Region: europe
All entries tagged europe.
- Water-utility PLC lockouts reach at least twelve US states, and Clayton County publicly confirms a distribution-side consequence as its own
- Traefik 3.7.10 / 3.6.25 / 2.11.54 — a route identity built by joining names with hyphens lets one Kubernetes namespace silently take over another's traffic on a shared Gateway
- CVE-2026-17583 — Thermo Fisher Applied Biosystems genetic analyzers write DNA result files with no integrity checking, so results can be altered after the run and no vendor fix is offered
- Phishing kits are registering browser service workers to build in-page transparent proxies — relaying credentials and live MFA codes from a fake browser window on trusted cloud hosting
- NCSC-CH advises its own constituency on the actively exploited Power Pages misconfiguration — anonymous web roles granted excessive Dataverse table permissions
- N-able N-central post-exploitation, unpacked: six remote-access tools pushed to managed endpoints, a Cloudflare tunnel renamed as a Microsoft updater, and an EDR-evasion driver staged from a remote-support directory
- Liechtenstein VwbP breach: forensics identify a possible entry point, confirm the register was hit in isolation, and publish the exact field set — identity data, no contact details, no financial data
- ByteToBreach hits Hungary's State Treasury after Romania's land registry — the reported entry point is an Oracle WebLogic server left unpatched since a 2017 patch cycle
- CVE-2026-9198 — a third Langflow pre-auth code-execution path reaches CISA KEV: an unauthenticated auto-login endpoint mints a superuser token, and code validation executes what it is handed
- CVE-2026-34486 — Apache Tomcat: the fix for an earlier EncryptInterceptor flaw reintroduced a bypass, and CISA's KEV listing lands months after a China-nexus campaign was already exploiting it
- CVE-2026-18574 — Check Point Security Management: unauthenticated bypass of management authentication to arbitrary command execution, with no fix for seven end-of-support trains
- Switzerland's federal IT provider BIT confirms a SharePoint Server intrusion: ~200 federal user and technical accounts compromised while the July patches were already being installed
- PNLD confirms the police contact-data breach and names a second affected service; researchers trace the ExfilSquad campaign to anonymously readable Power Pages portals, but not PNLD's own root cause
- Liechtenstein's beneficial-ownership register breached: copies of ~31,000 legal entities' records taken, and four more e-government systems pulled offline as a precaution
- BSI and NCSC-NL withdraw SQLite advisories built on LLM-fabricated CVEs — and GitHub's advisory database was still serving one of them
- 2026-W31 looking ahead — items already in motion: a committed firmware date of 12 August, WebSphere fix packs not due before 3Q2026, an extortion campaign between exfiltration and publication, three flaws with no fix at all, and the CRA reporting clock at six weeks
- The European Commission published its first official Cyber Resilience Act application guidance six weeks before the regulation's reporting obligations begin — clarifying which products are in scope, including remote data processing and free and open-source software
- ShinyHunters status: a sector ISAC formalised the helpdesk-vishing-to-SSO chain as a written advisory and told defenders to protect the identity provider like a domain controller, while deliberately declining to name victims
- Open-source supply-chain wave status: a second vendor assesses the escalation at high confidence, the CI trigger that hands over base-repository secrets is named, and two vendors independently attribute the axios compromise to the same DPRK cluster
- Joomla third-party-extension wave status: the wave crossed from disclosed to evidenced this week — server access logs showing exploitation requests, and 92 planted administrator accounts on one live site
- The autonomous-attacker claim got measured this week rather than argued — and the AI toolchain became the vulnerable surface while AI-assisted review failed as an assurance control
- This week's tradecraft was built against the analyst's environment, not the endpoint agent — samples that refuse to run without a keyed argument, loaders that cannot decrypt away from the host they infected, and operators driving the victim's own logged-in session
- Criminal claims outran confirmation in every direction this week — a victim list a vendor assesses is more likely fabricated than real, yet containing a confirmed government breach; a blast-radius claim on one outlet; an attribution the victim will not endorse
- In every confirmed European public-sector and critical-infrastructure incident this week the entry point was an already-valid credential, and the attacker's tool was the platform's own export or admin function
- 2026-W31 vulnerability status roll-up — twelve CVEs stood at confirmed exploitation, three carry public exploit chains, and a dense critical tail hit management planes, OT, ERP and the AI toolchain
- Both standard prioritisation feeds failed in the same week — an exploited flaw absent from KEV, and four critical flaws with no fix to apply
- Every authentication bypass disclosed this week came from code accepting an attacker-supplied value as proof of identity — the check ran, it just validated the wrong thing
- Two independently-operating Russian state clusters converged this week on the government user's mailbox and the government user's travel — and both leave persistence that a patch or a password reset does not remove
- Water-sector PLC lockouts went from one state to seven inside the week, and the European exposure got counted — 86% of 4,117 internet-facing Siemens S7-1200 units sit in four EU countries, reached through mobile carriers
- The exploited surface this week was the management plane itself — VeloCloud Orchestrator, Secure FMC, Check Point SmartConsole, FortiOS SSL-VPN and exposed BMCs, and on several of them what the attacker obtained outlives the upgrade
- Correction — Unit 42's autonomous-agent campaign confirmed command execution on 11 Marimo notebook endpoints as well as three NetScaler exfiltrations
- CVE-2026-7849 and 19 more — Phoenix Contact CHARX SEC-3xxx EV charging controllers: unauthenticated command injection as root, unsigned firmware updates, and no fix released at disclosure
- CVE-2026-48449 — Adobe Campaign Classic: an authorization flaw gives unauthenticated arbitrary code execution (CVSS 10.0), on-premise and hybrid deployments only
- CVE-2026-65766 and CVE-2026-65879 — SP Page Builder for Joomla: a CSRF token Joomla hands to anonymous visitors is the only guard on an ORDER BY injection, plus a shipped-in-source shared secret that opens a mail relay
- CVE-2026-66066 (Rails Active Storage) — the withheld attack chain is public four weeks early, and Rails has shipped forensic tooling to answer 'was I exploited?'
- CCI Nice Côte d'Azur: a compromised administrator account on the chamber's jobseeker platform was used to run the platform's own export function
- Adform: the shared tracking script every customer site embeds was trojanised with a clipboard-rewriting crypto-clipper, and no antivirus engine flagged it
- Water-utility PLC lockouts spread to seven US states — FBI names the targeted controllers, and a Censys scan puts 86% of exposed Siemens S7-1200 units in four European countries
- CVE-2026-65883 — Aimy Captcha-Less Form Guard for Joomla: the anti-spam token is deserialized before any check, and the XOR keystream ships in the same page (CVSS 9.8)
- French Éducation nationale: a hijacked staff account reached the agent-training system, exposing identity and NIR data for everyone who has worked in an académie since 2001
- CaptiveCrunch: an SVR-linked sub-cluster hijacks hotel and conference captive portals to serve fake update lures, a Go RAT and a token-stealing PowerShell module to travelling staff
- Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory — the confirmed compromises came from manual Citrix NetScaler exploitation (CVE-2026-3055), not the agent
- CVE-2026-42897 — Exchange OWA stored XSS weaponised by TA488/LAUNDRY BEAR as a probable zero-day, delivering the browser-resident OWAReaper implant
- Health-ISAC tells the health sector to treat SSO as Tier 0 against ShinyHunters, and deliberately declines to name victims — the pattern, not the tally, is the advisory's point
- UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad — a five-day-old extortion brand whose other 14 claims look fabricated
- Stadler Rail: Everest moves from ransom demand to publication, and claims the released archive touches four other rail operators — Stadler's own channel has said nothing about it
- CVE-2026-66066 — Ruby on Rails Active Storage: an unauthenticated image upload reaches arbitrary file read through libvips' unfuzzed loaders, exposing every application secret (CVSS 4.0 9.5)
- CVE-2026-65884 / CVE-2026-65885 — Balbooa Gridbox for Joomla: anyone can register themselves straight into an administrator group, then upload PHP; 23 flaws found in a vendor-invited audit and exploitation is under way
- Romanian public university UVVG Arad confirms a cyberattack on its IT infrastructure; a Qilin leak-site listing is the only thing linking an actor to it
- CVE-2025-15467 — Siemens Desigo CC: a vendored OpenSSL CMS parsing overflow gives pre-auth code execution, and the V7 family still has no fix (CVSS 9.8)
- Chat Control backlash turns operational: a hacktivist compiles targeting dossiers on French and EU officials out of old breach data, not a new intrusion
- Cl0p-affiliated actors move the PTC Windchill / FlexPLM intrusions (CVE-2026-12569) into a mass extortion-email phase, with no victims named yet
- 2026-W30 looking ahead — items already in motion: a nginx pre-auth RCE PoC on a ~21-day release clock, Oracle Fusion Middleware abuse assessed 'very likely', a public AD CS DCSync PoC, a Mitel CVE pending, and two EU compliance clocks tightening
- BaFin fined TeamViewer EUR 240,000 for how it disclosed its 2024 nation-state breach — a website notice did not satisfy the ad-hoc-disclosure duty, setting a breach-disclosure-mechanics precedent for any SIX/EU-listed software or CI supplier
- ENISA moved cyber-assurance into procurement leverage this week — a public consultation on a mandatory EU Managed Security Services certification, and concrete hospital-procurement security guidance under a new Health Action Plan
- Joomla third-party-extension vulnerability wave status: the mySites.guru campaign added a new technique class this week — a client-supplied cookie accepted as proof of identity, giving anonymous Super User access
- npm / AI-developer-toolchain supply-chain wave status: this week the front edge moved from poisoning packages to poisoning the AI coding assistant's own trust config, via rogue MCP tool-provider entries
- 2026-W30 vulnerability status roll-up — five CVEs crossed into confirmed exploitation/KEV, three more carry public exploit code, and a dense CVSS-9-to-10 tail hit edge, ERP, OT and file-transfer
- Swiss and European public-sector bodies carried the week's home-region incident load — and nearly every one was reached through a third party, a shared platform or a fiduciary, then followed by a disclosure that had to be walked back
- This week's tradecraft converged on hiding command-and-control inside trusted services and native tooling — Graph-API calendars, DNS, the Telegram API, a browser the malware never connects through, and BitLocker instead of a ransomware binary
- AI crossed from accelerant to autonomous operator this week — and AI infrastructure became a first-class target and lure: agents ran live intrusions end-to-end, an LLM rebuilt a patched exploit chain for ~$25, and ransomware was built to destroy model artifacts
- Self-hosted webmail is a standing state-espionage battleground — this week a 16-nation advisory exposed Russia's LAUNDRY BEAR Zimbra zero-click and Proofpoint detailed a separate GRU actor's live 'half-click' zero-day supply across five webmail platforms
- Internet-facing enterprise and admin software crossed into confirmed exploitation again this week — ServiceNow, SharePoint, Check Point management, Langflow and WordPress core all moved to under-attack, and several leave persistence the patch does not remove
- Oracle July 2026 CPU — nine unauthenticated CVSS 10.0 flaws in Fusion Middleware, with NCSC-NL assessing large-scale abuse as very likely in the short term
- CVE-2026-61425 — Balbooa Gridbox for Joomla: a client-supplied cookie is accepted as proof of identity, giving anonymous Super User access
- IFAGE Geneva — DragonForce publishes the stolen data, exposing student exam results the institute had said were unaffected
- ANCPI Romania — DNSC interim report confirms vCenter-to-ESXi ransomware and exfiltration of ~2 million ePayment user records
- TA458 / Operation RoundPress: a running supply of half-click webmail zero-days adds a fresh SOGo flaw (CVE-2026-8496)
- Swiss autism-support foundation Stiftung Autismuslink confirms data-theft cyberattack; INC Ransom claims it
- LAUNDRY BEAR's Zimbra zero-click, unpacked: ZimReaper's CSS-@import sanitizer bypass and an app-password that survives a password reset
- MZ Automation libIEC61850: unauthenticated heap-overflow RCE via crafted MMS Initiate (CVE-2026-49035) plus four sibling OT-library flaws
- Mitel MiCollab AWV: unauthenticated command injection to full system compromise (CVSS 9.8, MTLVULN-1694, CVE pending)
- Russian state actor LAUNDRY BEAR weaponised a Zimbra webmail zero-click (CVE-2025-66376) for mailbox exfiltration — now exposed in a 16-nation joint advisory
- German BKA dismantles Kratos, the Sneaky2FA-derived AiTM phishing-as-a-service platform behind ~15,000 monthly Microsoft 365 credential-theft campaigns
- US agencies expand the Iranian PLC-intrusion advisory (AA26-097A) to Schneider Electric and Siemens controllers, with new project-file tampering detection
- BravoX ransomware leaks 220 GB from a Vaud fiduciary, exposing ~15 municipalities' data and a cantonal minister's tax file
- GLPI 11.0.8 / 10.0.26 — critical RCE via form import and complete MFA bypass in the public-sector ITSM platform
- Everest ransomware breaches a Stadler Rail supplier data-exchange platform, demands CHF 10 million — the Swiss rail manufacturer refuses to pay
- CVE-2026-50522 — SharePoint Server pre-auth deserialization RCE moves to active exploitation via public PoC; attackers steal machine keys for persistent forged authentication
- ANCPI (Romania cadastre): agency says core databases were NOT compromised, contradicting ByteToBreach's destruction claim; Gov Cloud migration to complete 22 July
- CERT-UA: Sandworm subcluster UAC-0145 pairs ClickFix fake-CAPTCHA with Ethereum-smart-contract C2 resolution and a Signal-delivered Android backdoor
- 2026-W29 looking ahead — items already in motion: WordPress WP2Shell and Firefox public exploit code, a SharePoint Pwn2Own chain half-patched until August, a withheld ShareFile CVE, and two EU regulatory clocks running
- Nearly every breach disclosed this week entered through someone else's infrastructure — a service provider, a data-centre host, an ITSM platform and a CI/CD pipeline, not the victim's own perimeter
- EU critical-entity and product-resilience regulation reached concrete operator-facing milestones this week — ENISA shipped a CRA readiness self-assessment ahead of the 11 September reporting clock, and Germany's KRITIS-Dachgesetz opened its first CER-Directive registration window
- OT/ICS carried a full week of high-severity advisories across energy, water, transport and manufacturing — a CVSS-10 debug-port takeover, a persistent-root switch chain, an early-boot coupler backdoor, and a KEV-listed building-automation lockout with no software fix
- Swiss and European public-sector, utility and transport organisations carried the week's home-region incident load — a land registry offline for days, two Swiss utilities/foundations hit through third parties, an EU transit ransomware and a EUR 1.7M telco enforcement
- The week's identity intrusions all abused a trusted relationship rather than breaking authentication — OAuth consent and secret reuse, forged and unverified tokens, and helpdesk process abuse turned valid trust into valid-account access
- 2026-W29 vulnerability status roll-up — nine CVEs crossed into confirmed exploitation/KEV, two more carry public exploit code, and a dense critical-but-unexploited tail hit edge, ERP and OT
- Russian state-nexus pre-positioning against European critical infrastructure reached a new attribution-and-consequence threshold this week — router hijacking, the Turla espionage cluster, the Poland grid attack and camera surveillance all named on the same day the EU and UK imposed their first joint cyber-sanctions
- Internet-facing enterprise software moved from 'at risk' to 'under attack' across the week — SonicWall SMA1000, Progress ShareFile, Oracle E-Business Suite and on-prem SharePoint all crossed into confirmed exploitation
- npm / developer-ecosystem supply-chain wave status: AsyncAPI was the week's marquee compromise, and DPRK's Contagious Interview broadened the developer-as-target vector from package poisoning to CI/CD pipelines and job-interview repos
- The Gentlemen (Storm-2697) status: ReliaQuest's Q2 2026 numbers put it ahead of Qilin on the ransomware leaderboard, and a European public-transport victim (Metro Mondego) landed this week
- State-nexus tradecraft this week targeted defenders' own visibility — HelloNet blinds user-mode network EDR by intercepting raw AFD IOCTLs from a trusted-updater sideload, and GoSerpent shows weeks-long silent collection as deliberate design
- The week's AI-and-attackers reporting converged on a calibrated read — AI is accelerating existing tradecraft, not creating a new attack class — and handed defenders a concrete hunt signal: emoji and Unicode artefacts in compiled-malware debug strings
- ClickFix was the week's universal crimeware delivery vector, and macOS gained a coercion playbook — five families this week converged on paste-into-terminal delivery, local password validation before theft, and decentralized dead-drop C2
- Romania's national cadastre agency ANCPI hit by a multi-day cyberattack; ByteToBreach claims citizen-data and e-Terra source-code theft plus ransomware
- ClickLock Stealer — a macOS ClickFix infostealer that force-kills every visible app until the victim types their login password
- Moodle local_o365 plugin: unverified JWT signature on the Teams SSO endpoint lets anyone authenticate as any user (CVE-2026-54733)
- CVE-2026-47865 — VMware Avi Load Balancer: unauthenticated control-plane authentication bypass (CVSS 9.8), no workaround
- SonicWall SMA 1000 zero-day exploitation (CVE-2026-15409/-15410): Volexity reconstructs UTA0533's full appliance-to-network kill chain
- CVE-2025-40948/-40947/-40949 — Siemens RUGGEDCOM ROX II: Unit 42 chains three OT-switch flaws to persistent root
- TheGentlemen ransomware hits Portugal's Metro Mondego (Coimbra light-rail); operator confirms attack, notifies CNCS and CNPD
- Cisco Talos: UAT-11795 deploys the Python-based Starland RAT and a bespoke PowerShell C2 implant (WLDR), resolving fallback C2 through a Polygon blockchain dead-drop
- Garante fines Wind Tre EUR 1.7M over a vishing-enabled API-enumeration breach that exposed 365,048 telco customers
- Nayax refuses The Syndicate's extortion demand and narrows its disclosed breach scope
- CVE-2023-4346 — KNX building-automation protocol: account-lockout DoS added to CISA KEV, no software patch (CVSS 7.5)
- DragonForce lists Geneva's IFAGE adult-education foundation on its leak site, claiming 850 GB — an attribution and volume IFAGE has not confirmed
- Progress confirms the ShareFile Storage Zone Controller shutdown was forced by a path-traversal zero-day; patches 5.12.5 / 6.0.2 ship and service is restored
- SAP July 2026 Security Patch Day: three CVSS ≥9.1 flaws in NetWeaver AS ABAP, Approuter and Commerce Cloud — two reachable without authentication
- Progress ShareFile Storage Zone Controller — Shadowserver confirms active exploitation of CVE-2026-2699; exposed instances collapse ~30,000 to ~1,000
- US and UK sanction First VPN Service (1VPNS), its administrator and a Belarusian cryptor seller — the sanctions follow-through on the Swiss-assisted Operation Saffron takedown
- AIVD/MIVD: Russia-linked actors hijack default-credential IP cameras along NATO military-supply routes to monitor Ukraine-bound shipments
- France and the EU attribute the Turla intrusion set to FSB Centre 16, with French victimology, TTPs and EU/UK sanctions
- CVE-2026-4769 — WAGO I/O System Field: undocumented early-boot interface allows unauthenticated full compromise (CVSS 9.8)
- Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat' — day three, no patch or root cause disclosed
- FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions
- Looking ahead — 2026-W28
- FINMA sets post-quantum crypto expectations for the Swiss financial sector — Aufsichtsmitteilung 05/2026 flags 'harvest now, decrypt later' and a missing migration roadmap
- Netherlands NIS2 transposition confirmed: the Senate passed the Cyberbeveiligingswet on 7 July, fixing entry into force at 15 August 2026
- The Gentlemen (Storm-2697) status update — Unit 42's full profile: 580 victims, a Qilin-affiliate lineage, and a suspected EDR-disable zero-day
- Threat-actor developments this week: Group-IB reframes Scattered Spider as a decentralised collective, and China- and Iran-nexus edge/ORB tradecraft advances
- Trust-primitive forgery was a research theme this week: recovering live ADFS signing keys, and minting a second 'Verified' GitHub commit
- AI as operator, not target: this week's research showed adversaries using AI to run attacks faster, evade AI defences, and generate tooling
- This week's disclosures clustered on third-party, cloud-account and vendor exposure — the breach rarely started inside the victim
- Healthcare across Switzerland and the UK saw ransomware confirmation, mailbox compromise and an insider-access clampdown this week
- Government and public administration across Switzerland and Europe took a broad spread of attacks this week — ransomware, espionage watering-holes, AI-tooled APTs and credential-phishing
- Vulnerability status roll-up — 2026-W28: what moved into exploitation, what reached KEV, and what to patch out-of-band
- Microsoft 365 account-takeover tradecraft converged this week on auth flows Conditional Access rarely covers — device-code, AiTM, ROPC and manager-impersonation vishing all beat MFA without breaking it
- Confirmed in-the-wild exploitation of internet-facing enterprise software converged this week — ColdFusion, Citrix NetScaler and Gitea all moved from 'at risk' to 'under attack'
- A researcher-driven Joomla extension file-upload wave produced four unauthenticated RCE disclosures this week — several exploited as zero-days before a patch existed
- Progress MOVEit Transfer: pre-auth SFTP DoS (CVE-2026-10699), admin table-scope bypass (CVE-2026-10698) and stored XSS (CVE-2026-11903), patched 2026.0.2
- Joomla file-upload RCE wave adds RSFiles! (CVE-2026-57827, unauth, CVSS 10.0) and Phoca Download (CVE-2026-57828, CVSS 9.0)
- NHS England issues insider-access controls after staff 'snooping' on high-profile patients' records
- Zimbra Classic Web Client: crafted-email code execution fixed in ZCS 10.1.19, surfaced by NCSC-CH (no CVE, exploitation unknown)
- Siemens SICAM 8 (A8000/EGS/S8000) grid RTUs: firmware-signature-validation bypass + OPC-UA-off-by-default among four CVEs (SSA-229470)
- CVE-2026-48939 — iCagenda for Joomla: unauthenticated file-upload-to-RCE, exploited as a zero-day, added to CISA KEV (CVSS 4.0 10.0)
- CVE-2026-20896 — NCSC-CH escalates the Gitea Docker reverse-proxy auth bypass to 'actively exploited'
- ShinyHunters' Odido (NL telecom) breach: Dutch police voice analysis points to Dutch-national involvement; same vishing-into-spoofed-portal playbook, now against an EU telco
- Nextcloud GmbH's own hosting infrastructure exposed 367K internal records via a misconfigured public Elasticsearch cluster, including client setup scripts with hardcoded credentials
- CERT.LV: ransomware crew breaches Latvia's state forestry operator LVM via a 2-year-unpatched system, hits essential-services provider Olpha, and is probing other EU/NATO institutions
- UNK_MassTraction: suspected China-aligned actor exploits Roundcube as an edge device, chaining CVE-2024-42009 XSS into CVE-2025-49113 deserialization
- Deutsche Bank confirms a third-party vendor incident after 'Unsafe' ransomware group posts alleged employee data
- CERT Polska: UNC1151/Ghostwriter shifts to Gmail with real-time 2FA-relay phishing against officials and public administration
- Nayax (Bank-of-Lithuania-licensed EEA payment institution) discloses a cloud-account incident; "The Syndicate" claims 1B card records — claim unverified and contradicted by the filing
- Mandiant "Ghost in the Database": recovering an active ADFS token-signing key from Machine DPAPI when the WID/DKM Golden SAML path fails
- ESET Threat Report H1 2026: first Android malware using generative AI at runtime, ClickFix detections more than double, record QR-phishing, 100+ EDR-killers
- CVE-2026-48614 — Plesk XML API code injection: authenticated low-privilege user to root (CVSS 9.9)
- Unit 42: Factory-v3 loader-builder abuses fraudulent code-signing and 491 MB file inflation to smuggle Vidar and XMRig past sandboxes
- Ubiquiti UniFi SAB-066 — 25 vulnerabilities incl. unauthenticated CVSS 10.0 command injection in UniFi Connect (CVE-2026-50746)
- Looking ahead — 2026-W27
- Netherlands NIS2 transposition slips past its 1 July target — Senate vote set for 7 July, entry into force now 15 August 2026
- FortiBleed status update — the FortiGate credential-theft campaign is now attributed to INC Ransom / Lynx, with a scaled-up victim count and an unconfirmed Nextcloud zero-day claim
- ShinyHunters / UNC6240 Oracle campaign — status update: Nissan is the largest named victim, notifications keep landing, and a separate Medtronic claim surfaces
- Government and public administration took three distinct hits this week — a Swiss cantonal leak-site claim, a Pegasus-infected MEP, and a US federal info-sharing breach
- Vulnerability status roll-up — 2026-W27: what moved, what to patch on the exploited-flaw clock vs the monthly cycle
- Edge and VPN appliances took three pre-auth RCE/overread disclosures in one week — Citrix NetScaler, WatchGuard Firebox, Kemp LoadMaster
- Two internet-facing Oracle enterprise product lines were under active exploitation this week — E-Business Suite RCE joins the PeopleSoft campaign
- CVE-2026-59509 — cve-search: unauthenticated /fetch_cve_data parameter manipulation exposes admin credential hashes (CVSS 9.2)
- Citizen Lab: a European Parliament spyware-inquiry member was himself infected twice with Pegasus
- CVE-2026-14439 — Altium Enterprise Server / Altium 365: authenticated path-traversal to RCE
- Oracle E-Business Suite CVE-2026-46817: pre-auth RCE in the Payments File Transmission servlet, first in-the-wild exploitation
- CVE-2026-8451 — Citrix NetScaler ADC/Gateway: pre-auth SAML memory overread (CitrixBleed lineage), public PoC
- US posts $10M bounty on the Russia-nexus Signal/WhatsApp crews and adds Signal Backup-Recovery-Key theft to the advisory
- Mustang Panda abuses Zoho WorkDrive as a dead-drop C2 channel (ZOHOMURK) against government and energy targets
- CERT Polska discloses a JAR parser-confusion RCE in the SzafirHost e-signature client (CVE-2026-13165)
- EU Cyber Resilience Act — 75 days to the 11 September vulnerability/incident-reporting obligation
- EU Commission proposes a major Europol / Eurojust mandate expansion
- Netherlands NIS2 (Cyberbeveiligingswet) clears the lower house — entry into force targeted for 1 July 2026
- Operation Endgame
- The Gentlemen
- ShinyHunters / UNC6240 Oracle PeopleSoft campaign
- FortiBleed
- ESET Gamaredon 2025 — annual actor retrospective
- ESET "Killing me gently" — a de-facto mid-year RaaS-tooling report
- Threat-actor developments: Russia-nexus espionage broadens; new China-nexus and DPRK clusters
- Research: the trust chain, not the perimeter, was the week's attack surface
- Attribution and accountability: Jaguar Land Rover and Scattered Spider
- Technology & SaaS supply chain — the week's busiest victim class
- Education
- Healthcare
- Public administration & government
- CVE-2026-11800 (JWT algorithm-confusion) and CVE-2026-9800 (policy-enforcer authz bypass) — Keycloak identity-plane fixes
- CVE-2026-58053 — Gitea act_runner Docker backend: container-hardening bypass to host escape (public PoC, ENISA-critical)
- CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910 — Ubiquiti UniFi OS Server: pre-auth RCE chain, exploited (CISA KEV)
- CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converters: unauthenticated command injection to root (BRIDGE:BREAK, CISA KEV)
- CVE-2026-12569 — PTC Windchill / FlexPLM: pre-auth deserialization RCE, now confirmed exploited with JSP web shells (CISA KEV)
- ShinyHunters (UNC6240) — one cluster, multiple reported tradecraft paths in one week
- Klue / Icarus Salesforce OAuth-integration breach — from nine named victims to ~24, then the attacker gets hacked
- ShapedPlugin's official update channel shipped backdoored WordPress Pro plugins — credential, 2FA-secret and web-shell theft
- NAIC breached through an Oracle PeopleSoft zero-day; ShinyHunters dumps 3.1 TB and US rating-agency feeds stall
- Keycloak JWT algorithm confusion (CVE-2026-11800): forging federated identity in the EU public sector's dominant IdP
- Island: "BadBlocker" — an 11M-user Chrome ad-blocker is one server config change away from arbitrary JavaScript on any site
- Netcraft: Bluekit PhaaS uses Browser-in-the-Middle to defeat FIDO2 and Device Bound Session Credentials
- CVE-2026-58053 — Gitea act_runner Docker backend: container-hardening bypass to host escape (CVSS 9.4, public PoC)
- NYT investigation gives first named attribution for the Jaguar Land Rover ransomware attack — a Russian state-linked criminal group
- NAIC breached via Oracle PeopleSoft zero-day; ShinyHunters publishes 3.1 TB of US insurance-regulatory data and rating-agency feeds pause
- Turla's STOCKSTAY: a four-component .NET backdoor for diplomatic intelligence collection
- "The Gentlemen" ransomware claims 478 victims and adds worm propagation — Switzerland the second-most-targeted European country
- Klue/Icarus Salesforce breach widens to ~24 firms; the attacker is itself hacked and a second extortion actor emerges
- PTC Windchill CVE-2026-12569 now confirmed exploited in the wild with JSP web shells
- Citizen Lab: Cellebrite UFED used by Russian authorities three months after the vendor's Russia pull-out
- Kaspersky GReAT: "StrikeShark" loader deploys Cobalt Strike via "Perfect DLL Hijacking" against government targets
- Microsoft: "Photo ZIP" phishing laundered through Calendly drops Node.js TonRAT against European hospitality front desks
- UK Cyber Monitoring Centre publishes sector review of the Canvas/Instructure LMS breach — 160 universities, ShinyHunters extortion, ransom paid
- FBI/CISA: Russian intelligence now phishing Signal Backup Recovery Keys for persistent account takeover
- ESET's 2025 Gamaredon paper: exfil and C2 moved wholesale onto trusted cloud services (ANNUAL REPORT)
- Ukrposhta digital services disrupted by an overnight attack; pro-Russian hacktivists claim a prior data theft
- CVE-2026-56447, CVE-2026-56446, CVE-2026-56425, CVE-2026-56424, CVE-2026-56423, CVE-2026-56422 — MISP 2.5.42: two site-admin RCE paths plus Azure-AD auth and broken-access-control hardening
- Operation Endgame dismantles the Amadey and StealC malware-as-a-service backbone
- Ubiquiti UniFi OS triple-flaw chain to unauthenticated root (CVE-2026-34908 / -34909 / -34910)
- CVE-2025-67038 — Lantronix EDS5000 serial-to-IP converter: unauthenticated OS command injection to root, first BRIDGE:BREAK flaw added to CISA KEV
- WhatsApp-borne VBScript silently installs a ManageEngine RMM agent for living-off-the-land remote control
- SonicWall CVE-2024-40766: why patched firewalls keep falling to Akira and Fog
- Klue/Icarus OAuth-token breach — named victim list expands to nine firms, mostly cybersecurity vendors
- FortiBleed — first full tool-chain disclosure (FortigateSniffer, SNIFTRAN, GPU cracking cluster); Fortinet confirms no new CVE
- Elastic shows how the newly-GA Azure AD Graph Activity Logs close a long-standing Entra enumeration blind spot
- "Squidbleed" — a 29-year-old heap over-read in Squid's FTP gateway leaks other users' cleartext HTTP credentials (CVE-2026-47729)
- CVE-2026-12789 — ILIAS 11.0: unpatched, PoC-public SQL injection in the learning-progress subsystem (DACH education exposure)
- CVE-2026-20896 — Gitea (Docker): trust-all reverse-proxy default lets an unauthenticated attacker impersonate any user via X-WEBAUTH-USER
- Two Scattered Spider members plead guilty over the 2024 Transport for London intrusion
- ShapedPlugin build pipeline compromised — three Pro WordPress plugins backdoored to steal credentials, 2FA secrets and drop a web shell
- AryStinger: a reconnaissance-and-proxy botnet built on end-of-life D-Link routers and QNAP NAS
- eBanking phishing hides its landing-page address in IPv4-mapped IPv6 notation to slip past URL scanners
- Brazil's national Cell Broadcast alert platform hijacked to push fake "Extreme Alert" messages to ~30M phones
- G7 Évian cybersecurity declaration calls PQC an "urgent priority" — and the expected hacktivist DDoS materialised on day one
- NIS2 transposition remains incomplete — France and Spain still among the laggards
- CRA reporting obligation lands 11 September — ENISA Single Reporting Platform access manual due, dry-runs before go-live
- EDPB adopts a harmonised GDPR Article 33 breach-notification template — consultation open to 5 August
- SocGholish / TA569 — Operation Endgame seized 106 servers, but seven delivery clusters remain operational
- Check Point State of Ransomware Q1 2026 — ecosystem consolidation, with Switzerland and Germany named
- DORA Year 1 — the ESAs' first annual ICT-incident report: 3,383 major incidents, a third cross-border, only ~10% cyber
- Threat actor: FishMonger (I-SOON) ports SprySOCKS to Windows with a kernel-mode rootkit
- Law-enforcement momentum — Operation Endgame expands, Silver Fox mass-arrest, Conti loader plea
- Education — exposed CMS and forum software stack a structural risk
- Public administration — named European institutions and government data in the firing line
- CVE-2026-55803 / CVE-2026-55804 — Drupal core: PHP object-injection chain in JSON:API, BSI-rated critical
- CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (9.4) and Logix CIP DoS, flagged by NCSC-CH
- CVE-2026-20181 / CVE-2026-20190 — Cisco Identity Services Engine: unauthenticated credential read chaining to root command execution
- CVE-2026-50751 — Check Point Security Gateway IKEv1 VPN authentication bypass: public PoC, Qilin affiliate use
- CVE-2026-0257 — Palo Alto Networks PAN-OS GlobalProtect: authentication bypass under active exploitation
- ShinyHunters extortion brand — Council of Europe named, Kodak and One Medical added to the leak-site pressure
- CVE-2026-12569 — PTC Windchill / FlexPLM pre-auth deserialization RCE, exploited, BSI calling admins at 02:30
- CVE-2026-20253 — Splunk Enterprise pre-auth RCE flips to confirmed exploitation and CISA KEV
- FortiBleed — Russian-speaking operator cracking 86,644 FortiGate credentials into Active Directory
- Prinz Eugen: a Go-based encryptor that targets recent files first and leaves no ransom note
- HCRG Care Group first notifies patients of a February 2025 Medusa breach — 16 months on
- UK Information Commissioner resigns with immediate effect — regulator left leaderless mid-restructure
- PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane
- Splunk CVE-2026-20253 now under confirmed limited targeted exploitation
- FortiBleed reaches 86,644 compromised FortiGate devices; CISA issues emergency hardening guidance
- CVE-2026-52806 — Gogs self-hosted Git server: argument injection to OS command execution (BSI critical batch)
- CVE-2026-40624 — AVer PTC-series conference cameras: unauthenticated RCE via the management web interface
- Cisco ISE CVE-2026-20181 + CVE-2026-20190: an unauthenticated credential-harvest primitive feeding authenticated root code execution on the identity plane
- ESET: the Gentlemen RaaS gang centrally builds and maintains its affiliates' EDR-killer framework
- CVE-2026-55803 / CVE-2026-55804 — Drupal core: PHP object-injection chain in JSON:API, BSI-rated critical
- CVE-2026-42530 / CVE-2026-42055 — NGINX: HTTP/3 QUIC use-after-free and HTTP/2-proxy heap overflow, out-of-band F5 patches
- CVE-2026-12046 / CVE-2026-12045 / CVE-2026-12048 — pgAdmin 4: unauthenticated pickle deserialization RCE, AI-Assistant read-only-transaction bypass, stored XSS
- CVE-2026-20181 / CVE-2026-20190 — Cisco Identity Services Engine: unauthenticated credential read chaining to authenticated root command execution
- UK ICO issues criminal caution to London Clinic insider over Princess of Wales medical-record access
- Operation Endgame expands to SocGholish/TA569 — 106 C2 servers down, FakeUpdates loader stripped from 14,971 WordPress sites
- 15 malicious JetBrains Marketplace plugins exfiltrate AI provider API keys on "Apply"
- BSI flags 13 vulnerabilities patched in Zammad 7.1 — admin privilege escalation in a DACH public-sector helpdesk platform
- CVE-2026-0647 et al. — Rockwell Automation FLEX I/O unauthenticated password reset (CVSS 9.4) and Logix CIP denial-of-service, flagged by NCSC-CH
- ScarCruft (APT37) delivers NarwhalRAT behind fake Microsoft OTP "security alert" lures
- Novo Nordisk — FulcrumSec claims authorship, $25M demand refused, data offered for private sale
- Check Point IKEv1 CVE-2026-50751 — public PoC raises exploitation risk
- PAN-OS GlobalProtect CVE-2026-0257 — exploitation wave with Impacket post-compromise, NCSC-CH refreshes advisory
- Zimperium: Rokarolla Android banking trojan targets 217 apps with full device takeover
- Sekoia: ErrTraffic — a ClickFix Malware-as-a-Service framework resolving C2 through the Polygon blockchain
- Munich: ~120,000 student records suspected on the darknet — terminated employee under investigation
- Novo Nordisk clarifies stolen-data scope — non-pseudonymised HCP data in play
- Council of Europe named as a victim of the Oracle PeopleSoft (CVE-2026-35273) campaign
- CVE-2026-48611 / CVE-2026-48612 — phpBB: unauthenticated authentication bypass to admin, one HTTP request
- DPRK UNK_DeadDrop weaponises VS Code / Cursor auto-run to hit developers, including EU targets
- PRC UNC6508 ran year-plus espionage through internet-facing REDCap servers and a Google Workspace BCC rule
- FBI "Operation Ghost Hook" seizes the Outsider PhaaS infrastructure Google had sued
- Handala breaches California Water Service through an internet-exposed RTKBase GNSS platform — billing PII for ~2M customers leaked, no OT access
- EDPB adopts a harmonised GDPR Article 33 breach-notification template
- ENISA publishes the first EU-wide SBOM Adoption State of Play — consumption lags generation
- Germany's Bundestag opens first reading of the CRA domestic-implementation bill
- European Commission refers France and Spain to the CJEU over NIS2 non-transposition
- APT28 (GRU Unit 26165) — Sekoia documents a shift to LLM-generated payloads and cloud-native C2
- Law-enforcement follow-through — Conti loader developer pleads guilty, AudiA6 laundering service dismantled
- Novo Nordisk — theft of non-public data including personal data
- France's Tchap government messenger — account-takeover scrapes 73,467 civil servants' metadata
- Education — ShinyHunters' PeopleSoft campaign lands disproportionately on universities
- Public administration — the week's centre of gravity
- CVE-2025-8088 — WinRAR path traversal: still fuelling Ukraine intrusions a year after the fix
- CVE-2026-41089 — Windows Netlogon: pre-auth SYSTEM RCE on domain controllers, confirmed exploited in the EU
- Ivanti Sentry CVE-2026-10520 — exploitation confirmed in the wild, gateways backdoored
- Sekoia: APT28 (GRU Unit 26165) tradecraft shifts to LLM-generated payloads and cloud-native C2
- Conti loader developer Oleksii Lytvynenko pleads guilty in US federal court after extradition from Ireland
- Cyber Europe 2026 tests the revised EU Cyber Blueprint and triggers the first live activation of the EU Cybersecurity Reserve
- Oracle PeopleSoft CVE-2026-35273 attributed to ShinyHunters; confirmed zero-day, 100+ victims, education sector hit hardest
- CVE-2026-48558 — SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician session
- Novo Nordisk discloses theft of clinical-trial and healthcare-professional data
- MariaDB CVE-2026-49261: Galera wsrep_notify_cmd shell injection (CVSS 10.0)
- ShinyHunters PeopleSoft campaign — Oracle confirms CVE-2026-35273 and ships an out-of-band patch; Nottingham quantifies 455,000 records
- CVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)
- The Gentlemen ransomware: 478 claimed leak-site victims, self-propagating Go encryptor, operator publicly named
- AudiA6 ransomware crypto-laundering service dismantled — two charged, Switzerland among the participating countries
- ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltration
- Windows Netlogon RCE CVE-2026-41089 now confirmed exploited in the wild in the EU; CERT-EU issues advisory 2026-007
- EDPB adopts a harmonised GDPR Article 33 breach-notification template; consultation open to 5 August
- Dragos Q1 2026 Industrial Ransomware Analysis: 1,020 industrial incidents, The Gentleman's 4× surge against Romanian energy, and the IT-adjacent intrusion pattern
- EU Cyber Resilience Act reaches its first hard deadline — notifying-authority designation due 11 June
- Year-old WinRAR flaw (CVE-2025-8088) still fuels Ukraine intrusions — GIFTEDCROOK via UAC-0226 and an Earth Dahu chain
- CVE-2026-47344 et al. — TYPO3 core June release: 13 CVEs across every supported branch (10.4 ELTS → 14.3 LTS)
- CVE-2026-47895 — strongSwan: pre-auth double-free in libstrongswan identity cloning, unauthenticated RCE over EAP (patched 6.0.7)
- CVE-2026-44748 — SAP June Patch Day: SAML XML Signature Wrapping in NetWeaver AS ABAP (CVSS 9.9) plus an unauth RFC kernel memory-corruption (CVSS 9.8)
- CVE-2026-10520 / CVE-2026-10523 — Ivanti Sentry: pre-auth OS command injection to root (CVSS 10.0), public PoC published today
- "Ghost-Sender": Exchange Online accepts spoofed inbound mail bypassing SPF/DKIM/DMARC when a third-party MX fronts the tenant — no vendor patch
- France's Tchap government messenger breached via account takeover — 73,467 civil servants' metadata scraped, CNIL notified
- Meta files contempt complaint against NSO Group over fresh WhatsApp spyware phishing
- Oxford University CareerConnect (Group GTI) breach exposes students at multiple UK universities
- FortiGuard documents C0XMO, a cross-platform Gafgyt variant propagating through a five-year-old DD-WRT UPnP flaw
- CVE-2026-49200 / CVE-2026-49201 — Acer Wave-7 mesh routers: cleartext-credential log + hardcoded backup key, CVSS 10.0, no patch
- FIFA World Cup 2026 pre-event threat cluster: Android banking trojans in pirated streaming apps, plus a 13,000-domain fraud layer, ahead of the 11 June kick-off
- Keycloak 26.6.3: privilege escalation via OAuth token-exchange and SSRF in the EU public sector's reference identity platform
- Magecart family runs its skimmer out of Stripe — payload in customer metadata, stolen cards exfiltrated back through api.stripe.com
- OP-512: China-linked cluster runs a cryptographically-unique, self-reporting IIS web-shell framework against legacy .NET servers
- CVE-2026-10868 — MISP: critical mass-assignment account-takeover in the EU threat-sharing platform
- University of Toronto / Vector Institute: a self-propagating worm that runs open-weight LLMs on compromised hosts to synthesise per-target exploits
- CVE-2026-34906 / CVE-2026-34907 — Simple SA "Wirtualna Uczelnia": unauthenticated SSTI-to-RCE in the student-administration platform used across Polish public universities
- Unit 42 Operation FlutterBridge: notarized macOS backdoor hides its logic in a remote WebView and exfiltrates documents through an "AI summarise" feature
- Proofpoint TA4922: a China-nexus cybercrime cluster expands from Japan into Germany, the UK and Italy with native-language lures and DLL-side-loaded Atlas RAT
- VerdantBamboo (UNC5221 / WARP PANDA): an 18-month China-nexus intrusion that lived entirely on EDR-blind edge appliances and proxied into Microsoft 365 past Conditional Access
- CVE-2026-10611 — MISP: OTP bypass when LDAP mixed-auth and OTP enforcement are both enabled
- CVE-2026-20230 — Cisco Unified Communications Manager: unauthenticated SSRF to OS-root file write
- Shared booking-software breach exposes guests at 100+ Dutch, Belgian and Irish hotels; phishing wave already underway
- NCSC Switzerland: Booking.com breach feeds two-pronged WhatsApp hotel-booking phishing against Swiss travellers
- Gamaredon weaponises WinRAR CVE-2025-8088 and adds the GammaSteel stealer
- Operation XENOFISCAL: SideCopy (APT36) hits provincial treasury officials with XenoRAT via an mshta/HTA chain
- CVE-2024-21182 — Oracle WebLogic Server: unauthenticated T3/IIOP data access, KEV-listed on active exploitation
- NCSC Switzerland warns of cyber operations around the G7 Évian summit (15–17 June)
- Operation Dragon Weave: China-nexus espionage against Czech government with Azure Blob Storage dead-drop C2
- Windows Netlogon CVE-2026-41089 moves from "patch-available" to actively exploited
- Sekoia consolidates Gamaredon tooling under GammaPhish / GammaWorm, details an NTFS-ADS USB+network worm
- CVE-2026-8931 — Disig Web Signer: critical RCE in a Slovak electronic-signature client
- Spain arrests doxer who published personal data on INCIBE, prosecutorial and security-service staff
- EU Council TTE June 9: CSA2 (high-risk supplier framework) + NIS2 simplification progress reports tabled; trilogue targeted early 2027
- EU 20th Russia sanctions package: managed security services prohibition in force since 25 May; Commission interpretive guidance outstanding
- CRA June 11 notifying-authority deadline — first hard CRA milestone with ENISA SRP manual and Secure Update Mechanisms advisory published
- Germany's Gesetzentwurf zur Stärkung der Cybersicherheit: cabinet-approved active-cyberdefence powers for BKA, Bundespolizei and BSI
- Gamaredon — GammaPhish / GammaWorm / GammaSteel: Russian FSB campaign with USB worm and S3 exfiltration (Sekoia TDR part one)
- TA4922 — China-nexus cybercrime cluster expands from Japan into Germany, UK and Italy with native-language lures and Atlas RAT
- VerdantBamboo / UNC5221 / WARP PANDA — 18-month undetected China-nexus intrusion through MSP pfSense
- ENISA NIS360 2026 (3rd edition) — seven sectors in the persistent risk zone where criticality outpaces maturity
- Booking.com WhatsApp phishing + upstream hotel SaaS breach: real reservation data weaponised, 100+ properties affected, Dutch DPA opens investigation
- Healthcare — HIPAA breach + healthcare supply-chain exposure
- Public sector — most-targeted sector this week by volume and by operational severity
- CVE-2026-10868 — MISP: mass-assignment account-takeover (CVSS 9.0) in the EU threat-sharing platform
- Keycloak 26.6.3 — 16 CVEs in the EU public sector's reference IAM, led by token-exchange privilege escalation and SSRF
- Gamaredon: GammaPhish → GammaWorm (NTFS ADS + USB) → GammaSteel (S3 exfil) — the week's most complete intrusion kill-chain disclosure
- Italy's low-cost commercial spyware economy: Accessibility-API abuse as the cheap alternative to zero-days
- SmartApeSG ClickFix stages an unnamed RAT that pivots to a weaponised NetSupport Manager
- CVE-2026-41089 — Windows Netlogon: pre-auth SYSTEM RCE on domain controllers, actively exploited
- Mautic 7.1.2 / 6.0.9 — seven authenticated flaws, including two post-auth RCE paths (SSTI and path-traversal-to-PHP-RCE), an SSRF and an API authorization bypass
- Kimsuky (Velvet Chollima) deploys HTTPSpy RAT and Rust-based HelloDoor via VS Code Remote Tunnel and Cloudflare Quick Tunnel C2
- ESET APT Activity Report Q4 2025–Q1 2026: Sandworm strikes NATO energy, Lazarus targets EU drone sector, UNC5221 pivots to Ivanti SPAWN toolset
- GREYVIBE — newly documented Russia-nexus cluster deploys five parallel attack chains against Ukraine with AI-generated lures and two PowerShell RATs
- Ghost Stadium PhaaS — 300+ FIFA domain clones, multi-language fake SSO, targeting UK/Germany/Portugal/Spain fan credentials before June 11 kickoff
- CNIL fines IQVIA Operations France €5M for health data warehouse security failures: no MFA, no log monitoring, no network segmentation
- FortiClient EMS CVE-2026-35616 + EKZ Infostealer kill chain
- The Gentlemen ransomware — Microsoft publishes full technical dissection of the Storm-2697 Go-encryptor
- WatchGuard documents Grandoreiro's Delphi-DLL-side-loading + WebSocket/STUN C2 against Portuguese & Spanish banks; ESET maps parallel Android BTMOB MaaS
- Wiz CIRT names JINX-0164 — LinkedIn-recruiter lures, AUDIOFIX macOS infostealer, MINIRAT npm pivot into CI/CD
- CVE-2026-32996 & CVE-2026-32997 — Veeam Backup & Replication KB4852: LPE in Windows Agent, arbitrary file write in Linux appliance
- CVE-2026-4868 (+ five further CVEs) — GitLab 19.0.1 / 18.11.4 / 18.10.7 patch release: Duo AI identity impersonation, unauthenticated project enumeration
- CVE-2026-9170 — IBM HTTP Server / WebSphere Application Server: pre-auth RCE via improper input validation (CVSS 9.8)
- CVE-2026-44848 & CVE-2026-44849 — Portainer CE: Docker plugin endpoints unguarded; Swarm-service security checks bypassed (CVSS 9.4)
- CVE-2026-44939 (+ CVE-2026-41052, CVE-2026-41053) — SUSE Rancher: command injection on cluster import, PSA label privilege-escalation, GitHub-App over-inclusive team membership
- CVE-2026-4408 & CVE-2026-4480 — Samba: unauthenticated RCE in SAMR RPC and print-command subsystems (CVSS 10.0)
- TechCrunch finds 100 K passport scans and selfies on a public-read S3 bucket behind a UK Visa Portal lookalike
- Dutch Police + NCSC dismantle Asocks residential-proxy botnet (~17 M devices, 200 NL-hosted servers seized)
- Carnival Corporation confirms 5.99 M-record ShinyHunters breach — passport + driver's-licence numbers exposed across four cruise brands
- Rapid7 publishes unpatched Gogs argument-injection RCE with a Metasploit module; maintainer non-responsive
- FortiClient EMS CVE-2026-35616 actively exploited to push EKZ Infostealer through trusted endpoint-management channel
- Apereo CAS version 7.3.7.1 patches an OIDC-provider flaw reported by Coop Switzerland; CERT-FR issues advisory CERTFR-2026-AVI-0654
- Nx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entries
- MuddyWater / Seedworm — Symantec and Carbon Black document new DLL-side-loading pair via signed Fortemedia and SentinelOne binaries, ChromElevator for Chromium App-Bound Encryption bypass, Node.js orchestration
- CVE-2026-35087 / CVE-2026-35089 / CVE-2026-35090 — Slican PBX telephony exchanges, triple pre-authentication admin bypass (CERT Polska)
- CVE-2026-48842 — Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)
- FBI FLASH CSA 260526 — Silent Ransom Group sends operatives physically into US law-firm offices to insert USB exfiltration devices when remote social engineering fails
- Dutch National Police arrest 35-year-old over AFC Ajax fan-data breach — misconfigured API access-control and shared keys exposed 300,000+ accounts and 42,000 season-ticket records
- CrowdStrike, Google and Shadowserver simultaneously sever all four C2 channels of the GlassWorm developer-targeting botnet (not to be confused with the Nx Console / TanStack GitHub-publish chain in § 5) — Russia-attributed, active since early 2025
- Germany's federal cabinet approves the Cybersicherheitsstärkungsgesetz — BKA, BSI and Federal Police gain authority to redirect traffic and disable attacker infrastructure
- ILIAS LMS — nine fixes shipped 2026-05-27, two critical access-control gaps (CVSS 9.8 + 9.3), NCSC.ch flags SOAP interface as primary unauthenticated attack surface
- Nimbus Manticore (UNC1549 / Screening Serpens) — Check Point details MiniFast backdoor, Zoom-task hijacking and SEO-poisoning delivery
- Lithuania's Centre of Registers loses ~600,000 state-register records to abused institutional credentials; foreign-state actor suspected
- Lazarus "RemotePE": a three-stage memory-only RAT that unhooks EDR and blinds ETW
- TeamPCP / Mini Shai-Hulud — framework open-sourced, Microsoft PyPI SDK trojanised with a wiper stage, forged Sigstore badges
- Google's threat-intel group maps a Chinese-language PhaaS ecosystem doing real-time OTP relay over RCS/iMessage
- CVE-2026-9058 — Szafir SDK (KIR): signature-verification routine reports success on an untrusted certificate chain, enabling auth bypass in Polish e-government
- "TrapDoor" cross-ecosystem supply-chain campaign validates stolen tokens before exfil and poisons AI-assistant config files
- Data-protection enforcement converges on a health-data controls floor — CNIL fines IQVIA €5M; California AG sues over 23andMe
- EU Cyber Resilience Act — 11 June notifying-authority deadline, then September reporting obligations
- ENISA NIS360 2026 — public administration, health and water sit in the NIS2 "risk zone"
- EU 20th-package managed-security-services ban in force from 25 May — Switzerland adopted listings only; MSS prohibition deferred
- Germany's Cybersicherheitsstärkungsgesetz — federal cabinet approves active-cyber-defence powers; Bundestag passage still ahead
- GREYVIBE — independent corroboration; OPSEC slips enabled attribution; charity-front sub-campaign
- UNC6671 / BlackFile — GTIG publishes the full profile; group announced shutdown "under this name", rebrand probable
- ShinyHunters Salesforce campaign — 40+ listed victims; Canada Life and Pitney Bowes confirm; the BreachForums extortion channel was previously seized
- Mini Shai-Hulud / TeamPCP — @antv npm wave and confirmed Maven Central poisoning; Cargo still un-hit
- The Gentlemen / Storm-2697 — internal "Rocket" backend leaked by a rival; KELA and Check Point dissect the operator inner circle
- Check Point Q1 2026 State of Ransomware — ecosystem reconsolidates; LockBit returns with a deliberate Europe pivot
- ESET APT Activity Report Q4 2025–Q1 2026 — three state programmes converging on EU energy, defence and edge appliances
- Asocks residential-proxy botnet — Dutch Police + NCSC dismantle ~17M-device infrastructure hosted in the Netherlands
- UK Visa Portal — ~100,000 passport scans and selfies on a public-read S3 bucket behind a government-lookalike site
- AFC Ajax — 300,000+ fan accounts exposed via misconfigured API access control; Dutch suspect arrested
- Finance — Iberian retail-banking pressure from Grandoreiro plus a parallel Android MaaS
- Healthcare — administrative and imaging intermediaries remain the soft surface
- Public administration & identity (CH / DACH lead) — the LMS, SSO and e-government estate under multi-product pressure
- CVE-2026-48842 — Roundcube Webmail pre-authentication SQL injection
- CVE-2026-9170 — IBM HTTP Server / WebSphere Application Server: pre-auth RCE (CVSS 9.8)
- Mini Shai-Hulud / TrapDoor — the supply-chain worm goes cross-ecosystem, open-source and destructive
- Ghost CMS CVE-2026-26980 → ClickFix: the CMS-compromise-to-endpoint kill chain
- CVE-2026-4408 / CVE-2026-4480 — Samba dual unauthenticated RCE (CVSS 10.0), patch window closed mid-week
- CVE-2026-26980 — Ghost CMS unauthenticated blind SQL injection, mass-exploited into a ClickFix infostealer chain
- CVE-2026-35616 — Fortinet FortiClient EMS pre-auth bypass, exploited to push EKZ Infostealer down the management channel
- Large-scale ClickFix campaign mass-compromises self-hosted Ghost CMS sites via CVE-2026-26980
- Packagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strand
- Six German university hospitals lose ~97,600+ patient records to a breach at billing processor Unimed
- Ghostwriter / UAC-0057 / FrostyNeighbor — CERT-UA documents new OYSTERFRESH → OYSTERBLUES → OYSTERSHUCK implant chain via Prometheus learning-platform lures
- Drupal CVE-2026-9082 — CISA KEV addition + active exploitation confirmed; NCSC.ch flips post 12584 to "Actively exploited"
- Unit 42 — ROADtools operationalised by Midnight Blizzard, Curious Serpens and UTA0355 for Entra ID device registration, token theft and tenant enumeration
- ANSSI / CERT-FR publishes CERTFR-2026-AVI-0635 on SPIP < 4.4.15 — security-policy bypass in the dominant French public-administration CMS
- Rhysida claims Stuttgart municipal-data theft for 5 BTC; city denies a confirmed incident
- Netherlands FIOD arrests two over EU sanctions evasion for Stark Industries front; 800 servers seized; NoName057(16) DDoS plumbing dismantled
- Red Lamassu (Calypso/Bronze Medley): Showboat + JFMBackdoor telco espionage implant pair
- Calypso/Red Lamassu (Bronze Medley) deploys Showboat (Linux) and JFMBackdoor (Windows) against telecoms — new implant pair disclosed by Lumen Black Lotus Labs and PwC Threat Intelligence
- Operation Saffron dismantles First VPN — 33+ servers seized, user database captured, Switzerland named JIT participant; Phobos RaaS infrastructure link confirmed
- Drupal SA-CORE-2026-004 / CVE-2026-9082 ships — "highly critical" pre-auth SQL injection in core database API, PostgreSQL-only
- Keycloak 26.6.2 — 16 CVEs including OIDC session fixation (CVE-2026-7507), WebAuthn execute-actions token replay (CVE-2026-37982), introspection audience bypass (CVE-2026-37979) and cross-realm IDOR in Authorization Services (CVE-2026-4630)
- B1ack's Stash carding marketplace publicly releases 4.6M card records — SOCRadar attributes collection to e-skimming and phishing; not confirmed by issuing banks
- SonicWall Gen6 SSL-VPN incomplete-patching (CVE-2024-12802) — Akira-linked actors brute-force MFA via UPN/SAM account-name split, February–March 2026 intrusions
- Webworm (China-aligned) shifts to EU government targets — EchoCreep (Discord C2) and GraphWorm (Microsoft Graph / OneDrive C2) backdoors documented by ESET, with Belgian, Italian, Serbian, Polish and Spanish governmental victims
- Prepare emergency Drupal patch window for today 17:00–21:00 UTC
- Storm-2949 SSPR-to-Key-Vault Azure kill chain
- TheGentlemen RaaS lists Czech university and Swiss engineering firm on leak site
- SEPPmail Secure E-Mail Gateway — InfoGuard Labs full technical write-up; new CVE-2026-2743 (CVSS 10.0 pre-auth path traversal in LFT)
- Huawei VRP enterprise-router zero-day caused POST Luxembourg nationwide telecom outage (July 2025) — no CVE filed 10 months later
- Sparx Enterprise Architect / Pro Cloud Server — five-CVE chain (pre-auth SQL injection + WebEA race-condition RCE), public PoC, no vendor patch
- Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operations
- Drupal core "highly critical" pre-patch warning — unauthenticated, zero-complexity, patch window today 17:00–21:00 UTC
- n8n prototype-pollution chain (CVE-2026-42231 et al.): authenticated-to-RCE on a workflow-automation platform that Swiss/EU agencies increasingly stand up as their integration bus
- Grafana Labs CoinbaseCartel breach — victim confirms source-code-only theft, no customer data, ransom rejected
- TeamPCP / Shai-Hulud — first copycat wave (Phantom Bot + SSH/cloud stealers), Checkmarx Jenkins plugin trojanised again, PCPJack rival worm hits exposed cloud services
- CVE-2026-42231 / -42232 / -44789 / -44790 / -44791 — n8n self-hosted automation: chained prototype-pollution and injection flaws enabling authenticated-to-RCE plus a Git-node arbitrary file read
- INTERPOL Operation Ramz — 13-country MENA cybercrime sweep: 201 arrests, 53 servers seized, Algerian PhaaS server takedown
- 7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records — same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic
- BigBlueButton bbb-web < 3.0.21 / < 3.0.23 — three flaws in EU education and government virtual-classroom platform: weak session-token randomness, API checksum bypass, SSRF
- ARWINI (Lower Saxony statutory-prescription audit body) — investigators confirm data exfiltration after 4 May intrusion; Kairos ransomware group claims 2.87 TB; ~70,000 GDPR Art. 9 records in scope
- Law-enforcement infrastructure takedowns — Operation Saffron (Switzerland JIT), FIOD/Stark Industries, Kimwolf, INTERPOL Ramz
- EU 20th Russia sanctions package — managed-security-services prohibition effective 25 May; Switzerland adopted most measures 22 May
- The Gentlemen RaaS — Czech university and Swiss engineering firm listed; comms overhaul continues
- Fox Tempest — Microsoft DCU disrupts the malware-signing service feeding Rhysida, INC, Qilin and Akira
- Calypso / Red Lamassu (Bronze Medley, China-aligned) — Showboat and JFMBackdoor against telecoms
- Midnight Blizzard and others operationalise ROADtools for Entra ID abuse
- Ghostwriter / UAC-0057 / FrostyNeighbor (Belarus-aligned) — new OYSTER implant chain
- Webworm (China-aligned; FishMonger / Aquatic Panda) — pivots to EU government targets
- Rhysida claims Stuttgart municipal data — city denies a confirmed incident
- 7-Eleven — ShinyHunters Salesforce campaign claims another 600,000+ records
- ARWINI (Lower Saxony prescription-audit body) — exfiltration confirmed; Kairos claims 2.87 TB including ~70,000 GDPR Art. 9 records
- Six German university hospitals — patient records exfiltrated via billing processor Unimed
- Education — virtual-classroom platforms and EdTech SaaS exposure
- Telecom — sustained pressure from espionage tradecraft and fragile carrier infrastructure
- Public administration — web-CMS and identity estate under multi-vector pressure
- Healthcare (DACH) — the soft surface is the administrative intermediary, not the hospital
- CVE-2026-7507 (+15) — Keycloak 26.6.2: identity-provider cluster including OIDC session fixation and cross-realm IDOR
- CVE-2026-42096 … -42100 — Sparx Enterprise Architect / Pro Cloud Server: five-CVE pre-auth chain, public PoC, no patch
- Tycoon2FA after the March 2026 takedown — OAuth Device Authorization Grant abuse on Microsoft 365
- SonicWall Gen6 SSL-VPN CVE-2024-12802 — Akira-linked actors bypassing MFA on *officially-patched* firmware
- Pwn2Own Berlin 2026: Master-of-Pwn outcomes, the new AI Agents category, and the compound-Exchange-threat picture for European defenders
- Exchange CVE-2026-42897 — Pwn2Own DEVCORE three-bug SYSTEM RCE chain emerges alongside active OWA-XSS exploitation
- Kaspersky GReAT documents Kimsuky's Rust-based HelloDoor and TryCloudflare-tunnel C2 added to the PebbleDash toolkit
- CVE-2026-41553 — DHTMLX PDF Export Module: unauthenticated server-side JavaScript injection RCE (CVSS 4.0 score 10.0), with CVE-2026-41552 and CVE-2026-7182 path-traversal companions
- CERT-PL CVE-2026-44088 — SzafirHost JAR zip-polyglot bypass in Poland's qualified e-signature browser helper
- BKA arrests Dream Market lead administrator "Speedstepper" in Germany — cryptocurrency-to-physical-gold OPSEC failure after seven years at large
- Sophos 2026 State of Identity Security: Switzerland records highest identity-breach incidence globally; energy and federal government hardest-hit sectors
- CVE-2026-45691 — Nextcloud Server / Enterprise Server: 2FA bypass on WebDAV via pre-authenticated session token reuse
- FrostyNeighbor / Ghostwriter (UNC1151, Belarus state-aligned): ESET documents March–May 2026 campaign targeting Polish, Lithuanian, and Ukrainian government and industrial sectors
- FamousSparrow Three-Wave Intrusion of an Azerbaijani Energy Operator: ProxyNotShell Re-exploitation and a Wave-1 DLL-Sideload Loader That Overrides Two Hamachi Exports to Defeat Sandbox Analysis
- The Gentlemen RaaS — backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims, decryptor published on GitHub
- GemStuffer — RubyGems weaponised as a one-way exfiltration channel scraping UK local-authority ModernGov portals; new abuse pattern targets the asymmetric monitoring gap between package pull and push
- Dutch IGJ rules Clinical Diagnostics/NMDL failed NEN 7510 information-security standard at time of July 2025 ransomware breach; ~941,000 patients affected, cervical-cancer screening data exposed
- Instructure Canvas — US House Homeland Security Committee opens formal investigation; Instructure paid ransom
- TrickMo "TrickMo C" — Android banking trojan migrates C2 to The Open Network blockchain, adds SOCKS5 / SSH device-as-pivot
- CERTFR-2026-AVI-0572 — Centreon Infra Monitoring: RCE / SQLi / XSS cluster (April 2026 bulletin)
- CERTFR-2026-AVI-0564 — SPIP < 4.4.14: multiple RCEs (public and private area)
- TeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin — third Checkmarx supply-chain compromise in three months, SANDCLOCK exfiltrates every CI secret reachable from the runner
- Instructure (Canvas LMS) — ransom paid to ShinyHunters with "shred logs"; second intrusion confirmed; per-institution leak deadline reset to today
- Škoda Auto Deutschland online-shop breach exposes customer PII and password hashes; logging gap prevents exfiltration confirmation
- BKA and ZIT dismantle relaunched Crimenetwork darknet marketplace; German operator arrested in Mallorca on European Arrest Warrant
- ICO fines South Staffordshire Water £963,900 — water-sector OES with partial SIEM coverage; Cl0p attribution and ZeroLogon kill-chain detail sourced to The Record
- NIS2 transposition — status update; no Court of Justice referral announced this week
- BKA — Dream Market lead administrator "Speedstepper" arrested in Germany
- ENISA CVE Numbering Authority Root — 4 new CNAs onboarded, identities undisclosed; 7 existing CNAs migrated from MITRE Root
- KRITIS-DachG — German registration deadline 17 July 2026 is now 61 days out
- EDPB Coordinated Enforcement Framework 2026 — 25 DPAs investigating GDPR Articles 12–14 transparency
- DORA first oversight cycle — 19 designated CTPPs under Joint Examination Team activity
- EU CRA milestones — 11 June 2026 CAB notification, 11 September 2026 Article 14 reporting obligations
- EU Digital Omnibus political agreement — AI Act high-risk Annex III compliance deadline extended to 2 December 2027
- SEPPmail CVE-2026-44128 — CIRCL advisory confirms CVSS 9.3 unauthenticated Perl-eval RCE; no third-party PoC in window
- Canvas / Instructure — ShinyHunters / WorldLeaks ransom-paid, US House investigation
- Qilin / Agenda RaaS — April 2026 lead at 15% of global ransomware activity, Germany 5% of global victims
- FrostyNeighbor / Ghostwriter (UNC1151) — ESET analysis corroborated, Poland / Lithuania / Ukraine in EU scope
- Check Point April 2026 ransomware analysis — Qilin leads at 15%, Germany at 5% of global victims
- BKA Dream Market arrest — "Speedstepper" detained in Germany after seven years at large
- Škoda Auto Deutschland — online-shop breach exposes customer PII and password hashes
- West Pharmaceutical Services — SEC Form 8-K Item 1.05
- Clinical Diagnostics / NMDL — Dutch IGJ formal NEN 7510 non-conformity ruling
- BWH Hotels — 181-day unauthorised access to guest-reservation web application
- Hospitality
- Manufacturing
- Public administration and government
- Healthcare
- CVE-2026-44088 — CERT-PL SzafirHost JAR zip-polyglot bypass in Poland's qualified e-signature browser helper
- Canvas / Instructure extortion — ransom paid, US House investigation, second-intrusion vulnerability re-exploited
- Dirty Frag — Microsoft confirms limited in-the-wild exploitation; Red Hat, NCSC.ch, CCB Belgium publish coordinated advisories
- BSI flags Netgate pfSense Community Edition as critical-unpatched — CVE-2025-69690 / CVE-2025-69691 authenticated root RCE, vendor refuses to fix
- DENIC .de DNSSEC outage post-mortem — three private keys generated with the same Key Tag (33834); only one DNSKEY published
- Ivanti EPMM CVE-2026-6973 — KEV deadline expired today; ~850 internet-exposed instances globally with 508 in Europe; companion CVE-2026-5786/5788 ship in same patch
- Canvas/Instructure — ShinyHunters claims a *second* intrusion despite May 8 patches; seven Dutch universities executed emergency disconnects on/before May 9
- Bauman University "Department No. 4" — leaked GRU cyber-operator training pipeline reveals direct line to Sandworm and APT28 operations against European targets
- JDownloader official site compromised — Windows and Linux installers swapped for a Python RAT for ~48 hours
- Polish water OT intrusions — ABW annual report names five facilities; APT28 / APT29 / UNC1151 formally attributed; NIS2 enforcement context
- Canvas/Instructure extortion — Oxford, Cambridge, Liverpool issue public statements; 44 Dutch universities confirmed; May 12 deadline active
- Ivanti EPMM CVE-2026-5787 / CVE-2026-6973 — KEV deadline TOMORROW (2026-05-10); EU victim organisations named; 508 internet-exposed EU instances
- German court finds bank liable for sophisticated phishing loss — PSD2/IP-analytics obligations clarified
- ENISA expands CVE Root: four new European organisations onboarded as CVE Numbering Authorities
- CVE-2026-40982 — Spring Cloud Config Server: pre-authentication path traversal, CVSS 9.8; all actively-maintained branches affected
- DENIC .de DNSSEC outage — faulty key rollover; 3.5 h disruption for German government and public-sector .de domains
- Inditex (Zara) — ShinyHunters publishes 140 GB; 197,400 EU customer records confirmed via third-party analytics compromise
- DAEMON Tools Lite supply chain — QUIC RAT deployed via signed installer; EU governments among targeted victims
- Instructure/Canvas extortion: 330 institutions across six countries; May 12 extortion deadline; 44 Dutch institutions confirmed
- Amazon SES weaponised for authenticated phishing and BEC (Kaspersky, 2026-05-04, ~96 h)
- GLPI CERTFR-2026-AVI-0551 — Seven CVEs including SSRF and XSS in EU ITSM platform (advisory 2026-04-29)
- CVE-2026-32202 — Windows Shell NTLM coercion, APT28 ITW (CVSS 4.3, CISA KEV deadline 2026-05-12)
- CERT-FR CERTFR-2026-ACT-016: Agentic AI tools introduce prompt-injection and supply-chain attack surfaces
- Eurail breach: 308 777 travellers notified three months after December 2025 compromise; Dutch DPA and EDPS open reviews
- Qilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)
- MuddyWater (Iran/MOIS) deploys Chaos ransomware as false flag; harvests credentials via Teams
- Pro-Russian hacktivists modify OT pump settings at five Polish water treatment facilities
- Poland NIS2 transposition in force 3 April 2026 — water-sector essential-entity status would now apply to the ABW-named facilities
- EDPB Coordinated Enforcement Framework 2026 — 25 DPAs target GDPR transparency obligations (Articles 12–14)
- Germany KRITIS-DachG in force — public administration first time in critical-infrastructure scope; registration deadline 17 July 2026
- EU Cybersecurity Package 2026 — NIS2 amendment (COM(2026) 13) + Cybersecurity Act 2 enter EP preparatory phase; PQC obligation embedded
- Europol shadow-IT — LIBE committee MEPs call for mandate-expansion pause; EDPS sanctioning toolkit identified as binary
- German LG Berlin II — Apobank ruling sets PSD2 IP-analytics obligation as case law
- Polish NIS2 transposition + ABW recommendation to expand essential-entity coverage below headcount threshold
- CERT-FR CERTFR-2026-ACT-016 — agentic AI three-risk-class advisory; defender obligations explicit
- ENISA expands CVE Numbering Authority root — 4 new CNAs, 7 migrated from MITRE; ~90 European CNAs eligible for transfer
- Akira playbook quarterly context — Q1 2026 healthcare concentration; Qilin remains the dominant operator on German healthcare victims
- The Gentlemen RaaS — Europe-skewed operation surged approximately 448% QoQ; 32% of Q1 2026 victims in Europe; FortiGate CVE-2024-55591 initial-access funnel
- Qilin / Agenda RaaS — Die Linke confirms Q2 2026 German activity continuity
- Akira ransomware — Swiss healthcare case confirmed; broader European playbook unchanged
- Sandworm / GRU Unit 74455 — Bauman pipeline disclosure
- APT28 / APT29 / UNC1151 (Polish water OT)
- ShinyHunters / WorldLeaks family (financial-data extortion, third-party-SaaS pivot)
- UAT-8302 (China-nexus, Talos; SE European government victims)
- CL-STA-1132 (PAN-OS CVE-2026-0300 exploitation cluster, likely state-sponsored)
- ABW (Poland) 2025 Annual Report — APT28/APT29/UNC1151 tri-attribution on small-municipal water facilities
- Dragos 2025 OT Cybersecurity Year in Review — Frontlines IR Edition
- Google Threat Intelligence Group — Europe data-leak landscape 2025
- Europol IOCTA 2026
- German LG Berlin II ruling — Apobank liable for €218,000+ phishing loss; PSD2 IP-analytics obligation clarified
- DENIC .de DNSSEC outage — 3.5 h registry-side trust failure traced to keytag 33834 collision and an alerting-layer fire-without-page
- JDownloader official site compromised — Windows and Linux installers swapped for ~48 hours
- DAEMON Tools Lite supply-chain compromise — China-nexus QUIC RAT delivered via signed installers; ~12 selective government / scientific / manufacturing targets
- Media and political (HU, DE)
- Transport (NL/EU)
- Critical infrastructure water (PL)
- Public-sector administration and digital identity (FR, EU, FI, CH)
- Education (NL, UK, DE)
- Healthcare (CH, NL)
- CVE-2026-32202 — Windows Shell NTLM coercion; Akamai's PatchDiff-AI shows the residual zero-click path left by the CVE-2026-21510 patch
- CL-STA-1132 — PAN-OS CVE-2026-0300 exploitation cluster: disclosure-to-deadline-to-deadline-expiry inside the window
- Canvas / Instructure breach — five-day arc from first claim to seven Dutch universities executing emergency disconnects
- ShinyHunters / WorldLeaks — week-long cross-incident operator activity touching Inditex, Vimeo, ADT, and Instructure / Canvas
- CVE-2026-6973 + CVE-2026-5787 — Ivanti EPMM on-prem pre-auth chain to admin RCE; 508 EU instances internet-exposed; named EU victims include the European Commission
- CVE-2026-0300 — Palo Alto PAN-OS Captive Portal unauthenticated root RCE; CL-STA-1132 active since 2026-04-09; no patch until 2026-05-13