Vulnerabilities
8 storiesSAP warns of critical flaws in NetWeaver and Commerce Cloud
Three critical SAP flaws in NetWeaver, Commerce Cloud, and AppRouter demand urgent patching — European enterprises running SAP-centric landscapes face elevated ERP exposure.
BleepingComputer9/1015-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
CVE-2026-43499 (GhostLock) exposes a 15-year-old Linux kernel locking flaw enabling any local user to achieve root and escape containers—affecting virtually every mainstream distribution since 2011 and demanding immediate patching.
THN (Feedburner)9/10[NEU] [hoch] JetBrains TeamCity: Mehrere Schwachstellen
BSI flags high-severity flaws in JetBrains TeamCity enabling RCE, data manipulation, and XSS — a direct threat to CI/CD pipeline integrity and software supply-chain trust across European enterprises.
CERT-Bund (BSI)9/10[UPDATE] [hoch] Splunk Splunk Enterprise: Mehrere Schwachstellen
CERT-Bund escalates multiple high-severity Splunk Enterprise flaws spanning RCE, data manipulation, and DoS — a direct threat to organisations relying on Splunk as their security backbone.
CERT-Bund (BSI)9/10Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
Microsoft's largest-ever Patch Tuesday addresses 570 flaws including two actively exploited zero-days — European enterprises should treat the sheer scope as a stress test for patch-management SLAs.
BleepingComputer9/10[UPDATE] [hoch] Microsoft Windows: Mehrere Schwachstellen
BSI updates its high-severity advisory for Windows client and server, covering privilege escalation to admin, RCE, and spoofing—European enterprises should accelerate Patch Tuesday rollouts.
CERT-Bund (BSI)8/10CISA warns of actively exploited RCE flaws in Joomla extensions
CISA flags active exploitation of file-upload RCE in two Joomla extensions—many Mittelstand web presences still run unpatched Joomla stacks, making rapid triage essential.
BleepingComputer8/10[UPDATE] [kritisch] Wazuh Manager: Schwachstelle ermöglicht Privilegieneskalation
A critical BSI-rated vulnerability in Wazuh Manager allows remote, unauthenticated privilege escalation — compromising the very SIEM/XDR platform defenders depend on, making this a top-priority patch.
CERT-Bund (BSI)8/10
Threat Intel
7 storiesRussia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions
The UK and EU imposed their first joint cyber sanctions on Russia's FSB Center 16 for attempted sabotage of Poland's energy grid — a watershed moment for European critical-infrastructure threat posture.
The Record9/10NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Dutch intelligence links Russian services to systematic compromise of IP cameras monitoring NATO supply routes and Ukrainian personnel across Europe — a hybrid-warfare escalation with direct NIS2 implications for critical-infrastructure operators.
The Record9/10OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Two threat groups are exploiting OAuth client-ID spoofing to silently validate stolen Microsoft Entra ID credentials while evading standard sign-in telemetry — a blind spot most SOCs aren't watching.
THN (Feedburner)9/10ClickFix's Mushrooming Ecosystem Demands New Defense Tactics
ClickFix has matured into a rentable attack ecosystem that consistently bypasses AV and EDR — YARA-based analysis is currently the most reliable detection method.
Dark Reading8/10Finding SOCKS with Proxywatch
SpecterOps introduces Proxywatch, a behavioural detection approach for SOCKS proxy tunnels used in lateral movement — addressing a gap where static IOC rules consistently fall short.
SpecterOps8/10Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
Unit 42 dissects a Vidar Stealer campaign that chains code-signing abuse, Go-compiled DLL sideloading, and file inflation to bypass endpoint defences — a commodity threat adopting APT-grade evasion.
Unit 42 (Palo Alto)8/10Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
Microsoft documented three attack paths used by ShinyHunters to breach Salesforce environments purely through abused OAuth trust — no platform vulnerability required — over the past year.
THN (Feedburner)8/10
Compliance
3 storiesEU takes member states to court over unimplemented cybersecurity law
The European Commission is taking Ireland, Spain, France, and the Netherlands to court over NIS2 transposition delays exceeding 20 months — a clear signal that enforcement patience has expired.
The Record10/10Reverse Engineering Compliance: A Dual-Graph Verification Framework for Auditing Legacy IT Security Concepts
Dual-graph verification framework automates auditing of legacy IT security concepts against NIS2 via OSCAL, helping enterprises shift from document-based compliance to machine-readable evidence.
arXiv Crypto & Security9/10Manage Vendor Risk in a Few Practical Steps
A practical framework for vendor risk governance — covering risk tolerance, exposure visibility, and board oversight — offers timely guidance as NIS2 supply-chain obligations come into force.
Dark Reading8/10
DevSecOps
2 storiesCompromised AsyncAPI npm packages: inside a CI supply-chain attack
Four @asyncapi npm packages (3M+ weekly downloads) were compromised to steal CI credentials — Datadog's detailed writeup offers actionable IOCs and a CI supply-chain attack playbook.
Datadog Security Labs10/10Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
Heimdallr systematically maps how LLM integrations in GitHub Actions create injectable attack surfaces via externally controllable inputs—a concrete and growing risk for any enterprise using AI-augmented CI/CD pipelines.
arXiv Crypto & Security9/10
Research
2 storiesMako: A Self-Evolving Agentic Operating System (SE-AOS) for Autonomous Web Exploitation
Self-evolving AI agent 'Mako' autonomously synthesises and chains web exploits at runtime — a paradigm shift that accelerates the offensive-defensive arms race.
arXiv Crypto & Security9/10Build your own vulnerability harness
Hacker News (Security)8/10
AI Security
2 storiesCursor IDE Auto-Executes Malicious Code in Poisoned Repos
Cursor IDE still auto-executes malicious code from poisoned repositories months after disclosure — a critical risk for enterprises using AI coding assistants with external codebases.
Dark Reading9/10When Local Monitors Miss Compositional Harm: Diagnosing Distributed Backdoors in Multi-Agent Systems
Researchers show that per-message runtime monitors for multi-agent LLM systems miss distributed backdoors where harmful payloads are split across cooperating agents — demanding compositional safety analysis.
arXiv Crypto & Security9/10
Regulatory
2 storiesCertifying Ghosts: How Cybersecurity AI Agents Break the EU Cyber Resilience Act
Researchers argue the CRA's process-based compliance model breaks down when autonomous AI agents — not humans — handle vulnerability discovery, patching, and disclosure for certified products.
arXiv Crypto & Security9/10AWS designated as a critical third party to the UK financial sector
HM Treasury's designation of AWS as a UK Critical Third Party foreshadows how DORA's ICT oversight regime may treat hyperscalers — EU financial-sector CISOs should prepare now.
AWS Security Blog8/10
Security
1 storyBoardroom Brief
What this week's reporting means for the board, in one line per story.
- Compromised AsyncAPI npm packages: inside a CI supply-chain attack
A supply-chain attack on widely used npm packages compromised CI/CD credentials at scale — immediate audit and credential rotation are required.
- EU takes member states to court over unimplemented cybersecurity law
The EU is suing four member states over NIS2 delays — enterprises should not wait for national law to begin compliance.
- Mako: A Self-Evolving Agentic Operating System (SE-AOS) for Autonomous Web Exploitation
An AI system that autonomously discovers and chains web exploits signals a new class of offensive capability enterprises must prepare for.
- SAP warns of critical flaws in NetWeaver and Commerce Cloud
Critical SAP vulnerabilities in core ERP products require emergency patching to protect financial and operational systems.
- Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions
The first joint UK-EU cyber sanctions against Russia's FSB for attacking EU energy infrastructure mark a new phase in state-sponsored cyber risk for European operators.
- 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
A newly disclosed 15-year-old Linux kernel vulnerability allows full system takeover and container escape, requiring immediate enterprise-wide patching.
- Cursor IDE Auto-Executes Malicious Code in Poisoned Repos
A popular AI coding tool executes malicious code automatically from untrusted sources — an unpatched flaw that directly threatens software supply-chain integrity.
- Lessons Learned from CISA’s Recent GitHub Leak
The US cybersecurity agency leaked cloud credentials on GitHub for six months — ensure your organisation's secret-management controls would prevent the same.
- [NEU] [hoch] JetBrains TeamCity: Mehrere Schwachstellen
High-severity vulnerabilities in JetBrains TeamCity could allow attackers to inject malicious code into your software build pipeline.
- Heimdallr: Characterizing and Detecting LLM-Induced Security Risks in GitHub CI Workflows
AI-augmented CI/CD pipelines introduce a new class of supply-chain injection risk that requires immediate workflow-level security review.
- Reverse Engineering Compliance: A Dual-Graph Verification Framework for Auditing Legacy IT Security Concepts
Automated verification of legacy security documentation against NIS2 can reduce audit preparation effort and compliance risk.
- Certifying Ghosts: How Cybersecurity AI Agents Break the EU Cyber Resilience Act
Research highlights that the EU Cyber Resilience Act may not adequately govern autonomous AI security tools, creating potential compliance blind spots for product manufacturers.
- [UPDATE] [hoch] Splunk Splunk Enterprise: Mehrere Schwachstellen
Critical vulnerabilities in a widely deployed security-monitoring platform require urgent patching to maintain detection capability.
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
Microsoft's record 570-flaw patch cycle includes two zero-days already weaponised — patching speed directly correlates with breach risk this month.
- NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Russian intelligence is exploiting networked cameras across Europe to surveil NATO logistics, making IoT hardening a board-level geopolitical risk item.
- OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
Attackers can now verify stolen cloud credentials invisibly, highlighting the need to upgrade identity-monitoring capabilities beyond standard Microsoft telemetry.
- AWS designated as a critical third party to the UK financial sector
UK regulators now directly oversee AWS as critical infrastructure — a model the EU is likely to replicate under DORA.
- [UPDATE] [hoch] Microsoft Windows: Mehrere Schwachstellen
Multiple high-severity Windows vulnerabilities enable full system takeover; patch deployment must be verified enterprise-wide.
- ClickFix's Mushrooming Ecosystem Demands New Defense Tactics
A widely rented attack toolkit now evades standard endpoint defences, requiring investment in alternative detection capabilities.
- CISA warns of actively exploited RCE flaws in Joomla extensions
Actively exploited web-platform vulnerabilities require immediate patching to prevent potential breach of customer-facing systems.
- Finding SOCKS with Proxywatch
New research provides defenders with behavioural methods to detect stealthy network tunnelling that conventional rules miss.
- [UPDATE] [kritisch] Wazuh Manager: Schwachstelle ermöglicht Privilegieneskalation
A critical flaw in the open-source Wazuh security platform could let attackers disable or subvert the enterprise's own monitoring infrastructure.
- Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation
Commodity malware is adopting nation-state-grade evasion techniques, requiring enterprises to upgrade detection capabilities.
- Manage Vendor Risk in a Few Practical Steps
Structured third-party risk governance is no longer optional — NIS2 and DORA mandate it, and practical frameworks are available to close gaps.
- Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity
A major data-extortion group has spent a year breaching companies through misconfigured SaaS integrations, not software flaws — a governance gap boards should address.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.