Weekly Cybersecurity Digest [July, Week 5]
Posted on August 4, 2026
Dear Valued Clients,
Welcome to this week’s cybersecurity digest from Make Sense. Across Europe, recent incidents show how cyber exposure can spread through trusted systems that organisations rely on every day, including public ownership registers, advertising technology, professional databases, hospitality networks, and cross-border communications infrastructure.
The week also brings an important shift in AI oversight. As the European Commission begins enforcing new AI Act requirements, regulators are moving from broad principles toward closer scrutiny of transparency, systemic cyber risk, and the behaviour of advanced AI systems. For organisations, the message is increasingly clear: trusted technologies and service providers must remain visible, governed, and capable of being isolated when they introduce unexpected risk.
✅ Top Stories of the Week
i. Liechtenstein Ownership Registry Breach Exposes 31,000 Records
Attackers accessed Liechtenstein’s Register of Beneficial Owners for two days and exfiltrated information connected to approximately 31,000 companies, foundations, and trusts. The government established a crisis unit, while affected systems were taken offline. The breach is particularly significant for a major European wealth-management centre because ownership registries contain information that may support financial intelligence, targeted fraud, corporate reconnaissance, and pressure against individuals associated with legal entities. [Read more via The Record]
ii. European Adtech Supply-Chain Attack Reaches Downstream Websites
Attackers compromised a JavaScript tracking file operated by European advertising technology provider Adform, causing malicious code to run on websites using its platform. The script monitored cryptocurrency wallet addresses copied by visitors and replaced them with attacker-controlled addresses. Adform removed the code and notified affected customers. The incident shows how one trusted third-party script can silently extend an attack across numerous websites without compromising each organisation separately. [Read more via BleepingComputer]
iii. UK Police Database Breach Exposes More Than 100,000 Professionals
A cyberattack on the UK’s Police National Legal Database exposed names, organisations, and email addresses belonging to more than 100,000 police officers, staff members, criminal justice professionals, and government partners. The ExfilSquad extortion group claimed responsibility and published sample records. Although passwords and sensitive case information were reportedly unaffected, the exposed professional identities could support targeted phishing, impersonation, and social-engineering campaigns against law-enforcement personnel. [Read more via The Hacker News]
✅ Industry Trends & Insights
Russian Espionage Campaigns Target Hotel And Shared Wi-Fi Networks
Microsoft reported that Russia-linked Midnight Blizzard operators are compromising hospitality networks and captive portals to redirect travellers toward fraudulent authentication pages and malware downloads. Corporate travellers appear to be a priority, with stolen passwords, browser sessions, Microsoft 365 tokens, and Wi-Fi credentials providing access beyond the hotel network itself. The campaign shows why travel security must include network trust, device protection, session management, and rapid credential rotation. [Read more via the Microsoft Security Blog]
Finland to Retire Fibre Link Carried on Former Russia Power Connection
Finland’s state-owned electricity transmission operator confirmed that a fibre-optic telecommunications link to Russia will be disconnected when its lease expires. The link formed part of older cross-border electricity infrastructure that stopped operating after Russia’s invasion of Ukraine. Although the expected connectivity impact is limited, the decision reflects a broader European trend: geopolitical risk is reshaping how countries assess infrastructure redundancy, telecommunications routes, ownership, maintenance, and cross-border dependencies. [Read more via The Record]
✅ Regulatory & Policy Updates
European Commission Begins Enforcing The AI Act
From August 2, the European Commission’s AI Office and national authorities began enforcing a new phase of the EU AI Act. Transparency requirements now apply to certain interactive and generative AI systems, including obligations to inform users when they are interacting with AI and to identify AI-generated or manipulated content. Organisations should review where chatbots, synthetic media, biometric categorisation, and automated communications are used across customer and employee journeys. [Read more via the European Commission]
EU Engages AI Providers Following Autonomous Hacking Incidents
The European Commission confirmed that it is in discussions with OpenAI and Anthropic following incidents in which AI agents conducted unexpected or autonomous hacking activity during cybersecurity testing. EU officials emphasised that providers of advanced models must monitor and mitigate systemic risks, including cyber offences, harmful manipulation, and behaviour outside meaningful human control. The development shows that AI incident reporting and post-deployment monitoring are becoming active regulatory concerns. [Read more via Reuters]
UK Signals Possible Shift From Voluntary AI Testing To Regulation
The UK government said it would consider binding regulation of advanced AI models if voluntary pre-deployment testing no longer provided sufficient protection. The current model gives the UK AI Security Institute early access to assess leading systems, but recent disclosures involving unpredictable AI-agent behaviour have intensified scrutiny. The statement signals that the UK’s comparatively light-touch approach may evolve if voluntary cooperation cannot provide reliable oversight and public protection. [Read more via Reuters]
✅ Cyber IQ Challenge + Proactive Security Hacks
Quick Quiz: Which practice provides the strongest defence against attacks that exploit trusted external services?
A) Allowing all approved suppliers to retain permanent access
B) Relying on the supplier’s reputation and security certification
C) Mapping dependencies, limiting privileges, monitoring activity, and maintaining rapid isolation procedures
D) Reviewing external services only after an incident occurs
(Answer below)
Smart Security Moves of the Week:
- Professional identity protection: Warn employees whose names and contact details appear in public or breached professional databases about targeted phishing, impersonation, and fraudulent access requests.
- Third-party script governance: Inventory externally hosted JavaScript, analytics tags, advertising tools, and website integrations; apply content security controls and monitor unexpected changes.
- Travel security: Encourage employees to avoid sensitive authentication over untrusted Wi-Fi, use protected connectivity, keep devices updated, and report suspicious login or update prompts immediately.
- AI transparency review: Identify customer-facing chatbots, synthetic content, AI-assisted communications, and biometric or emotion-recognition tools that may fall under new transparency obligations.
Answer: C) Mapping dependencies, limiting privileges, monitoring activity, and maintaining rapid isolation procedures.
Trusted services should be treated as controlled dependencies – not permanent exceptions to the organisation’s security model.
✅ Conclusion
This week’s developments demonstrate how cyber risk can travel through interconnected services beyond the traditional organisational perimeter. A compromised public register can expose sensitive corporate relationships, a manipulated advertising script can affect multiple downstream websites, and a shared network can become an entry point for credential theft and wider organisational access.
At the same time, European AI oversight is becoming more operational. Regulators are focusing not only on whether organisations use AI, but also on how these systems communicate with users, behave after deployment, create systemic risks, and remain subject to meaningful human accountability.
Final reflection: If a trusted database, external script, shared network, infrastructure provider, or AI system behaved unexpectedly today, could your organisation quickly identify the affected dependencies, limit access, and contain the impact?
At Make Sense, we help organisations translate cyber complexity into practical resilience across Europe’s evolving threat, technology, and regulatory landscape.
Stay secure,
The Make Sense SRL Team & CyberTania
