Region: europe
All entries tagged europe.
- Oracle's September 2026 Critical Security Patch Update carries six unauthenticated CVSS 10.0 flaws across WebLogic Server, Access Manager, Forms, Internet Directory, Platform Security for Java and Hyperion Financial Management
- WaterPlum ("Contagious Interview"): a seven-agency joint advisory quantifies the DPRK fake-job campaign for the first time, 30,000+ devices, 100+ countries, $10.7M in crypto, and Japan's first dismantled "laptop farm"
- Spain's AEPD discloses the first GDPR breach notification attributed to an autonomous AI agent, and tells data controllers to name AI-agent attacks explicitly in risk analyses
- A small French commune confirms a ransomware attack and data theft, days after the extortion actor Kairos claimed it on its leak site
- GTG-27005: Anthropic discloses a freelance Russia-based team that used Claude Code to engineer an autonomous FPV kamikaze-drone-swarm targeting stack with no human veto over target selection or detonation
- GTG-20006: a Russian espionage cluster runs AI-orchestrated intrusions and autonomously rebuilds detected malware across 20+ government, military and drone-supply-chain targets
- Apereo CAS: an embargoed remote-code-execution disclosure affects every 7.3.x deployment regardless of configuration, patched to 7.3.8.3, no CVE or technical detail published yet
- France's Ministry of Ecological Transition confirms a 'sophisticated' attack on mail systems; a criminal separately claims 22,000+ records via an IDOR flaw in its inspection-oversight tool
- CVE-2026-75650 ("StyleSmuggler"), Magento/Adobe Commerce: unauthenticated CVSS 10.0 RCE via template-engine injection, exploited three days before Adobe's hotfix existed
- ChimeraZ claims France's Département de l'Aveyron employment platform, exposing 20,000+ people's data including 1,499 CVs, a customer account without MFA, an IDOR flaw and a misconfigured Odoo database, per one of two trackers who reviewed the leak
- CVE-2026-86206 / CVE-2026-86207 / CVE-2026-86218, N-able N-central: a third, unrelated auth-bypass/RCE chain in five weeks, the third CVE a pre-auth CVSS 10.0 zero-day N-able says is already exploited
- Chaotic Eclipse turns its zero-day drops on third-party security products: local privilege escalation in CrowdStrike Falcon and Avast, with working proof-of-concept code public; all three vendors have since remediated
- Dell Secure Connect Gateway DSA-2026-382: an unauthenticated request replayed indefinitely mints ADMIN tokens, and Dell ships no workaround for any of the 105 flaws
- Association des maires de France confirms a UNION-based SQL-injection breach exposing 114,000 records on mayors, municipal councillors and territorial agents, plaintext passwords included
- CVE-2026-63219 / CVE-2026-58400, GeoNetwork opensource: chained unauthenticated formatter upload plus unsafe Saxon XSLT processing reaches unauthenticated RCE (CVSS 8.6 / 9.1)
- CNIL fines Hôpital privé de la Loire EUR 500,000 over a 727,000-record breach traced to a single unprotected external physician account
- CVE-2026-83548 / CVE-2026-83549 (SonicWall SMA1000: a pre-auth SSRF through an undocumented Work Place access path chains into post-auth command injection in the Management Console) both under active exploitation
- A recurring wave of data-leak claims against French departmental fire-and-rescue services (SDIS) hits seven more units, with the first board-level victim confirmation
- ZeroBytes claims a third French government platform in three months: ~148.9M rows from Zéro Logement Vacant via a Metabase admin session and a cleartext production database password
- CVE-2026-60004: Gitea's diffpatch endpoint turns an attacker-supplied patch into a live Git hook, giving command execution as the service account; KEV-listed after miner deployment
- CVE-2026-21962: an unauthenticated request bypasses access control in the Oracle WebLogic Server Proxy Plug-in, CISA KEV-listed on 24 August with exploitation running since January
- German mobile carriers leaked callees' IMEI, device model and OS version to callers during call setup, GSMA confirmed the flaw and warned its 1,000+ member operators worldwide
- Finland's NCSC-FI publishes an operational manufacturer checklist for the EU Cyber Resilience Act's 24h/72h/14-day/1-month reporting clock, two weeks before the 11 September 2026 go-live
- NCSC UK advisory: increased targeting of internet-exposed OT and edge devices globally, including the UK, by state and non-state actors, with 'some limited real-world disruption'
- Claroty Team82: Danfoss AK-SM 800A refrigeration system managers, undocumented 'code-of-the-day' authentication bypass and post-authentication command-injection RCE across thousands of internet-exposed devices
- Claroty Team82: 23 vulnerabilities in Copeland XWEB Pro supervisory refrigeration controllers chain to unauthenticated root RCE; a deterministic admin password derived from the device's own MAC address is one of THREE independent pre-auth paths
- SUEZ Eau France notifies customers of a technical service provider's breach, identity, contract and, for some customers, bank and identity-document data exposed
- La Protection Civile (France): eProtec volunteer-management platform breach, 525,000+ profiles including minors, intrusion dated to March 2026 discovered mid-August
- TA4922 adds PackClient, a Telegram-sold modular RAT/C2 framework, to its toolkit, dual-channel C2, registry-resident configuration, and tax-themed lures against mainland China and India
- Nimbus Manticore (Iranian IRGC-affiliated APT, aka Tortoiseshell/UNC1549/Smoke Sandstorm/Mirage Kitten) deploys a third 2026 toolset refresh (a TWOSTROKE-like backdoor abusing DLL search-order hijacking, paired with a reverse SSH tunneler) with confirmed expansion into the UK, France, Albania and Belarus
- Manchester Airports Group confirms a breach touching roughly 8.7 million customers across Manchester, Stansted and East Midlands, car-park, lounge and airport-WiFi sign-up data taken; FulcrumSec later claims credit and a client-side API-credential access vector
- DOJ/FBI seize domains behind QScan and QTRouter, the hacking-as-a-service platforms a PRC contractor sold to China's MSS and PLA, NASA, the Federal Reserve, DOJ, HHS, NIH and the US Senate named among the targets of QTFY, which DOJ separately dates to at least 2018; European infrastructure appears among Lumen's own profiled targets
- Kaltura mwEmbed/html5lib video player: unauthenticated RCE and arbitrary file read via an undocumented ServiceUrl parameter; patched for legacy Player V2 after months of no vendor response, 630+ exposed instances found by the discoverer
- miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products, one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line
- Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0, unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk
- isolated-vm sandbox escape (GHSA-864f-rcv7-6rh4): a TOCTOU type-confusion in ExternalCopy's transferList marshaling breaks the V8 Isolate guest/host boundary, the sandbox underneath a wide range of AI-agent and low-code automation platforms
- Zalktis (Latvian accounting software): unauthenticated SQL injection reachable by any PEPPOL/UBL e-invoice sender, no account, no network position, just a routine bookkeeping import (CVE-2026-59109)
- Johnson Controls C-CURE 9000 / victor: unauthenticated adjacent-network deserialization RCE on physical access-control application servers reaches connected security-workstation clients too (CVE-2026-21655, CVSS 9.6)
- YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix
- Adobe August 2026 Patch Day: ColdFusion ships a CVSS 10.0 unauthenticated OS command injection, and Campaign Classic ships two more unauthenticated CVSS 10.0 flaws in the same release
- SilkParasite runs seven RAT families behind six signed-application side-loading pairs, and the reusable detection is the pairing itself, not any DLL name: a signed binary loading a library placed beside it from an unusual location
- Rapid7's Q2 2026 quarterly report: high- and critical-severity disclosures doubled year on year to 8,539 while the number newly exploited held flat at 40, and 62% of what was exploited needed no user interaction at all
- SynkLoader: a Teams message from a lookalike tenant, an MSI called 'PowerShell Cleaner', and a six-module toolkit whose fake lock screen harvests the domain password its own tunnel then uses from the victim's IP
- Switzerland's federal cyber authority reports the public sector as still the largest share of mandatory critical-infrastructure notifications, and devotes its half-year report to two things a Swiss defender can act on: the anatomy of the Polish energy sabotage, and a crypto-theft playbook that recruits its victims on LinkedIn
- A Zurich business school tells students their bank details and sick-leave records were stolen, not from its own systems, but through the infrastructure of an IT service provider whose leak-site listing names seven other Swiss customers alongside it, and does not close the list
- A Valais commune's secretariat mailbox was compromised on 10 August and sat quiet until the attacker used it on 18 August to mail roughly 450 of the commune's own contacts; the send is what triggered detection
- Three Russia-nexus espionage clusters compromise European diplomats and academics without malware, by talking targets through app passwords, device-code approvals and WhatsApp device-linking, all of which are legitimate features working as designed
- A hijacked crates.io account added the first dependency arrayref has taken in ten years, and that dependency ran a backdoor at compile time; every machine that built an affected project during a ninety-minute window must be treated as compromised
- CVE-2026-72529 and CVE-2026-72530, a pre-auth chain on TrueConf Server's port 4307 reaches SYSTEM, and the operators use it to replace the client installer the server hands to everyone who joins a meeting
- An intrusion crew's AI-written playbook records why time-based blind testing fails against ViewState deserialization, and that a successful exploit returns HTTP 500, which is what most error-rate alerting is tuned to ignore
- SPECTRE unlinks EDR's kernel callbacks one at a time using a two-driver BYOVD toolkit and an offset table for thirteen Windows builds, and its Linux half hides through ftrace rather than the syscall table
- Windows Defender ships its own kernel write primitive: BTR.sys, the signed boot-time remediation driver, takes an encrypted job list from an alternate data stream and will delete or create any file or registry value asked of it
- Dead-drop command-and-control went commodity: three of four new entrants on Red Canary's monthly list resolve their C2 from a dead drop, two of them from a public blockchain, and the fourth is a GUI for Entra ID device-code phishing
- Three misp-stix flaws put the CTI pipeline itself in scope: a crafted STIX document can set its own MISP distribution and sharing fields, kill a long-running importer, or bleed data into the next event
- CVE-2026-69836, Microsoft corrected its own Entra ID CVSS 10.0 record from exploited to not-exploited within a day, and ENISA's exploited feed still says otherwise two days later
- Kairos claims 77.6 GB from a second Madrid-region municipality in three months, and the town hall confirms a security incident while stating it cannot yet confirm that any data was actually accessed or taken
- SPIP shipped two emergency releases in three days, each fixing an unconditional pre-authentication RCE the vendor says is already being exploited, and only the first one has a CVE
- Zoomsday; the Zoom client build that closes the first two annotation flaws leaves the third open, and the national advisory that raised the alarm covers only one of the three
- Thirteen CVEs in ATutor, none of which will ever be fixed, including an unauthenticated auto-login token forgery that authenticates as any account, administrators included
- DOJ's superseding indictment against Iran's Mabna Institute names Switzerland twice; among the countries whose universities were compromised, and among those whose companies had employee mailboxes taken
- Spain's Castilla-La Mancha regional government confirms a cyberattack after the Panzer extortion group lists it; the government confirms the intrusion, not the group's data claims
- Latvia's vehicle-registration authority lost payment records on two-thirds of the country's population, and the provider contractually watching its infrastructure round the clock did not notice
- Grandoreiro's loader decides it is in a sandbox when it finds seven ordinary desktop shortcuts, an inverted environment check, behind a two-hop DLL sideload
- Oracle's August 2026 Critical Security Patch Update carries three unauthenticated CVSS 10.0 flaws, one of them in the LDAP server of Oracle Internet Directory
- CVE-2026-73570, Zimbra Collaboration: a pre-auth command injection patched without a CVE in July is now recorded as actively exploited, four weeks after the fix shipped
- CVE-2026-19490, Citrix NetScaler: an authentication bypass on Gateway and AAA virtual servers (CVSS 9.3), and on older builds no SAML configuration is needed to be exposed
- PurpleDelta: Insikt Group gets inside a North Korean IT-worker operation and finds the detectable half is on the endpoint, a second remote-management tool on the company laptop, and a device whose location never matches the login
- StopAndProtect runs its whole operation off other people's WordPress sites, a must-use plugin that never appears in the plugin list, a hidden REST route that accepts PHP, and an installer that deletes itself
- CVE-2026-15826, User Profile Builder: a 61-to-70-character username makes WordPress return an error object, absint() turns it into the integer 1, and the plugin logs the caller in as user ID 1 (CVSS 9.8)
- CVE-2026-15748, Forminator Forms (600,000+ WordPress sites): a forged Select-field value overrides the upload allow-list, and the root cause went public seventeen days after the patch (CVSS 9.8)
- Medusa's joint advisory update puts a number on the patch race: affiliates weaponise newly announced flaws within 24 hours, and the agencies find no sign the group develops any of them itself
- CVE-2026-18963; Keycloak's password-reset flow can be driven to completion without the verification email being clicked, handing an unauthenticated attacker any account including administrators (CVSS 9.1)
- CVE-2026-19478; GitLab ships an out-of-band critical patch for a GraphQL directive flaw that lets an unauthenticated caller modify or delete public projects and user data (CVSS 9.4)
- Arbeiterkammer Oberösterreich cannot scope its own breach because the attackers wiped the traces, so every member is being notified under Article 34 as a precaution
- Zurich District Court opens the LockerGoga / MegaCortex / Nefilim trial: four named Swiss victims, CHF 100m+ in damage, and an indictment that describes the intrusion pattern step by step
- CVE-2025-62593; Ray's dashboard is defended against browsers by a User-Agent string check, and CISA now records the DNS-rebinding bypass as exploited
- Evooo1Bot: a Mirai-derived Linux botnet whose exploit arsenal reaches Confluence, WSO2 and Kubernetes ingress-nginx, and whose SSH dictionary is stocked with enterprise service accounts rather than router defaults
- CVE-2026-71362, Adobe Commerce and Magento Open Source: an unauthenticated attacker switches a customer session to another customer's account (CVSS 9.1), and a WAF vendor reports it is already blocking attempts
- The '2,500-organisation LiteLLM breach' was mostly not LiteLLM: 95% of the identified victims were collected before the poisoned packages existed, through the Trivy scanner their pipelines pulled unpinned
- CVE-2026-26035, FortiWeb: one non-default RADIUS admin setting turns any username and password into a valid GUI/CLI login, alongside an FGFM impersonation bug and a FortiClient flaw reachable by anyone who can answer a laptop's DNS
- Threema and its Swiss colocation partner were hit by the same adaptive DDoS wave, the attack moved to the hosting layer, and only the self-hosted customers stayed up
- NHS Blood and Transplant sent organ-offer messages naming recipients over an unencrypted pager network, and because pager broadcasts leave no receiver log, it cannot scope who received them
- France's tax authority cut the intruders' accounts in June and July and found no data theft, it took the criminal's sale listing two months later to establish that 678,000 records had already gone
- GeoServer: an unauthenticated SQL injection in the jsonArrayContains filter is being exploited with no CVE and no patch, and NCSC-CH has put it in front of Swiss operators
- WindRelay, a purpose-built Android NFC-relay malware installed silently by a companion remote-access trojan during the fraud call itself, with per-victim app names carrying the victim's own name
- UK ICO reprimands the national criminal-records office over a seven-month website compromise; outsourced patching with no internal owner was the cause, and network segmentation is what capped the damage
- MyDr, a Polish electronic health record platform serving thousands of clinics, confirms a deliberate criminal intrusion, and because it is a processor, not a controller, the people affected cannot be told directly
- CVE-2026-58115; Siemens SIMATIC IoT2050 Advanced ships a Node-RED interface with no authentication, so one unauthenticated HTTP request runs code as root on an OT edge gateway (CVSS 10.0)
- A German federal- and state-funded memorial foundation is rebuilding its entire IT from scratch after ransomware, all seven sites offline, data assumed exfiltrated, no actor named
- ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 2025
- CVE-2026-20349, Cisco Secure Firewall ASA/FTD: one crafted HTTP request to the Remote Access SSL VPN reloads the device, exploitation confirmed, no workaround and a three-day KEV deadline
- CVE-2026-58231, SAP Commerce Cloud: an unauthenticated request to the Data Hub Adapter import endpoint reaches arbitrary code execution (CVSS 10.0), and the fix needs a rebuild and redeploy
- Lazarus burned a Windows AFD.sys zero-day (CVE-2026-68820) on European defence targets, FudModule v3.1 blinds the endpoint, and the C2 is other people's Roundcube and WordPress servers
- One compromised contract-logistics processor put ten organisations into breach notification at once, CEVA Logistics, eight European warehouses, and a bank, a retailer and a games platform all learning from their supplier
- Belgium's eID signing extension handed any web page the card, the PIN and a drive-by RCE, an eIDAS Qualified Trust Service Provider's browser bridge that never checked the caller's origin
- Gunra ransomware-as-a-service: a joint six-agency advisory documents FortiOS edge exploitation, a persistent MFA backdoor built from one fixed OTP value, and a Linux encryptor whose keys can be reconstructed
- Qilin compromised Italian telecommunications and cloud operator Retelit on 8 June, the company confirmed it only after an investigation forced the question, and one of the three affected data centres was its certified backup site
- Coding-agent CI harnesses broke on the same trust boundary three different ways, and the two findings that matter most carry no CVE at all
- Linux kernel bridge STP timer use-after-free, a control-flow hijack primitive with a published exploit, no CVE, and no confirmed stable backport
- NatJack, sharing a NAT table is a trust relationship nobody declared: five named primitives against NAT state, of which only the downstream TCP hijack got a CVE on each platform
- Żabka confirms an external service-provider account reached its ticketing system; the claimed pivot from Jira into source control and production is the seller's assertion, not the company's
- CERT Intrinsec maps where autonomous coding agents leave evidence on disk; the same session databases and token files an investigator needs are a credential-collection target
- An intruder used pam_rootok to move between low-privileged identities as a deliberate forensic smokescreen, inverting what a responder infers from the authentication trail
- CrowdStrike catalogues 21 working command-obfuscation techniques inside VMware ESXi's BusyBox ash shell, and shell logs record the command before expansion, so the logged string is not what ran
- Interlock ran Volatility3 and WinPmem against a live endpoint to harvest credentials, the responder's own memory-forensics toolkit used in place of a commodity dumper
- FreeBSD CTL HA, three independent pre-authentication remote kernel-code-execution primitives behind an unauthenticated failover port, and the project's answer is a manpage warning rather than a patch
- CVE-2026-64638 (XSS2Shell), WordPress Core: a sanitiser disagreement on the login screen chains through DOM clobbering and a JSONP callback into administrator-minted Application Passwords and plugin upload
- Wazuh 4.14.6, two cluster-protocol paths to root that bypass the CVE-2026-25770 fix, a DAPI deserialization RCE, and a pre-auth stack overflow on the enrollment port
- CVE-2026-71851, crypto-js below 4.0.0 generates 'random' values with about 2^39 of real entropy, and attackers were draining wallets built on it while the investigation ran
- WALLIX Bastion's REST API hands full appliance administration to an unauthenticated caller (CVSS 4.0 10.0), the credential vault and session recordings included, with public technical details due in September
- Metabase: an unauthenticated SQL-injection zero-day gave attackers administrator access to BI instances, exploited since 3 August, and no CVE was ever assigned
- CERT Polska: a second Polish CHP plant was shut down on 29 December 2025 through the distribution operator's private APN, the first real-world use of that path into an OT network
- Beacon CRM tells around 1,500 UK charities to assume everything they stored was taken, a compromised access key, exfiltrated backups, and encryption its experts think the attacker could undo
- CVE-2026-65400, macOS Screen Sharing lets a network attacker authenticate without valid credentials, the second severe defect in the same daemon in two releases
- A Flemish Government agency confirms a DPRK compromise reached it through a contractor's workstation, one of 1,640 organisations a researcher counted from inside the actors' own servers
- UNC6671 kept operating after BlackFile's announced retirement, across four further extortion brands, and its vishing pretext is now an urgent order to enroll a FIDO2 passkey
- CVE-2026-16443, Keycloak: importing SAML metadata without key-usage attributes silently disables response signature validation, so an unauthenticated attacker forges a login as any known user
- Adobe Campaign Classic APSB26-120, three more unauthenticated CVSS 10.0 code-execution flaws, and last week's build 9398 is the version they affect
- Traefik 3.7.10 / 3.6.25 / 2.11.54, a route identity built by joining names with hyphens lets one Kubernetes namespace silently take over another's traffic on a shared Gateway
- CVE-2026-17583, Thermo Fisher Applied Biosystems genetic analyzers write DNA result files with no integrity checking, so results can be altered after the run and no vendor fix is offered
- Phishing kits are registering browser service workers to build in-page transparent proxies, relaying credentials and live MFA codes from a fake browser window on trusted cloud hosting
- ByteToBreach hits Hungary's State Treasury after Romania's land registry; the reported entry point is an Oracle WebLogic server left unpatched since a 2017 patch cycle
- CVE-2026-34486, Apache Tomcat: the fix for an earlier EncryptInterceptor flaw reintroduced a bypass, and CISA's KEV listing lands months after a China-nexus campaign was already exploiting it
- CVE-2026-18574, Check Point Security Management: unauthenticated bypass of management authentication to arbitrary command execution, with no fix for seven end-of-support trains
- Switzerland's federal IT provider BIT confirms a SharePoint Server intrusion: ~200 federal user and technical accounts compromised while the July patches were already being installed
- Liechtenstein's beneficial-ownership register breached: copies of ~31,000 legal entities' records taken, and four more e-government systems pulled offline as a precaution
- BSI and NCSC-NL withdraw SQLite advisories built on LLM-fabricated CVEs, and GitHub's advisory database was still serving one of them
- CVE-2026-18556 / CVE-2026-18577, N-able N-central: unauthenticated admin access to the RMM console, exploited in the wild, and the day-one fix was itself bypassable
- CVE-2026-7849 and 19 more, Phoenix Contact CHARX SEC-3xxx EV charging controllers: unauthenticated command injection as root, unsigned firmware updates, and no fix released at disclosure
- CVE-2026-48449, Adobe Campaign Classic: an authorization flaw gives unauthenticated arbitrary code execution (CVSS 10.0), on-premise and hybrid deployments only
- CVE-2026-65766 and CVE-2026-65879, SP Page Builder for Joomla: a CSRF token Joomla hands to anonymous visitors is the only guard on an ORDER BY injection, plus a shipped-in-source shared secret that opens a mail relay
- CCI Nice Côte d'Azur: a compromised administrator account on the chamber's jobseeker platform was used to run the platform's own export function
- Adform: the shared tracking script every customer site embeds was trojanised with a clipboard-rewriting crypto-clipper, and no antivirus engine flagged it
- CVE-2026-65883, Aimy Captcha-Less Form Guard for Joomla: the anti-spam token is deserialized before any check, and the XOR keystream ships in the same page (CVSS 9.8)
- French Éducation nationale: a hijacked staff account reached the agent-training system, exposing identity and NIR data for everyone who has worked in an académie since 2001
- CaptiveCrunch: an SVR-linked sub-cluster hijacks hotel and conference captive portals to serve fake update lures, a Go RAT and a token-stealing PowerShell module to travelling staff
- Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory, the confirmed compromises came from manual Citrix NetScaler exploitation (CVE-2026-3055), not the agent
- UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad, a five-day-old extortion brand whose other 14 claims look fabricated
- CVE-2026-66066, Ruby on Rails Active Storage: an unauthenticated image upload reaches arbitrary file read through libvips' unfuzzed loaders, exposing every application secret (CVSS 4.0 9.5)
- VMSA-2026-0006, VMware vCenter: unauthenticated Directory Service auth bypass and Syslog traversal RCE (both CVSS 9.8), plus a VMXNET3 guest-to-host escape
- Romanian public university UVVG Arad confirms a cyberattack on its IT infrastructure; a Qilin leak-site listing is the only thing linking an actor to it
- Coordinated two-day cyberattack disrupts operational technology at 30+ Minnesota water and wastewater utilities; no authority has attributed it
- LegacyHive: a public Windows technique that redirects a profile's Local AppData into the NT Object Manager namespace via offline hive edits, reproduced on fully patched systems
- CVE-2025-15467, Siemens Desigo CC: a vendored OpenSSL CMS parsing overflow gives pre-auth code execution, and the V7 family still has no fix (CVSS 9.8)
- Chat Control backlash turns operational: a hacktivist compiles targeting dossiers on French and EU officials out of old breach data, not a new intrusion
- Oracle July 2026 CPU, nine unauthenticated CVSS 10.0 flaws in Fusion Middleware, with NCSC-NL assessing large-scale abuse as very likely in the short term
- CVE-2026-61425, Balbooa Gridbox for Joomla: a client-supplied cookie is accepted as proof of identity, giving anonymous Super User access
- TA458 / Operation RoundPress: a running supply of half-click webmail zero-days adds a fresh SOGo flaw (CVE-2026-8496)
- Swiss autism-support foundation Stiftung Autismuslink confirms data-theft cyberattack; INC Ransom claims it
- MZ Automation libIEC61850: unauthenticated heap-overflow RCE via crafted MMS Initiate (CVE-2026-49035) plus four sibling OT-library flaws
- Mitel MiCollab AWV: unauthenticated command injection to full system compromise (CVSS 9.8, MTLVULN-1694, CVE pending)
- Russian state actor LAUNDRY BEAR weaponised a Zimbra webmail zero-click (CVE-2025-66376) for mailbox exfiltration, now exposed in a 16-nation joint advisory
- German BKA dismantles Kratos, the Sneaky2FA-derived AiTM phishing-as-a-service platform behind ~15,000 monthly Microsoft 365 credential-theft campaigns
- US agencies expand the Iranian PLC-intrusion advisory (AA26-097A) to Schneider Electric and Siemens controllers, with new project-file tampering detection
- BravoX ransomware leaks 220 GB from a Vaud fiduciary, exposing ~15 municipalities' data and a cantonal minister's tax file
- GLPI 11.0.8 / 10.0.26, critical RCE via form import and complete MFA bypass in the public-sector ITSM platform
- CVE-2026-0770, Langflow: CISA confirms active exploitation of an unauthenticated exec_globals RCE the same day a 15-CVE batch (incl. unauthenticated account creation) is patched in 1.10.1
- Everest ransomware breaches a Stadler Rail supplier data-exchange platform, demands CHF 10 million, the Swiss rail manufacturer refuses to pay
- CERT-UA: Sandworm subcluster UAC-0145 pairs ClickFix fake-CAPTCHA with Ethereum-smart-contract C2 resolution and a Signal-delivered Android backdoor
- Romania's national cadastre agency ANCPI hit by a multi-day cyberattack; ByteToBreach claims citizen-data and e-Terra source-code theft plus ransomware
- ClickLock Stealer, a macOS ClickFix infostealer that force-kills every visible app until the victim types their login password
- Moodle local_o365 plugin: unverified JWT signature on the Teams SSO endpoint lets anyone authenticate as any user (CVE-2026-54733)
- WP2Shell: pre-auth RCE chain in stock WordPress core (CVE-2026-63030 + CVE-2026-60137), out-of-band 7.0.2 patch, exploitation expected short-term
- CVE-2026-47865, VMware Avi Load Balancer: unauthenticated control-plane authentication bypass (CVSS 9.8), no workaround
- CVE-2025-40948/-40947/-40949, Siemens RUGGEDCOM ROX II: Unit 42 chains three OT-switch flaws to persistent root
- TheGentlemen ransomware hits Portugal's Metro Mondego (Coimbra light-rail); operator confirms attack, notifies CNCS and CNPD
- Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records
- Cisco Talos: UAT-11795 deploys the Python-based Starland RAT and a bespoke PowerShell C2 implant (WLDR), resolving fallback C2 through a Polygon blockchain dead-drop
- Garante fines Wind Tre EUR 1.7M over a vishing-enabled API-enumeration breach that exposed 365,048 telco customers
- CVE-2023-4346, KNX building-automation protocol: account-lockout DoS added to CISA KEV, no software patch (CVSS 7.5)
- DragonForce lists Geneva's IFAGE adult-education foundation on its leak site, claiming 850 GB; an attribution and volume IFAGE has not confirmed
- CVE-2026-15409, SonicWall SMA1000: unauthenticated SSRF (CVSS 10.0) chained to post-auth code injection, actively exploited
- SAP July 2026 Security Patch Day: three CVSS ≥9.1 flaws in NetWeaver AS ABAP, Approuter and Commerce Cloud, two reachable without authentication
- Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days, AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)
- AIVD/MIVD: Russia-linked actors hijack default-credential IP cameras along NATO military-supply routes to monitor Ukraine-bound shipments
- CVE-2026-4769, WAGO I/O System Field: undocumented early-boot interface allows unauthenticated full compromise (CVSS 9.8)
- Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat', day three, no patch or root cause disclosed
- FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions
- Progress MOVEit Transfer: pre-auth SFTP DoS (CVE-2026-10699), admin table-scope bypass (CVE-2026-10698) and stored XSS (CVE-2026-11903), patched 2026.0.2
- Joomla file-upload RCE wave adds RSFiles! (CVE-2026-57827, unauth, CVSS 10.0) and Phoca Download (CVE-2026-57828, CVSS 9.0)
- NHS England issues insider-access controls after staff 'snooping' on high-profile patients' records
- Zimbra Classic Web Client: crafted-email code execution fixed in ZCS 10.1.19, surfaced by NCSC-CH (no CVE, exploitation unknown)
- Siemens SICAM 8 (A8000/EGS/S8000) grid RTUs: firmware-signature-validation bypass + OPC-UA-off-by-default among four CVEs (SSA-229470)
- CVE-2026-48939, iCagenda for Joomla: unauthenticated file-upload-to-RCE, exploited as a zero-day, added to CISA KEV (CVSS 4.0 10.0)
- ShinyHunters' Odido (NL telecom) breach: Dutch police voice analysis points to Dutch-national involvement; same vishing-into-spoofed-portal playbook, now against an EU telco
- Nextcloud GmbH's own hosting infrastructure exposed 367K internal records via a misconfigured public Elasticsearch cluster, including client setup scripts with hardcoded credentials
- CERT.LV: ransomware crew breaches Latvia's state forestry operator LVM via a 2-year-unpatched system, hits essential-services provider Olpha, and is probing other EU/NATO institutions
- UNK_MassTraction: suspected China-aligned actor exploits Roundcube as an edge device, chaining CVE-2024-42009 XSS into CVE-2025-49113 deserialization
- Deutsche Bank confirms a third-party vendor incident after 'Unsafe' ransomware group posts alleged employee data
- CERT Polska: UNC1151/Ghostwriter shifts to Gmail with real-time 2FA-relay phishing against officials and public administration
- Nayax (Bank-of-Lithuania-licensed EEA payment institution) discloses a cloud-account incident; "The Syndicate" claims 1B card records, claim unverified and contradicted by the filing
- Mandiant "Ghost in the Database": recovering an active ADFS token-signing key from Machine DPAPI when the WID/DKM Golden SAML path fails
- ESET Threat Report H1 2026: first Android malware using generative AI at runtime, ClickFix detections more than double, record QR-phishing, 100+ EDR-killers
- CVE-2026-53359, Linux KVM/x86 "Januscape": shadow-MMU use-after-free enables guest-to-host VM escape on Intel and AMD
- CVE-2026-48614, Plesk XML API code injection: authenticated low-privilege user to root (CVSS 9.9)
- Unit 42: Factory-v3 loader-builder abuses fraudulent code-signing and 491 MB file inflation to smuggle Vidar and XMRig past sandboxes
- Ubiquiti UniFi SAB-066, 25 vulnerabilities incl. unauthenticated CVSS 10.0 command injection in UniFi Connect (CVE-2026-50746)
- CVE-2026-59509, cve-search: unauthenticated /fetch_cve_data parameter manipulation exposes admin credential hashes (CVSS 9.2)
- Citizen Lab: a European Parliament spyware-inquiry member was himself infected twice with Pegasus
- CVE-2026-14439, Altium Enterprise Server / Altium 365: authenticated path-traversal to RCE
- CVE-2026-45659, Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed
- Oracle E-Business Suite CVE-2026-46817: pre-auth RCE in the Payments File Transmission servlet, first in-the-wild exploitation
- CVE-2026-8451, Citrix NetScaler ADC/Gateway: pre-auth SAML memory overread (CitrixBleed lineage), public PoC
- Mustang Panda abuses Zoho WorkDrive as a dead-drop C2 channel (ZOHOMURK) against government and energy targets
- CERT Polska discloses a JAR parser-confusion RCE in the SzafirHost e-signature client (CVE-2026-13165)
- Keycloak JWT algorithm confusion (CVE-2026-11800): forging federated identity in the EU public sector's dominant IdP
- Island: "BadBlocker"; an 11M-user Chrome ad-blocker is one server config change away from arbitrary JavaScript on any site
- Netcraft: Bluekit PhaaS uses Browser-in-the-Middle to defeat FIDO2 and Device Bound Session Credentials
- CVE-2026-58053, Gitea act_runner Docker backend: container-hardening bypass to host escape (CVSS 9.4, public PoC)
- NYT investigation gives first named attribution for the Jaguar Land Rover ransomware attack, a Russian state-linked criminal group
- NAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pause
- Turla's STOCKSTAY: a four-component .NET backdoor for diplomatic intelligence collection
- "The Gentlemen" ransomware claims 478 victims and adds worm propagation, Switzerland the second-most-targeted European country
- Citizen Lab: Cellebrite UFED used by Russian authorities three months after the vendor's Russia pull-out
- Kaspersky GReAT: "StrikeShark" loader deploys Cobalt Strike via "Perfect DLL Hijacking" against government targets
- Microsoft: "Photo ZIP" phishing laundered through Calendly drops Node.js TonRAT against European hospitality front desks
- UK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach, 160 universities, ShinyHunters extortion, ransom paid
- FBI/CISA: Russian intelligence now phishing Signal Backup Recovery Keys for persistent account takeover
- ESET's 2025 Gamaredon paper: exfil and C2 moved wholesale onto trusted cloud services (ANNUAL REPORT)
- Ukrposhta digital services disrupted by an overnight attack; pro-Russian hacktivists claim a prior data theft
- CVE-2026-56447, CVE-2026-56446, CVE-2026-56425, CVE-2026-56424, CVE-2026-56423, CVE-2026-56422, MISP 2.5.42: two site-admin RCE paths plus Azure-AD auth and broken-access-control hardening
- Operation Endgame dismantles the Amadey and StealC malware-as-a-service backbone
- Ubiquiti UniFi OS triple-flaw chain to unauthenticated root (CVE-2026-34908 / -34909 / -34910)
- CVE-2025-67038, Lantronix EDS5000 serial-to-IP converter: unauthenticated OS command injection to root, first BRIDGE:BREAK flaw added to CISA KEV
- WhatsApp-borne VBScript silently installs a ManageEngine RMM agent for living-off-the-land remote control
- SonicWall CVE-2024-40766: why patched firewalls keep falling to Akira and Fog
- Elastic shows how the newly-GA Azure AD Graph Activity Logs close a long-standing Entra enumeration blind spot
- "Squidbleed", a 29-year-old heap over-read in Squid's FTP gateway leaks other users' cleartext HTTP credentials (CVE-2026-47729)
- CVE-2026-12789, ILIAS 11.0: unpatched, PoC-public SQL injection in the learning-progress subsystem (DACH education exposure)
- CVE-2026-20896, Gitea (Docker): trust-all reverse-proxy default lets an unauthenticated attacker impersonate any user via X-WEBAUTH-USER
- Two Scattered Spider members plead guilty over the 2024 Transport for London intrusion
- ShapedPlugin build pipeline compromised, three Pro WordPress plugins backdoored to steal credentials, 2FA secrets and drop a web shell
- AryStinger: a reconnaissance-and-proxy botnet built on end-of-life D-Link routers and QNAP NAS
- eBanking phishing hides its landing-page address in IPv4-mapped IPv6 notation to slip past URL scanners
- Brazil's national Cell Broadcast alert platform hijacked to push fake "Extreme Alert" messages to ~30M phones
- Prinz Eugen: a Go-based encryptor that targets recent files first and leaves no ransom note
- Klue OAuth-token breach, victim list grows, CRM-API abuse chain detailed
- HCRG Care Group first notifies patients of a February 2025 Medusa breach, 16 months on
- UK Information Commissioner resigns with immediate effect, regulator left leaderless mid-restructure
- PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane
- CVE-2026-52806, Gogs self-hosted Git server: argument injection to OS command execution (BSI critical batch)
- CVE-2026-40624, AVer PTC-series conference cameras: unauthenticated RCE via the management web interface
- Cisco ISE CVE-2026-20181 + CVE-2026-20190: an unauthenticated credential-harvest primitive feeding authenticated root code execution on the identity plane
- ESET: the Gentlemen RaaS gang centrally builds and maintains its affiliates' EDR-killer framework
- CVE-2026-55803 / CVE-2026-55804, Drupal core: PHP object-injection chain in JSON:API, BSI-rated critical
- CVE-2026-42530 / CVE-2026-42055, NGINX: HTTP/3 QUIC use-after-free and HTTP/2-proxy heap overflow, out-of-band F5 patches
- CVE-2026-12046 / CVE-2026-12045 / CVE-2026-12048, pgAdmin 4: unauthenticated pickle deserialization RCE, AI-Assistant read-only-transaction bypass, stored XSS
- CVE-2026-20181 / CVE-2026-20190, Cisco Identity Services Engine: unauthenticated credential read chaining to authenticated root command execution
- UK ICO issues criminal caution to London Clinic insider over Princess of Wales medical-record access
- Operation Endgame expands to SocGholish/TA569, 106 C2 servers down, FakeUpdates loader stripped from 14,971 WordPress sites
- 15 malicious JetBrains Marketplace plugins exfiltrate AI provider API keys on "Apply"
- BSI flags 13 vulnerabilities patched in Zammad 7.1, admin privilege escalation in a DACH public-sector helpdesk platform
- CVE-2026-0647 et al. Rockwell Automation FLEX I/O unauthenticated password reset (CVSS 9.4) and Logix CIP denial-of-service, flagged by NCSC-CH
- ScarCruft (APT37) delivers NarwhalRAT behind fake Microsoft OTP "security alert" lures
- FortiBleed, 73,932 internet-facing FortiGate devices exposed, Russian-speaking group cracking credentials into Active Directory
- Zimperium: Rokarolla Android banking trojan targets 217 apps with full device takeover
- Sekoia: ErrTraffic, a ClickFix Malware-as-a-Service framework resolving C2 through the Polygon blockchain
- Munich: ~120,000 student records suspected on the darknet, terminated employee under investigation
- CVE-2026-48611 / CVE-2026-48612, phpBB: unauthenticated authentication bypass to admin, one HTTP request
- DPRK UNK_DeadDrop weaponises VS Code / Cursor auto-run to hit developers, including EU targets
- PRC UNC6508 ran year-plus espionage through internet-facing REDCap servers and a Google Workspace BCC rule
- Handala breaches California Water Service through an internet-exposed RTKBase GNSS platform, billing PII for ~2M customers leaked, no OT access
- Sekoia: APT28 (GRU Unit 26165) tradecraft shifts to LLM-generated payloads and cloud-native C2
- CVE-2026-20253, Splunk Enterprise: unauthenticated pre-auth RCE via the PostgreSQL sidecar proxy
- Conti loader developer Oleksii Lytvynenko pleads guilty in US federal court after extradition from Ireland
- Cyber Europe 2026 tests the revised EU Cyber Blueprint and triggers the first live activation of the EU Cybersecurity Reserve
- Google sues China-based "Outsider" PhaaS network for weaponising Gemini to mass-produce phishing pages
- CVE-2026-48558, SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician session
- Novo Nordisk discloses theft of clinical-trial and healthcare-professional data
- MariaDB CVE-2026-49261: Galera wsrep_notify_cmd shell injection (CVSS 10.0)
- CVE-2026-25089, Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)
- The Gentlemen ransomware: 478 claimed leak-site victims, self-propagating Go encryptor, operator publicly named
- AudiA6 ransomware crypto-laundering service dismantled, two charged, Switzerland among the participating countries
- ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration
- Windows Netlogon RCE CVE-2026-41089 now confirmed exploited in the wild in the EU; CERT-EU issues advisory 2026-007
- EDPB adopts a harmonised GDPR Article 33 breach-notification template; consultation open to 5 August
- Dragos Q1 2026 Industrial Ransomware Analysis: 1,020 industrial incidents, The Gentleman's 4× surge against Romanian energy, and the IT-adjacent intrusion pattern
- EU Cyber Resilience Act reaches its first hard deadline, notifying-authority designation due 11 June
- Year-old WinRAR flaw (CVE-2025-8088) still fuels Ukraine intrusions, GIFTEDCROOK via UAC-0226 and an Earth Dahu chain
- CVE-2026-47344 et al. TYPO3 core June release: 13 CVEs across every supported branch (10.4 ELTS → 14.3 LTS)
- CVE-2026-47895, strongSwan: pre-auth double-free in libstrongswan identity cloning, unauthenticated RCE over EAP (patched 6.0.7)
- CVE-2026-44748, SAP June Patch Day: SAML XML Signature Wrapping in NetWeaver AS ABAP (CVSS 9.9) plus an unauth RFC kernel memory-corruption (CVSS 9.8)
- CVE-2026-10520 / CVE-2026-10523, Ivanti Sentry: pre-auth OS command injection to root (CVSS 10.0), public PoC published today
- "Ghost-Sender": Exchange Online accepts spoofed inbound mail bypassing SPF/DKIM/DMARC when a third-party MX fronts the tenant, no vendor patch
- France's Tchap government messenger breached via account takeover, 73,467 civil servants' metadata scraped, CNIL notified
- CVE-2026-50751, Check Point Security Gateway: IKEv1 VPN authentication bypass, actively exploited by a Qilin affiliate
- Meta files contempt complaint against NSO Group over fresh WhatsApp spyware phishing
- Oxford University CareerConnect (Group GTI) breach exposes students at multiple UK universities
- FortiGuard documents C0XMO, a cross-platform Gafgyt variant propagating through a five-year-old DD-WRT UPnP flaw
- CVE-2026-49200 / CVE-2026-49201, Acer Wave-7 mesh routers: cleartext-credential log + hardcoded backup key, CVSS 10.0, no patch
- FIFA World Cup 2026 pre-event threat cluster: Android banking trojans in pirated streaming apps, plus a 13,000-domain fraud layer, ahead of the 11 June kick-off
- Keycloak 26.6.3: privilege escalation via OAuth token-exchange and SSRF in the EU public sector's reference identity platform
- Magecart family runs its skimmer out of Stripe, payload in customer metadata, stolen cards exfiltrated back through api.stripe.com
- OP-512: China-linked cluster runs a cryptographically-unique, self-reporting IIS web-shell framework against legacy .NET servers
- CVE-2026-10868, MISP: critical mass-assignment account-takeover in the EU threat-sharing platform
- University of Toronto / Vector Institute: a self-propagating worm that runs open-weight LLMs on compromised hosts to synthesise per-target exploits
- CVE-2026-34906 / CVE-2026-34907, Simple SA "Wirtualna Uczelnia": unauthenticated SSTI-to-RCE in the student-administration platform used across Polish public universities
- Unit 42 Operation FlutterBridge: notarized macOS backdoor hides its logic in a remote WebView and exfiltrates documents through an "AI summarise" feature
- Proofpoint TA4922: a China-nexus cybercrime cluster expands from Japan into Germany, the UK and Italy with native-language lures and DLL-side-loaded Atlas RAT
- VerdantBamboo (UNC5221 / WARP PANDA): an 18-month China-nexus intrusion that lived entirely on EDR-blind edge appliances and proxied into Microsoft 365 past Conditional Access
- CVE-2026-10611, MISP: OTP bypass when LDAP mixed-auth and OTP enforcement are both enabled
- CVE-2026-20230, Cisco Unified Communications Manager: unauthenticated SSRF to OS-root file write
- Shared booking-software breach exposes guests at 100+ Dutch, Belgian and Irish hotels; phishing wave already underway
- NCSC Switzerland: Booking.com breach feeds two-pronged WhatsApp hotel-booking phishing against Swiss travellers
- Operation XENOFISCAL: SideCopy (APT36) hits provincial treasury officials with XenoRAT via an mshta/HTA chain
- CVE-2024-21182, Oracle WebLogic Server: unauthenticated T3/IIOP data access, KEV-listed on active exploitation
- NCSC Switzerland warns of cyber operations around the G7 Évian summit (15–17 June)
- Operation Dragon Weave: China-nexus espionage against Czech government with Azure Blob Storage dead-drop C2
- Sekoia consolidates Gamaredon tooling under GammaPhish / GammaWorm, details an NTFS-ADS USB+network worm
- CVE-2026-8931, Disig Web Signer: critical RCE in a Slovak electronic-signature client
- Spain arrests doxer who published personal data on INCIBE, prosecutorial and security-service staff
- Italy's low-cost commercial spyware economy: Accessibility-API abuse as the cheap alternative to zero-days
- SmartApeSG ClickFix stages an unnamed RAT that pivots to a weaponised NetSupport Manager
- Mautic 7.1.2 / 6.0.9, seven authenticated flaws, including two post-auth RCE paths (SSTI and path-traversal-to-PHP-RCE), an SSRF and an API authorization bypass
- Kimsuky (Velvet Chollima) deploys HTTPSpy RAT and Rust-based HelloDoor via VS Code Remote Tunnel and Cloudflare Quick Tunnel C2
- ESET APT Activity Report Q4 2025–Q1 2026: Sandworm strikes NATO energy, Lazarus targets EU drone sector, UNC5221 pivots to Ivanti SPAWN toolset
- CVE-2026-0257, Palo Alto PAN-OS GlobalProtect: Pre-Auth Authentication Bypass via Certificate Reuse
- GREYVIBE, newly documented Russia-nexus cluster deploys five parallel attack chains against Ukraine with AI-generated lures and two PowerShell RATs
- Ghost Stadium PhaaS, 300+ FIFA domain clones, multi-language fake SSO, targeting UK/Germany/Portugal/Spain fan credentials before June 11 kickoff
- CNIL fines IQVIA Operations France €5M for health data warehouse security failures: no MFA, no log monitoring, no network segmentation
- FortiClient EMS CVE-2026-35616 + EKZ Infostealer kill chain
- The Gentlemen ransomware, Microsoft publishes full technical dissection of the Storm-2697 Go-encryptor
- WatchGuard documents Grandoreiro's Delphi-DLL-side-loading + WebSocket/STUN C2 against Portuguese & Spanish banks; ESET maps parallel Android BTMOB MaaS
- Wiz CIRT names JINX-0164, LinkedIn-recruiter lures, AUDIOFIX macOS infostealer, MINIRAT npm pivot into CI/CD
- CVE-2026-32996 & CVE-2026-32997, Veeam Backup & Replication KB4852: LPE in Windows Agent, arbitrary file write in Linux appliance
- CVE-2026-4868 (+ five further CVEs), GitLab 19.0.1 / 18.11.4 / 18.10.7 patch release: Duo AI identity impersonation, unauthenticated project enumeration
- CVE-2026-9170, IBM HTTP Server / WebSphere Application Server: pre-auth RCE via improper input validation (CVSS 9.8)
- CVE-2026-44848 & CVE-2026-44849, Portainer CE: Docker plugin endpoints unguarded; Swarm-service security checks bypassed (CVSS 9.4)
- CVE-2026-44939 (+ CVE-2026-41052, CVE-2026-41053), SUSE Rancher: command injection on cluster import, PSA label privilege-escalation, GitHub-App over-inclusive team membership
- CVE-2026-4408 & CVE-2026-4480, Samba: unauthenticated RCE in SAMR RPC and print-command subsystems (CVSS 10.0)
- TechCrunch finds 100 K passport scans and selfies on a public-read S3 bucket behind a UK Visa Portal lookalike
- Dutch Police + NCSC dismantle Asocks residential-proxy botnet (~17 M devices, 200 NL-hosted servers seized)
- Carnival Corporation confirms 5.99 M-record ShinyHunters breach, passport + driver's-licence numbers exposed across four cruise brands
- Rapid7 publishes unpatched Gogs argument-injection RCE with a Metasploit module; maintainer non-responsive
- FortiClient EMS CVE-2026-35616 actively exploited to push EKZ Infostealer through trusted endpoint-management channel
- Apereo CAS version 7.3.7.1 patches an OIDC-provider flaw reported by Coop Switzerland; CERT-FR issues advisory CERTFR-2026-AVI-0654
- Nx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entries
- MuddyWater / Seedworm, Symantec and Carbon Black document new DLL-side-loading pair via signed Fortemedia and SentinelOne binaries, ChromElevator for Chromium App-Bound Encryption bypass, Node.js orchestration
- CVE-2026-35087 / CVE-2026-35089 / CVE-2026-35090, Slican PBX telephony exchanges, triple pre-authentication admin bypass (CERT Polska)
- CVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)
- FBI FLASH CSA 260526, Silent Ransom Group sends operatives physically into US law-firm offices to insert USB exfiltration devices when remote social engineering fails
- Dutch National Police arrest 35-year-old over AFC Ajax fan-data breach, misconfigured API access-control and shared keys exposed 300,000+ accounts and 42,000 season-ticket records
- CrowdStrike, Google and Shadowserver simultaneously sever all four C2 channels of the GlassWorm developer-targeting botnet (not to be confused with the Nx Console / TanStack GitHub-publish chain in § 5), Russia-attributed, active since early 2025
- Germany's federal cabinet approves the Cybersicherheitsstärkungsgesetz, BKA, BSI and Federal Police gain authority to redirect traffic and disable attacker infrastructure
- ILIAS LMS, nine fixes shipped 2026-05-27, two critical access-control gaps (CVSS 9.8 + 9.3), NCSC.ch flags SOAP interface as primary unauthenticated attack surface
- Lithuania's Centre of Registers loses ~600,000 state-register records to abused institutional credentials; foreign-state actor suspected
- Lazarus "RemotePE": a three-stage memory-only RAT that unhooks EDR and blinds ETW
- Google's threat-intel group maps a Chinese-language PhaaS ecosystem doing real-time OTP relay over RCS/iMessage
- CVE-2026-9058, Szafir SDK (KIR): signature-verification routine reports success on an untrusted certificate chain, enabling auth bypass in Polish e-government
- "TrapDoor" cross-ecosystem supply-chain campaign validates stolen tokens before exfil and poisons AI-assistant config files
- Ghost CMS CVE-2026-26980 → ClickFix: the CMS-compromise-to-endpoint kill chain
- Large-scale ClickFix campaign mass-compromises self-hosted Ghost CMS sites via CVE-2026-26980
- Packagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strand
- Six German university hospitals lose ~97,600+ patient records to a breach at billing processor Unimed
- Ghostwriter / UAC-0057 / FrostyNeighbor, CERT-UA documents new OYSTERFRESH → OYSTERBLUES → OYSTERSHUCK implant chain via Prometheus learning-platform lures
- Unit 42, ROADtools operationalised by Midnight Blizzard, Curious Serpens and UTA0355 for Entra ID device registration, token theft and tenant enumeration
- Unit 42, Iran's Screening Serpens (UNC1549 / Smoke Sandstorm / Nimbus Manticore): AppDomainManager hijacking silently disables ETW + strong-name checks in six new RATs
- ANSSI / CERT-FR publishes CERTFR-2026-AVI-0635 on SPIP < 4.4.15, security-policy bypass in the dominant French public-administration CMS
- Rhysida claims Stuttgart municipal-data theft for 5 BTC; city denies a confirmed incident
- Netherlands FIOD arrests two over EU sanctions evasion for Stark Industries front; 800 servers seized; NoName057(16) DDoS plumbing dismantled
- Red Lamassu (Calypso/Bronze Medley): Showboat + JFMBackdoor telco espionage implant pair
- Calypso/Red Lamassu (Bronze Medley) deploys Showboat (Linux) and JFMBackdoor (Windows) against telecoms, new implant pair disclosed by Lumen Black Lotus Labs and PwC Threat Intelligence
- Operation Saffron dismantles First VPN, 33+ servers seized, user database captured, Switzerland named JIT participant; Phobos RaaS infrastructure link confirmed
- Keycloak 26.6.2, 16 CVEs including OIDC session fixation (CVE-2026-7507), WebAuthn execute-actions token replay (CVE-2026-37982), introspection audience bypass (CVE-2026-37979) and cross-realm IDOR in Authorization Services (CVE-2026-4630)
- B1ack's Stash carding marketplace publicly releases 4.6M card records, SOCRadar attributes collection to e-skimming and phishing; not confirmed by issuing banks
- SonicWall Gen6 SSL-VPN incomplete-patching (CVE-2024-12802), Akira-linked actors brute-force MFA via UPN/SAM account-name split, February–March 2026 intrusions
- Webworm (China-aligned) shifts to EU government targets, EchoCreep (Discord C2) and GraphWorm (Microsoft Graph / OneDrive C2) backdoors documented by ESET, with Belgian, Italian, Serbian, Polish and Spanish governmental victims
- Prepare emergency Drupal patch window for today 17:00–21:00 UTC
- Storm-2949 SSPR-to-Key-Vault Azure kill chain
- TheGentlemen RaaS lists Czech university and Swiss engineering firm on leak site
- Huawei VRP enterprise-router zero-day caused POST Luxembourg nationwide telecom outage (July 2025), no CVE filed 10 months later
- Sparx Enterprise Architect / Pro Cloud Server, five-CVE chain (pre-auth SQL injection + WebEA race-condition RCE), public PoC, no vendor patch
- Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operations
- Drupal core "highly critical" pre-patch warning, unauthenticated, zero-complexity, patch window today 17:00–21:00 UTC
- n8n prototype-pollution chain (CVE-2026-42231 et al.): authenticated-to-RCE on a workflow-automation platform that Swiss/EU agencies increasingly stand up as their integration bus
- Grafana Labs CoinbaseCartel breach; victim confirms source-code-only theft, no customer data, ransom rejected
- CVE-2026-42231 / -42232 / -44789 / -44790 / -44791, n8n self-hosted automation: chained prototype-pollution and injection flaws enabling authenticated-to-RCE plus a Git-node arbitrary file read
- INTERPOL Operation Ramz, 13-country MENA cybercrime sweep: 201 arrests, 53 servers seized, Algerian PhaaS server takedown
- 7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records, same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic
- BigBlueButton bbb-web < 3.0.21 / < 3.0.23, three flaws in EU education and government virtual-classroom platform: weak session-token randomness, API checksum bypass, SSRF
- ARWINI (Lower Saxony statutory-prescription audit body); investigators confirm data exfiltration after 4 May intrusion; Kairos ransomware group claims 2.87 TB; ~70,000 GDPR Art. 9 records in scope
- Tycoon2FA after the March 2026 takedown, OAuth Device Authorization Grant abuse on Microsoft 365
- CVE-2026-42897 Exchange OWA, EM Service auto-mitigation depends on outbound connectivity to officemitigations.microsoft.com
- Pwn2Own Berlin 2026: Master-of-Pwn outcomes, the new AI Agents category, and the compound-Exchange-threat picture for European defenders
- Exchange CVE-2026-42897, Pwn2Own DEVCORE three-bug SYSTEM RCE chain emerges alongside active OWA-XSS exploitation
- Kaspersky GReAT documents Kimsuky's Rust-based HelloDoor and TryCloudflare-tunnel C2 added to the PebbleDash toolkit
- CVE-2026-41553, DHTMLX PDF Export Module: unauthenticated server-side JavaScript injection RCE (CVSS 4.0 score 10.0), with CVE-2026-41552 and CVE-2026-7182 path-traversal companions
- CERT-PL CVE-2026-44088, SzafirHost JAR zip-polyglot bypass in Poland's qualified e-signature browser helper
- BKA arrests Dream Market lead administrator "Speedstepper" in Germany, cryptocurrency-to-physical-gold OPSEC failure after seven years at large
- Sophos 2026 State of Identity Security: Switzerland records highest identity-breach incidence globally; energy and federal government hardest-hit sectors
- CVE-2026-45691, Nextcloud Server / Enterprise Server: 2FA bypass on WebDAV via pre-authenticated session token reuse
- FrostyNeighbor / Ghostwriter (UNC1151, Belarus state-aligned): ESET documents March–May 2026 campaign targeting Polish, Lithuanian, and Ukrainian government and industrial sectors
- FamousSparrow Three-Wave Intrusion of an Azerbaijani Energy Operator: ProxyNotShell Re-exploitation and a Wave-1 DLL-Sideload Loader That Overrides Two Hamachi Exports to Defeat Sandbox Analysis
- The Gentlemen RaaS, backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims, decryptor published on GitHub
- GemStuffer, an OpenAI autonomous-agent swarm gained RCE on RubyGems' companion documentation-build service RubyDoc.info, then tried to steal other users' API keys, and OpenAI never reported it under the EU AI Act
- Dutch IGJ rules Clinical Diagnostics/NMDL failed NEN 7510 information-security standard at time of July 2025 ransomware breach; ~941,000 patients affected, cervical-cancer screening data exposed
- TrickMo "TrickMo C", Android banking trojan migrates C2 to The Open Network blockchain, adds SOCKS5 / SSH device-as-pivot
- CERTFR-2026-AVI-0572, Centreon Infra Monitoring: RCE / SQLi / XSS cluster (April 2026 bulletin)
- CERTFR-2026-AVI-0564, SPIP < 4.4.14: multiple RCEs (public and private area)
- CVE-2026-41089 / CVE-2026-41096 / CVE-2026-41103 / CVE-2026-42898; Microsoft May 2026 Patch Tuesday (120+ CVEs, no zero-days)
- TeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin, third Checkmarx supply-chain compromise in three months, SANDCLOCK exfiltrates every CI secret reachable from the runner
- Škoda Auto Deutschland online-shop breach exposes customer PII and password hashes; logging gap prevents exfiltration confirmation
- BKA and ZIT dismantle relaunched Crimenetwork darknet marketplace; German operator arrested in Mallorca on European Arrest Warrant
- ICO fines South Staffordshire Water £963,900, water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The Record
- BSI flags Netgate pfSense Community Edition as critical-unpatched, CVE-2025-69690 / CVE-2025-69691 authenticated root RCE, vendor refuses to fix
- Bauman University "Department No. 4", leaked GRU cyber-operator training pipeline reveals direct line to Sandworm and APT28 operations against European targets
- JDownloader official site compromised, Windows and Linux installers swapped for a Python RAT for ~48 hours
- German court finds bank liable for sophisticated phishing loss, PSD2/IP-analytics obligations clarified
- ENISA expands CVE Root: four new European organisations onboarded as CVE Numbering Authorities
- CVE-2026-40982, Spring Cloud Config Server: pre-authentication path traversal, CVSS 9.8; all actively-maintained branches affected
- CVE-2026-44128 et al. SEPPmail Secure Email Gateway: CVSS 9.3 unauthenticated RCE and five additional CVEs
- CVE-2026-43284 / CVE-2026-43500, Linux "Dirty Frag": deterministic LPE chain via page-cache write primitives in xfrm-ESP and RxRPC, active exploitation confirmed
- DENIC .de DNSSEC outage, faulty key rollover; 3.5 h disruption for German government and public-sector .de domains
- Inditex (Zara), ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromise
- DAEMON Tools Lite supply chain, QUIC RAT deployed via signed installer; EU governments among targeted victims
- Instructure/Canvas extortion: 330 institutions across six countries; May 12 extortion deadline; 44 Dutch institutions confirmed
- Amazon SES weaponised for authenticated phishing and BEC (Kaspersky, 2026-05-04, ~96 h)
- GLPI CERTFR-2026-AVI-0551, Seven CVEs including SSRF and XSS in EU ITSM platform (advisory 2026-04-29)
- CVE-2026-32202, Windows Shell NTLM coercion, APT28 ITW (CVSS 4.3, CISA KEV deadline 2026-05-12)
- CERT-FR CERTFR-2026-ACT-016: Agentic AI tools introduce prompt-injection and supply-chain attack surfaces
- Eurail breach: 308 777 travellers notified three months after December 2025 compromise; Dutch DPA and EDPS open reviews
- Qilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)
- MuddyWater (Iran/MOIS) deploys Chaos ransomware as false flag; harvests credentials via Teams
- Pro-Russian hacktivists modify OT pump settings at five Polish water treatment facilities
- CVE-2026-5787 / CVE-2026-6973, Ivanti EPMM pre-auth certificate impersonation → admin RCE (CISA KEV deadline 2026-05-10)