Weekly Cybersecurity Digest [July, Week 4]

Posted on July 28, 2026

Dear Valued Clients,

Welcome to this week’s cybersecurity digest from Make Sense. Across Europe, recent developments show how cyber risk is moving beyond traditional IT boundaries and into supplier platforms, connected vehicles, healthcare procurement, operational technology, AI systems, and trusted communication services.

The common challenge is control. Compromised supplier credentials can expose sensitive engineering data, poorly secured fleet platforms can affect physical vehicles, and zero-click techniques can bypass familiar user-awareness defences. At the same time, European institutions are strengthening expectations around secure product lifecycles, responsible technology procurement, AI assurance, and accountability for state-sponsored cyber activity.

For organisations, resilience increasingly depends on understanding how technology, suppliers, data, and physical operations connect – and ensuring those dependencies remain visible, governed, and containable.

✅ Top Stories of the Week

i. Swiss Train Manufacturer Rejects $12.3 Million Extortion Demand

Swiss rail manufacturer Stadler refused to pay a $12.3 million demand from the Everest extortion group after attackers stole technical documents from a supplier’s file-sharing platform. Compromised credentials were used to access the external environment, while Stadler’s own systems, production sites, and train operations remained unaffected. The case highlights how supplier-controlled collaboration platforms can expose commercially sensitive information without requiring attackers to compromise the primary organisation directly. [Read more via The Record]

ii. French Fleet Platform Exposure Could Have Enabled Remote Vehicle Commands

Researchers discovered 136GB of exposed data belonging to French fleet-management platform Globalfleet.eu, including driver information, account credentials, GPS histories, and vehicle identifiers. The database could have enabled remote commands to lock or unlock doors and start or stop engines across nearly 3,600 vehicles. France’s CERT assisted in securing the exposure. No evidence of malicious exploitation was identified, but the case demonstrates the cyber-physical impact of poorly secured management platforms. [Read more via Cybernews]

iii. Russia-Linked Hackers Use Zero-Click Emails Against Western Organisations

The UK’s NCSC and international partners warned that Russia-supported group Laundry Bear is exploiting vulnerable Zimbra webmail systems through a zero-click technique. A target can be compromised simply by viewing a malicious email, without opening an attachment or selecting a link. The campaign has targeted government, defence, transport, energy, financial, and other organisations, seeking emails, credentials, contact lists, authentication tokens, and passcodes for intelligence purposes. [Read more via the UK National Cyber Security Centre]

✅ Industry Trends & Insights

Cybersecurity Becomes Part Of Healthcare Procurement

ENISA published new guidelines helping European hospitals and healthcare providers integrate cybersecurity into the entire procurement lifecycle. The guidance covers supplier requirements, risk assessment, security documentation, and alignment with NIS2, GDPR, medical-device rules, and the European Health Data Space. The wider trend is important: healthcare security is moving upstream, from protecting deployed systems to evaluating cyber risk before technologies and suppliers enter clinical environments. [Read more via ENISA]

Europe’s Multilingual Reality Exposes AI Security Gaps

Research shows that AI safety controls do not perform consistently across languages, creating particular risk for multilingual European organisations. Models may resist unsafe prompts in English while responding differently to equivalent instructions in less-supported languages. As AI enters customer service, software development, analysis, and internal workflows, organisations need multilingual red-teaming, language-specific guardrail testing, and monitoring that reflects how employees and customers actually interact with AI systems. [Read more via Dark Reading]

Operational Technology Risk Still Struggles For Boardroom Attention

Despite increasing disruption across UK manufacturing, logistics, water, and other operational environments, board-level cyber discussions remain heavily focused on corporate IT and data breaches. Connected operational technology can create different consequences, including production shutdowns, safety risks, supply-chain disruption, and prolonged recovery. The trend reinforces the need to express OT exposure in business terms and make operational resilience a recurring governance responsibility rather than a specialist technical issue. [Read more via TechRadar Pro]

✅ Regulatory & Policy Updates

Commission Clarifies Cyber Resilience Act Requirements

The European Commission published new guidance explaining how the Cyber Resilience Act applies in practice. It clarifies product scope, substantial modifications, support periods, cybersecurity risk assessments, and reporting obligations, with additional guidance for smaller businesses. CRA reporting obligations begin on September 11, 2026, ahead of the broader December 2027 compliance deadline. Manufacturers and developers should now confirm product classifications, responsibilities, vulnerability processes, evidence requirements, and lifecycle-support arrangements. [Read more via the European Commission]

UK Supreme Court Limits State Immunity In Spyware Case

The UK Supreme Court ruled that Bahrain could not use state immunity to block a lawsuit brought by two dissidents who allege that government agents infected their computers with FinSpy. The court found that state immunity did not apply because the alleged hacking and resulting surveillance occurred in the UK. The decision could have wider implications for accountability when foreign governments deploy commercial spyware against individuals located within European jurisdictions. [Read more via The Record]

Council Approves Reinstatement Of Temporary Online Child-Safety Detection Rules

The Council of the EU approved the reinstatement of temporary rules allowing online service providers to voluntarily detect, report, and remove child sexual abuse material. The measure creates a limited derogation from electronic communications privacy rules and will apply until April 3, 2028, while longer-term legislation is negotiated. End-to-end encrypted number-independent interpersonal communications were excluded, reflecting the continuing policy tension between child protection, privacy, encryption, and platform responsibility. [Read more via the Council of the European Union]

✅ Cyber IQ Challenge + Proactive Security Hacks

Quick Quiz: Which approach provides the strongest protection when attackers may exploit suppliers, collaboration platforms, AI services, or connected operational tools?

A) Trusting any platform that has passed a security certification
B) Concentrating all critical services with one provider
C) Combining least privilege, segmentation, monitoring, patching, and tested alternatives
D) Waiting for evidence of exploitation before reviewing access

(Answer below)

Smart Security Moves of the Week:

  • Supplier-platform review: Identify external file-sharing and collaboration environments containing technical or commercially sensitive information, then review credentials, permissions, and audit logs.
  • Cyber-physical access control: Confirm that fleet, building, industrial, and connected-device platforms cannot execute sensitive commands through exposed databases or weakly protected interfaces.
  • Webmail security: Patch internet-facing collaboration platforms, review suspicious email activity, strengthen monitoring, and rotate credentials or authentication tokens where compromise cannot be excluded.
  • CRA readiness: Establish a product inventory, clarify manufacturer and importer responsibilities, document support periods, and prepare vulnerability-reporting procedures before obligations take effect.

Answer: C) Combining least privilege, segmentation, monitoring, patching, and tested alternatives.

No single control can secure a complex digital ecosystem. Resilience depends on layered safeguards that limit access, detect misuse, contain impact, and preserve operational options.

✅ Conclusion

This week shows how cyber risk is moving beyond traditional IT systems and into supplier platforms, connected vehicles, healthcare procurement, AI tools, and operational technology.

The key message is clear: resilience depends on understanding how these systems connect, who owns the risk, and how quickly access or disruption can be contained. Europe’s regulatory direction reinforces the same need for stronger governance, secure product lifecycles, and clearer accountability.

Final reflection: If a supplier, AI system, or connected platform were compromised or became unavailable today, would your organisation understand the impact quickly enough to respond?

At Make Sense, we help organisations translate cyber complexity into practical resilience across Europe’s evolving threat and regulatory landscape.

Stay secure,
The Make Sense SRL Team & CyberTania