Weekly Cybersecurity Digest [July, Week 3]
Posted on July 21, 2026
Dear Valued Clients,
Welcome to this week’s cybersecurity digest from Make Sense. Across Europe, recent developments are showing how cyber risk can spread through third-party providers, AI data pipelines, remote-access appliances, critical public infrastructure, and the digital platforms organisations increasingly depend on.
The common challenge is not simply preventing an initial compromise, but maintaining control when a trusted supplier, privileged account, dataset, or edge device is breached. At the same time, European policymakers are strengthening expectations around telecom resilience, secure platform access, cyber insurance, and the management of serious cyber offenders.
✅ Top Stories of the Week
i. Lidl Customers Exposed Through Third-Party Service Provider
Lidl warned customers after an incident at an external service provider exposed personal information belonging to online shoppers in Belgium, Germany, and the Netherlands. The stolen data included names, telephone numbers, email addresses, dates of birth, and customer numbers, although passwords and payment information were reportedly unaffected. The incident demonstrates how customer exposure can originate outside an organisation’s own systems while still creating phishing, impersonation, and reputational risks. [Read more via ITPro]
ii. Hugging Face Breached In Autonomous AI-Driven Attack
AI collaboration platform Hugging Face disclosed that an autonomous offensive agent compromised parts of its production environment, accessing internal datasets and service credentials. The intrusion began through a malicious dataset that exploited code-execution paths before escalating privileges and moving laterally. Hugging Face reported no evidence that public models or datasets were altered. The case shows how datasets, processing pipelines, models, and machine identities are becoming a distinct enterprise attack surface. [Read more via SecurityWeek]
iii. TfL Hackers Jailed After £29 Million Cyberattack
Two British hackers were each sentenced to five-and-a-half years in prison for the 2024 cyberattack on Transport for London. The intrusion cost TfL approximately £29 million and required six months of recovery work, with prosecutors warning that the attackers could have shut down the transport organisation completely. The case demonstrates how social engineering and compromised administrative access can create prolonged operational and financial consequences for critical public services. [Read more via Reuters]
✅ Industry Trends & Insights
Europe Treats AI Dependency As A Strategic Security Risk
EU digital chief Henna Virkkunen warned that artificial intelligence is becoming an instrument of geopolitical power, increasing pressure on Europe to reduce dependence on foreign AI, cloud, and semiconductor providers. The concern extends beyond industrial competitiveness: access restrictions, service withdrawal, or geopolitical intervention could affect critical European capabilities. For organisations, AI vendor selection is increasingly becoming a question of operational continuity, sovereignty, contractual control, and exit readiness. [Read more via Financial Times]
SonicWall Zero-Days Reinforce The Risk Around Edge Infrastructure
Researchers reported that attackers exploited two SonicWall SMA 1000 vulnerabilities as zero-days before patches became available. After gaining root access, the threat actor installed custom malware and could potentially access cached credentials or intercept network traffic. Remote-access appliances remain attractive because they sit between external users and internal environments. For organisations, patching alone is insufficient without appliance monitoring, credential rotation, configuration review, and visibility into activity at the network edge. [Read more via SecurityWeek]
Growing Cyber Threats Prompt A Rethink Of Insurance Strategy
Organisations are reassessing whether cyber insurance provides sufficient protection as ransomware, business interruption, AI-enabled fraud, and data breaches become more complex. Recent incidents involving uninsured organisations have highlighted the financial consequences of major attacks, while exclusions and unsuccessful claims continue to create uncertainty. For European businesses, insurance should support—not replace—tested recovery plans, incident governance, accurate risk disclosure, and clear understanding of which operational losses are actually covered. [Read more via Financial Times]
✅ Regulatory & Policy Updates
UK Issues Revised Telecommunications Security Code
The UK issued version 1.1 of its Telecommunications Security Code of Practice, updating guidance for large and medium-sized public telecoms providers. The revision addresses emerging threats and technological change while reinforcing a comprehensive, risk-based approach to security. It includes expectations concerning governance, patching, network oversight, supplier access, privileged administration, and third-party controls. The update shows how telecom security is increasingly being treated as a matter of national infrastructure resilience and regulatory accountability. [Read more on GOV.UK]
EU Sets Access And Security Requirements For Google’s AI Ecosystem
The European Commission ordered Google to give competing AI assistants access to 11 Android functions and share anonymised search-optimisation data with eligible rivals under the Digital Markets Act. Access will be subject to privacy, cybersecurity, and data-protection requirements, with Google permitted to assess whether participating companies create security risks. The decision shows how European digital regulation is increasingly combining market competition with safeguards for platform access, sensitive data, and device security. [Read more via Financial Times]
UK Police Back New Cyber Crime Risk Orders
UK law-enforcement leaders are supporting proposed Cyber Crime Risk Orders designed to restrict the digital activities of individuals suspected or convicted of serious cyber offences. Courts could place conditions on access to devices, online services, or technical environments to prevent further attacks. The proposal reflects the challenge of managing skilled offenders who can continue operating while under investigation or even in custody. It also raises practical questions about proportionality, enforceability, rehabilitation, and technical monitoring. [Read more via Infosecurity Magazine]
✅ Cyber IQ Challenge + Proactive Security Hacks
Quick Quiz: Which measure most effectively limits the impact of a compromised third-party provider?
A) Relying on the provider’s security certification
B) Giving the provider permanent access for operational convenience
C) Restricting access by purpose, monitoring its use, and maintaining rapid revocation procedures
D) Reviewing the relationship only when the contract is renewed
(Answer below)
Smart Security Moves of the Week:
- Third-party access control: Identify suppliers with system or data access, confirm why each permission is required, and remove dormant or excessive privileges.
- AI pipeline security: Treat training data, model repositories, processing workers, service accounts, and API credentials as production security assets.
- Edge-infrastructure review: Patch remote-access appliances, examine them for compromise, restrict management exposure, and rotate credentials that may have been accessible.
- Cloud activity monitoring: Review Microsoft 365, SaaS, OAuth, and application audit logs for unusual automated actions, distant-future calendar entries, or unexpected data transfers.
Answer: C) Restricting access by purpose, monitoring its use, and maintaining rapid revocation procedures.
A supplier should receive only the access required to perform an agreed function, while the organisation retains the visibility and authority needed to contain that access immediately.
✅ Conclusion
This week highlights how cyber resilience increasingly depends on controlling the technologies, suppliers, and access relationships that connect organisations to the wider digital ecosystem. Third-party service providers, AI processing environments, remote-access appliances, and privileged administrative accounts can all become pathways to sensitive systems and prolonged disruption.
The regulatory direction is equally clear. Organisations are being expected to demonstrate stronger governance over critical infrastructure, supplier access, recovery planning, platform dependencies, and emerging technologies. Resilience therefore means more than preventing compromise: it requires limiting lateral movement, detecting misuse quickly, preserving operational alternatives, and retaining the ability to revoke access when trust breaks down.
Final reflection: If a supplier, AI platform, remote-access appliance, or privileged account were compromised today, could your organisation identify the affected systems, contain the access, and continue operating without waiting for an external party to resolve the incident?
At Make Sense, we help organisations translate cyber complexity into practical resilience across Europe’s evolving threat and regulatory landscape.
Stay secure,
The Make Sense SRL Team & CyberTania
