, replacing a set-uid-root binary with a set-capabilities model, and the transition introduced the very race condition it was meant to close.
Craneware, an Edinburgh-headquartered billing and financial performance software provider whose Trisus Chargemaster platform underpins pricing and billing for more than 2,000 US hospitals and close to 10,000 clinics and pharmacies, confirmed on 20 July that attackers accessed and exfiltrated a subset of its data environment, including employee, customer and partner records. The company has notified the UK’s Information Commissioner’s Office and the FBI, a reminder that a single European vendor’s security posture can carry risk for an entire sector on another continent.
Security researcher Yuhang Wu of depthfirst published working exploit code on 24 July for a GitLab remote code execution chain that GitLab patched six weeks earlier, on 10 June, without ever flagging it as a security fix. Any authenticated user who can push to a self-managed GitLab instance running an unpatched version can commit two crafted Jupyter notebooks and end up running commands as the git user, no admin rights or CI access required.
Buried in Microsoft’s record-breaking July Patch Tuesday is CVE-2026-57092, a critical use-after-free in Windows VMSwitch that lets an attacker who already has code execution inside a guest VM send crafted network requests to the Hyper-V virtual switch and escalate to full control of the host, breaking the isolation boundary every multi-tenant hosting setup depends on. With a CVSS score of 9.9 and no user interaction required, any organisation running Hyper-V, including hosting providers, MSPs and businesses with on-premises virtualization, should treat this as a same-week patch.
A connectivity failure in AWS’s US-West-2 region on July 24 took down Reddit, Hulu, Apple Pay, DoorDash and PlayStation Network for roughly 80 minutes. AWS traced it to networking devices routing traffic between the region and the Seattle metro area, the third notable AWS reliability incident in about three months after a Northern Virginia thermal event in May and a network disruption in June. None of the three were application bugs, they were physical and network infrastructure failures, which is exactly the category of risk single-region architecture does not protect against.
Anthropic’s Claude models reached general availability on Microsoft Foundry with Azure-native billing and governance, but the EU Data Zone that would guarantee in-region processing was not part of the launch. Deployments run through Global Standard or US Data Zone routing, so prompts and responses can leave Europe even when the endpoint address reads Sweden. For any regulated organisation planning to buy Claude the way it buys the rest of its Azure estate, that gap turns a procurement decision into a compliance review.
A routine network change in Azure’s West US region on July 23 cascaded into a four-hour outage that disrupted more than twenty services, including AKS, Azure Virtual Desktop, ExpressRoute and Microsoft Sentinel, plus Microsoft 365, Teams and Outlook. Microsoft resolved it with a rollback, but the incident is the second major Azure region outage in barely a month and a reminder that your security monitoring platform can go down at exactly the moment you would most want it running.
This site uses cookies. By continuing to use this website, you agree to their use.
We’ll help you resolve your infrastructure challenges
Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.