Threat Intel
9 storiesBerlin Refuses to Pay Hackers Who Stole Data From the City's State Network
Berlin's government has publicly refused extortion demands after its state network was compromised, while forensic analysis uncovered additional data outflows — establishing a notable EU precedent for no-ransom public-sector policy.
THN (Feedburner)9/10APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Recorded Future links APT28 to a newly documented HOOKEDGE backdoor deployed against diplomatic and government targets in Romania, Spain, and Türkiye—escalating the direct threat to EU institutions.
THN (Feedburner)9/10BlueDelta Targets Defense and Diplomacy with HOOKEDGE
Recorded Future details how Russia's BlueDelta (APT28) deploys a new HOOKEDGE backdoor against European defence and diplomatic targets—directly relevant for EU organisations in the defence supply chain.
Recorded Future9/10Chinese and Russian spies stepping up cyberattacks, German companies report
A new German industry survey confirms that Chinese and Russian intelligence services are intensifying cyber operations against European companies — strategic threat data that should shape Mittelstand defence priorities.
The Record9/10FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
FulcrumSec's claimed 86 GB theft from Manchester Airports Group, independently validated by BleepingComputer, exposes passenger PII well beyond MAG's initial disclosure — a case study in critical-infrastructure breach transparency.
BleepingComputer8/10Tricky 'SynkLoader' Multitool May Herald Ransomware
SynkLoader revives screen-hijacking for credential theft alongside modern evasion features, positioning it as a versatile pre-ransomware loader worth immediate detection investment.
Dark Reading8/10TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Microsoft documents a ClickFix evolution that shifts user-tricked command execution from the Run dialog to Windows Terminal, broadening endpoint attack surface and complicating existing detection heuristics.
THN (Feedburner)8/10'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
NovaCookies offers adversary-in-the-middle M365 session theft at just $320/month, commoditising attacks that bypass conventional MFA — enterprises still relying on push-based authentication face escalating exposure.
Dark Reading8/10A Case-Control Measurement Study of OSINT Source Effectiveness for Critical Infrastructure Defense
Case-control study across 54 confirmed critical-infrastructure attacks identifies which public OSINT feeds actually delivered early-warning indicators — enabling evidence-based threat-intel spending.
arXiv Crypto & Security8/10
Vulnerabilities
7 storiesPopular code generator for TanStack Query hit by supply chain worm
A supply-chain worm embedded in the popular TanStack Query code generator @7nohe/openapi-react-query-codegen steals maintainer credentials and self-propagates to every package the victim publishes — an escalation beyond typical single-package compromises.
Aikido9/10[NEU] [kritisch] vm2: Mehrere Schwachstellen
BSI flags critical vm2 sandbox escapes enabling RCE and security bypass — a significant supply-chain concern for enterprises running Node.js automation or CI/CD workloads that rely on this deprecated library.
CERT-Bund (BSI)9/10[NEU] [kritisch] vm2: Mehrere Schwachstellen
BSI rates multiple vm2 flaws as critical, including sandbox-escape-to-RCE—notable because the long-deprecated library still lurks in many Node.js dependency trees across Mittelstand CI/CD environments.
CERT-Bund (BSI)9/10[NEU] [hoch] IBM QRadar SIEM: Mehrere Schwachstellen
BSI flags multiple high-severity flaws in IBM QRadar SIEM — including privilege escalation and XSS — putting the very platform enterprises rely on for threat detection at risk of compromise.
CERT-Bund (BSI)9/10Hackers target Microsoft SharePoint RCE chain with PoC exploit
Threat actors are actively chaining two SharePoint vulnerabilities for unauthenticated RCE using a public PoC—on-prem SharePoint operators, still common in European Mittelstand, face urgent patching pressure.
BleepingComputer9/10CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
CISA's emergency patching deadline for an actively exploited Citrix NetScaler RCE underscores the persistent risk of edge-appliance vulnerabilities — European enterprises should mirror this urgency given NIS2 patch-management requirements.
BleepingComputer9/10[NEU] [hoch] WatchGuard Firebox OS: Mehrere Schwachstellen
BSI warns of high-severity WatchGuard Firebox OS flaws enabling root-level code execution and denial of service — European Mittelstand organisations using these appliances should treat patching as urgent.
CERT-Bund (BSI)8/10
AI Security
7 storiesTitanCA: Lessons from Orchestrating LLM Agents to Discover 100+ CVEs
Orchestrated LLM agents discovered 100+ real CVEs, outperforming conventional static analysis — signalling that AI-augmented vuln discovery is moving from theory to practical tooling for security teams.
arXiv Crypto & Security9/10VMs won't contain cyber-capable agents
Trail of Bits reports that a cyber-capable AI agent escaped a QEMU/KVM sandbox, challenging the assumption that virtualisation alone can contain advanced autonomous agents — a finding with direct implications for EU AI Act risk classification.
Trail of Bits9/10Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety
Unit 42 research shows LLM safety refusal mechanisms concentrate in a thin neural layer, making them inherently brittle — reinforcing the case for external, defence-in-depth controls around any enterprise AI deployment.
Unit 42 (Palo Alto)8/10The Framing Gap: Indirect Prompt-Injection Exfiltration Defeats Surface-Level Defenses in Tool-Using Agents
Controlled experiments show indirect prompt injection reliably exfiltrates secrets from tool-using LLM agents despite common defences—enterprises must treat agent-ingested content as hostile.
arXiv Crypto & Security8/10Breaking Claude Code Opus 5 Auto Mode
Embrace The Red achieves 60-80% prompt injection success against Claude Code Opus 5's auto mode via website summaries—contradicting Anthropic's commissioned 0% evaluation and highlighting AI coding tool risks.
Embrace The Red (AI Security)8/10When Context Gets Root: Privilege Escalation in LLM Harnesses
Researchers demonstrate that LLM agent harnesses can inadvertently promote untrusted content to system-level privilege during context assembly, bypassing model-side instruction-hierarchy defences—a new class of privilege escalation for agentic AI.
arXiv Crypto & Security8/10Beyond the Editing Canvas: Evidence Divergence in OOXML-to-LLM Ingestion
Research reveals that Office documents ingested into LLM compliance and financial workflows can silently lose semantic fidelity — a hidden evidence-integrity risk for regulated enterprises relying on automated document analysis.
arXiv Crypto & Security8/10
Research
3 storiesReconstruction of Personally Identifiable Information from Proprietary Data in Supervised Fine-Tuned Models
Researchers show that personally identifiable information from fine-tuning datasets can be reconstructed from model outputs — a direct GDPR concern for European enterprises customising LLMs with proprietary data.
arXiv Crypto & Security8/10Cleartext Credential Recovery in ServiceNow
SpecterOps demonstrates how ServiceNow script includes can be abused to recover cleartext discovery and LDAP credentials, creating a high-impact post-authentication pivot path in enterprise ITSM environments.
SpecterOps8/10Exploits and vulnerabilities in Q2 2026
Kaspersky's Q2 2026 exploit report breaks new ground by aggregating AI framework and agent vulnerabilities alongside traditional CVE data—a signal that AI-specific risks are entering mainstream exploit tracking.
Securelist (Kaspersky)8/10
DevSecOps
3 storiesKubeCap: A Framework for Capability Minimization in Kubernetes via Static Analysis and LLM-Assisted Rule Inference
KubeCap automates Linux capability minimisation in Kubernetes via static analysis and LLM-assisted rule inference, tackling the pervasive problem of over-privileged container workloads in enterprise clusters.
arXiv Crypto & Security8/10Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps
Wiz's VCS forensics cheatsheet maps audit-log visibility gaps and threat-hunting strategies across four major platforms—a practical IR readiness resource for teams whose CI/CD pipelines are investigation blind spots.
Wiz Blog8/10Software supply chain security requires decisions rather than defaults
Aikido argues that pinning, gating, and SBOM upkeep remain ineffective without explicit ownership — a governance gap that CRA and NIS2 will increasingly scrutinise in European software producers.
Aikido8/10
OT/IoT Security
1 storyRegulatory
1 storyCompliance
1 storyBoardroom Brief
What this week's reporting means for the board, in one line per story.
- Popular code generator for TanStack Query hit by supply chain worm
A worm-like npm supply-chain compromise can spread across all packages a developer maintains, creating cascading risk for any organisation consuming affected libraries.
- [NEU] [kritisch] vm2: Mehrere Schwachstellen
A critical vulnerability in a widely-used Node.js sandboxing library could allow attackers to execute arbitrary code in automation and development pipelines.
- [NEU] [kritisch] vm2: Mehrere Schwachstellen
A deprecated but widely embedded open-source component has critical code-execution flaws requiring immediate removal from affected systems.
- Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
Berlin's refusal to pay extortionists after a state-network breach sets an EU public-sector precedent that may influence regulatory expectations for all critical entities.
- APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
Russian APT28 is deploying a new backdoor against European government entities—direct risk to EU-facing organisations.
- BlueDelta Targets Defense and Diplomacy with HOOKEDGE
Russian state hackers are actively deploying new backdoors against European defence and diplomatic organisations—a direct geopolitical cyber risk.
- [NEU] [hoch] IBM QRadar SIEM: Mehrere Schwachstellen
A critical vulnerability in your security monitoring platform could undermine the entire detection capability; patching is urgent.
- Hackers target Microsoft SharePoint RCE chain with PoC exploit
Attackers are actively exploiting a remote-code-execution chain in Microsoft SharePoint with a public exploit—unpatched on-premises servers are at immediate risk.
- TitanCA: Lessons from Orchestrating LLM Agents to Discover 100+ CVEs
AI agents are now discovering software vulnerabilities at scale — a capability that will change both offensive and defensive economics in software security.
- VMs won't contain cyber-capable agents
Research shows advanced AI agents can break out of standard VM sandboxes, undermining a key assumption in enterprise AI deployment risk models.
- CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday
A critical Citrix NetScaler vulnerability under active attack requires immediate patching — delays risk regulatory non-compliance under NIS2.
- Chinese and Russian spies stepping up cyberattacks, German companies report
German industry reports sharply rising cyberattacks from Chinese and Russian state actors — a strategic risk requiring board-level attention to national-security-grade threats.
- Risky Business #850 -- Widespread AI-enabled attacks target Siemens PLCs
AI-enabled attacks are hitting industrial control systems in the UK and US — European operators face the same threat under NIS2 obligations.
- Reconstruction of Personally Identifiable Information from Proprietary Data in Supervised Fine-Tuned Models
Fine-tuned AI models can leak personal data from training sets, creating direct GDPR liability for organisations customising large language models.
- Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety
Research proves AI safety guardrails are structurally fragile, reinforcing the need for layered external controls on enterprise AI deployments.
- The Framing Gap: Indirect Prompt-Injection Exfiltration Defeats Surface-Level Defenses in Tool-Using Agents
Research proves that AI agents handling external content can be tricked into leaking secrets despite existing safeguards.
- Cleartext Credential Recovery in ServiceNow
A research disclosure shows that ServiceNow, a platform managing enterprise IT credentials, can leak passwords in cleartext under certain configurations.
- Breaking Claude Code Opus 5 Auto Mode
Independent testing shows AI coding tools can be hijacked to execute malicious code at high success rates, contradicting vendor safety evaluations.
- Exploits and vulnerabilities in Q2 2026
AI software vulnerabilities are now tracked alongside traditional exploits in industry reports, signalling they require the same management rigour.
- FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
A major European airport group faces validated data theft far exceeding its initial disclosure, highlighting breach-transparency and regulatory risk.
- Tricky 'SynkLoader' Multitool May Herald Ransomware
A new multi-purpose malware loader could precede ransomware — early detection investment now may prevent costly encryption incidents later.
- When Context Gets Root: Privilege Escalation in LLM Harnesses
A newly identified privilege-escalation class in AI agent frameworks could let external content override system-level controls—relevant for any enterprise deploying LLM agents.
- Defining an AI Kill Switch Is Hard, but Necessary
Pending legislation may require companies to demonstrate the ability to shut down AI agents on demand — a capability that must be architected in, not bolted on.
- TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
A new social-engineering technique tricks employees into executing backdoors via Windows Terminal, bypassing common endpoint defences.
- [NEU] [hoch] WatchGuard Firebox OS: Mehrere Schwachstellen
Critical firewall vulnerabilities could allow full device takeover — patch status should be confirmed with IT operations.
- 'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
Session-stealing phishing kits are now sold as cheap subscriptions — traditional MFA no longer stops them; phishing-resistant alternatives are essential.
- A Case-Control Measurement Study of OSINT Source Effectiveness for Critical Infrastructure Defense
Empirical research shows most OSINT feeds fail to deliver early warning before critical-infrastructure attacks — an opportunity to optimise threat-intelligence spend.
- Software supply chain security requires decisions rather than defaults
Upcoming EU regulations will penalise software producers who cannot demonstrate deliberate, owned supply-chain security processes.
- Beyond the Editing Canvas: Evidence Divergence in OOXML-to-LLM Ingestion
Automated document analysis workflows may silently distort the evidence they process, creating hidden compliance and decision-making risks.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.