preloader

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

digital-security third-party-risk supply-chain gdpr data-breach compliance europe incident-response

One Shipping Company Got Breached and Steam, ING and a Football Club Are All Now Writing to Their Customers About It

A cyberattack on logistics giant CEVA between July 29 and August 1 exposed names, addresses, phone numbers and order details of customers belonging to companies that never had a direct breach of their own, including Valve’s Steam hardware store, banking group ING, football club Ajax and eyewear retailer Ace and Tate. Eight European warehouses were disrupted, and every affected brand is now issuing its own GDPR notifications for data it never held the underlying breach of, a textbook case of risk inherited through a shared vendor.

digital-security digital-privacy europe belgium authentication identity-management vulnerability-management supply-chain nis2

A Browser Extension Used by 8 of Belgium's 10 Biggest Banks Would Talk to Any Website That Asked, No Questions

Researcher James Arnott of Bay Area Labs disclosed at DEF CON that Connective, the digital identity extension developed by Nitro Software Belgium and used by over two million people, eight of Belgium’s ten largest banks and 60-plus government agencies, never checked which website was talking to it. Any page or embedded ad could silently read eID and payment card data, and a second flaw allowed drive-by remote code execution without an ID card even present. The vendor took 146 days to ship a full fix, longer than the exposure window many NIS2-regulated institutions would accept from a supplier.

devops digital-security open-source data-breach vulnerability-management patch-management business-intelligence europe self-hosted

A Maximum-Severity Flaw in Your BI Dashboard Just Gave Attackers Admin Access to Every Database It Connects To

Metabase, the open-source business intelligence tool widely self-hosted by European teams for data sovereignty reasons, patched an unauthenticated SQL injection flaw in its password-reset endpoint carrying the maximum CVSS score of 10.0. Attackers exploited it as a zero-day starting around August 3, using it to gain full admin access and pivot into every database connection Metabase held credentials for. Framework and Tally have both confirmed customer data was exposed before the vendor even had a patch out.

digital-security devops europe poland nis2 critical-infrastructure ot-security incident-response energy

Attackers Found a Way Into a Power Plant That No Firewall Rule Was Written to Stop: A Private Mobile Network Nobody Treated as the Internet

CERT Polska’s follow-up report on the December 2025 sabotage of a Polish combined heat and power plant confirms a previously unseen attack path: attackers pivoted from a compromised wind farm VPN device into the region’s private cellular APN, which let any connected device talk to any other, and rode it straight into a second facility’s PLCs. The agency attributes the intrusion to Static Tundra, linked to Russia’s FSB, and is now telling every energy operator using a private APN to stop treating it as trusted infrastructure.

digital-security devops malware rmm endpoint-security europe incident-response

A Fake Zoom Update Page Now Installs a Real, Digitally Signed Remote Access Tool on Your Network

Securonix is tracking an active campaign it calls SMOKE#SCREEN that lures victims with convincing fake update pages for Zoom, Adobe products and business document viewers, then installs ConnectWise ScreenConnect, a legitimate, digitally signed remote monitoring and management tool, as a persistent backdoor. Because the payload is genuine commercial software rather than custom malware, it frequently passes signature-based defences and blends into the traffic patterns IT teams already expect. The campaign has expanded beyond Windows to a fake macOS installer, and its use of legitimate RMM software as the final payload puts it in the same category of attack that has repeatedly hit European MSPs and their downstream clients this year.

devops digital-security supply-chain open-source developer-tools ci-cd europe

Eclipse Foundation Promised Pre-Publish Checks After GlassWorm. 77 Fake Extensions Got Through Anyway

Manifold Security found 77 ’evil twin’ extensions uploaded to the Open VSX marketplace between 26 July and 1 August 2026, each impersonating a real publisher, including AMD, Azure, Salesforce OSS and even the marketplace’s own namespace. Nineteen of them went beyond basic fingerprinting to exfiltrate Git repository names, branch details and CI system identifiers to a shared external domain. Open VSX removed the packages by 3 August, five months after the Eclipse Foundation, which maintains the registry, announced mandatory pre-publish security checks in response to the GlassWorm worm attack. The checks did not stop this campaign, and anyone who installed one of the 77 extensions still has it on disk until they remove it manually.

digital-privacy gdpr europe compliance consent-management regulation digital-omnibus

The EU Was Going to Kill the Cookie Banner With a Browser Signal. The Council Just Deleted That Plan

The European Commission’s November 2025 Digital Omnibus proposal included Article 88b, a mechanism that would have let browsers transmit a single machine-readable consent signal to every website a user visits, replacing the per-site cookie banner entirely. In its position paper of 18 June 2026, the Council removed Article 88b from the text after Germany, France and Poland pushed for its deletion, reportedly following lobbying against the change. Article 88a, which does survive and moves cookie rules from the ePrivacy Directive into the GDPR itself, narrows the consent-free exemptions and mandates a single-click reject button, but legal analysis from firms including Osborne Clarke concludes banner fatigue is not going away. The European Parliament has not yet taken its own position, so the final shape of the rules is still open.

devops digital-security cve ci-cd jenkins vulnerability-management patch-management europe supply-chain

Jenkins Just Patched a Bug That Turns One Compromised Build Agent Into Full Control of Your Server

CVE-2026-70426, rated critical with a CVSS score of 9.8, lets an attacker who can execute code on a Jenkins build agent bypass the JEP-200 deserialization filter and run arbitrary code on the controller itself, the single most trusted machine in a CI/CD pipeline. Jenkins disclosed the flaw and shipped fixed Remoting versions on 5 August 2026, affecting Jenkins 2.575 and earlier and LTS 2.568.1 and earlier. Jenkins remains the most widely deployed CI/CD platform in European engineering organisations, and a compromised controller means every credential, every signing key, and every downstream deployment it touches is in scope.

digital-security identity-management cve gdpr digital-privacy europe vulnerability-management iam

Keycloak's Admin API Had a Filter That Forgot to Filter. Every Restricted Admin Could Read User PII

CVE-2026-17059 let any Keycloak admin account that could view a role also see the personal data of every user assigned to it, including names, email addresses and account status, regardless of whether that admin’s permissions were meant to stop there. Escape’s research team reported the broken object-level authorisation flaw on 18 July 2026, Red Hat published the CVE on 24 July, and Keycloak shipped the fix in version 26.7.0 on 28 July, a single line adding the per-user visibility check the endpoint had always been missing. Keycloak underpins identity and access management across a large share of European public-sector and enterprise deployments, and this is precisely the kind of access-control gap GDPR’s security-of-processing obligations expect organisations to catch before a researcher does.

ai-agents digital-security devops cve github ci-cd supply-chain europe vulnerability-management

A GitHub Issue With Zero Privileges Was Enough to Run Code on Anthropic's and Google's Own Servers

Security researchers at Novee presented findings at Black Hat USA showing that Anthropic’s Claude Code, Google’s Gemini CLI, and OpenAI’s Codex could all be driven to remote code execution on their vendors’ own CI runners by a single GitHub issue filed by an account with no repository access at all. The bugs, now fixed, lived not in the AI models but in the surrounding harness, the permissions, sandboxing, and tool-execution code every team relies on when it wires an AI coding agent into GitHub Actions. Any European team running these agents in their default configuration was exposed to the same class of attack against its own pipeline secrets.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!