Tag: eu-nexus
All entries tagged eu-nexus.
- CVE-2026-56447, CVE-2026-56446, CVE-2026-56425, CVE-2026-56424, CVE-2026-56423, CVE-2026-56422, MISP 2.5.42: two site-admin RCE paths plus Azure-AD auth and broken-access-control hardening
- NCSC-CH: active Microsoft 365 "voicemail" phishing wave in Switzerland delivers infostealers and harvests M365 credentials
- Swiss Federal Audit Office: federal cyber-governance split leaves strategic oversight without a complete incident picture
- HCRG Care Group first notifies patients of a February 2025 Medusa breach, 16 months on
- UK Information Commissioner resigns with immediate effect, regulator left leaderless mid-restructure
- CVE-2026-55803 / CVE-2026-55804, Drupal core: PHP object-injection chain in JSON:API, BSI-rated critical
- Cyber Europe 2026 tests the revised EU Cyber Blueprint and triggers the first live activation of the EU Cybersecurity Reserve
- EDPB adopts a harmonised GDPR Article 33 breach-notification template; consultation open to 5 August
- EU Cyber Resilience Act reaches its first hard deadline, notifying-authority designation due 11 June
- Italy's low-cost commercial spyware economy: Accessibility-API abuse as the cheap alternative to zero-days
- CNIL fines IQVIA Operations France €5M for health data warehouse security failures: no MFA, no log monitoring, no network segmentation
- Dutch Police + NCSC dismantle Asocks residential-proxy botnet (~17 M devices, 200 NL-hosted servers seized)
- Germany's federal cabinet approves the Cybersicherheitsstärkungsgesetz, BKA, BSI and Federal Police gain authority to redirect traffic and disable attacker infrastructure
- Netherlands FIOD arrests two over EU sanctions evasion for Stark Industries front; 800 servers seized; NoName057(16) DDoS plumbing dismantled
- Keycloak 26.6.2, 16 CVEs including OIDC session fixation (CVE-2026-7507), WebAuthn execute-actions token replay (CVE-2026-37982), introspection audience bypass (CVE-2026-37979) and cross-realm IDOR in Authorization Services (CVE-2026-4630)
- Drupal core "highly critical" pre-patch warning, unauthenticated, zero-complexity, patch window today 17:00–21:00 UTC
- INTERPOL Operation Ramz, 13-country MENA cybercrime sweep: 201 arrests, 53 servers seized, Algerian PhaaS server takedown
- CVE-2026-41553, DHTMLX PDF Export Module: unauthenticated server-side JavaScript injection RCE (CVSS 4.0 score 10.0), with CVE-2026-41552 and CVE-2026-7182 path-traversal companions
- CERT-PL CVE-2026-44088, SzafirHost JAR zip-polyglot bypass in Poland's qualified e-signature browser helper
- ENISA expands CVE Root: four new European organisations onboarded as CVE Numbering Authorities
- DENIC .de DNSSEC outage, faulty key rollover; 3.5 h disruption for German government and public-sector .de domains