Weekly Cybersecurity Digest [August, Week 2]

Posted on August 18, 2026

Dear Valued Clients,

Welcome to this week’s cybersecurity digest from Make Sense. Across Europe, recent developments show how quickly cyber risk can move from a technical weakness into a wider privacy, operational, or national-security concern.

France confirmed a significant compromise of taxpayer data, Poland began investigating a breach at a healthcare software provider potentially affecting millions of people, and European defence organisations faced zero-day exploitation linked to a state-backed threat actor. At the same time, attacks against enterprise software and communication services reinforce an increasingly important operational reality: the window between vulnerability disclosure, exploitation, and disruption continues to shrink.

✅ Top Stories of the Week

i. French Tax Authority Breach Exposes Data of 678,000 Users

France’s Finance Ministry confirmed that attackers accessed the General Directorate of Public Finances and extracted taxpayer information, with the ministry later reporting that data belonging to 678,000 users had been stolen. Both individuals and professional taxpayers were affected, while investigations continue into the exact information compromised. The breach highlights the sensitivity of government-held financial data and the importance of rapidly detecting unauthorised access to public-sector systems. [Read more via Reuters]

ii. Poland Investigates Healthcare Software Breach Potentially Affecting Millions

Polish authorities are investigating a cyberattack against healthcare software provider MyDr that may have exposed data associated with nearly 19 million people and more than 12,000 medical facilities. Authorities say attackers gained unauthorised access to historical information held in MyDr systems, although the potential 19 million figure should be described carefully because not every customer or patient is necessarily affected. The Record published the report on August 17. [Read more via The Record]

iii. Lazarus Exploits Windows Zero-Day Against European Defence Sector

North Korea-linked Lazarus hackers exploited a Windows zero-day vulnerability as part of an Operation Dream Job campaign targeting defence, aerospace, and aviation organisations in Europe and India. Successful targeting was observed in France and Germany, while one compromised French organisation was subsequently used to support spear-phishing against additional targets. The campaign combines zero-day exploitation, fake recruitment opportunities, and trusted infrastructure to increase both technical and social-engineering effectiveness. [Read more via BleepingComputer]

✅ Industry Trends & Insights

SAP Commerce Cloud Vulnerability Targeted Days After Patch Release

Attackers began targeting a maximum-severity SAP Commerce Cloud remote-code-execution vulnerability only three days after SAP released a patch. The flaw can allow an unauthenticated attacker to execute arbitrary code, while thousands of systems carrying a Commerce Cloud fingerprint remain visible online, particularly across Europe and North America. The speed of exploitation reinforces why organisations cannot always rely on routine patching cycles for critical internet-facing vulnerabilities. [Read more via BleepingComputer]

Large-Scale DDoS Attacks Disrupt Swiss Messaging Provider Threema

Swiss secure-messaging provider Threema experienced a series of large-scale DDoS attacks that caused significant communication disruptions as attackers repeatedly changed techniques to bypass mitigation measures. Threema noted that customers using its on-premises deployment were unaffected because they relied on their own infrastructure. The incident offers a useful resilience lesson: architecture and deployment choices can materially change an organisation’s exposure to availability incidents affecting shared service infrastructure. [Read more via BleepingComputer]

✅ Regulatory & Policy Updates

Germany Moves to Give Intelligence Services New Cyber Powers

Germany’s cabinet approved proposals that would give its intelligence agencies broader powers to counter cyber and hybrid threats, including authority under defined conditions to access attackers’ IT systems, copy or delete data, and disable tools used in foreign-state cyber operations. The measures still require parliamentary approval and have also triggered debate over privacy, oversight, and the appropriate boundaries of state cyber capabilities. [Read more via Reuters]

UK ICO Reprimands ACRO Following Cybersecurity Failings

The UK Information Commissioner’s Office reprimanded the ACRO Criminal Records Office after security weaknesses potentially exposed the personal information of up to 10,920 people. The regulator identified shortcomings in patch management, responsibility for security updates, and the investigation of warning alerts, while network segmentation helped prevent the attacker from reaching core systems. The case reinforces that accountability for patching and monitoring must remain clear even when security activities are delivered through third-party providers. [Read more via the Information Commissioner’s Office]

✅ Cyber IQ Challenge + Proactive Security Hacks

Quick Quiz: An organisation learns that a critical vulnerability affecting an internet-facing business system is already being exploited. What is the strongest immediate response?

A) Wait for the next scheduled monthly patch cycle
B) Monitor the system until confirmed exploitation occurs internally
C) Assess exposure immediately, apply the security update or mitigation, and increase monitoring for signs of compromise
D) Notify employees and continue normal operations until the vendor provides further guidance

(Answer below)

Smart Security Moves of the Week:

  • Prioritise actively exploited vulnerabilities: Move critical internet-facing flaws out of routine patching queues when exploitation is confirmed or credible evidence indicates imminent risk.
  • Review enterprise software exposure: Identify externally accessible business platforms such as e-commerce, PLM, CMS, and remote-access systems, and confirm that ownership and patching responsibilities are clear.
  • Harden defence-sector recruitment processes: Employees working with sensitive technologies should independently verify recruitment contacts and avoid installing software supplied through unsolicited job opportunities.
  • Monitor public-sector and financial identities: Where sensitive personal or tax-related information is exposed, prepare employees and users for targeted phishing, impersonation, and fraudulent communications.
  • Plan for service availability failures: Assess how communications and other critical services would continue if a central cloud or hosted provider became temporarily unavailable.

Answer: C) Assess exposure immediately, apply the security update or mitigation, and increase monitoring for signs of compromise.

The SAP Commerce Cloud activity this week demonstrates how quickly attackers can begin testing newly disclosed vulnerabilities. Vulnerability management should therefore be driven by real-world risk and exposure, not only by fixed patching calendars.

✅ Conclusion

This week’s developments show how quickly cyber risk can spread across very different environments. Sensitive government and healthcare data can be exposed through compromised systems, newly disclosed vulnerabilities can move into active exploitation within days, and convincing recruitment processes can become delivery mechanisms for state-backed intrusion.

The same events underline the importance of fundamentals: clear ownership of security updates, visibility into internet-facing systems and third-party data dependencies, effective monitoring, segmentation, and the ability to adjust controls when threat conditions change.

European policy is evolving alongside that threat environment. From stronger regulatory scrutiny of basic cybersecurity controls to proposals for more active state cyber capabilities, resilience is increasingly being treated as both an organisational responsibility and a wider strategic-security priority.

Final reflection: If a critical system, software provider, or vulnerability created exposure today, would your organisation know what data and services were at risk, who was responsible for acting, and what evidence to check for compromise?

At Make Sense, we help organisations translate cyber complexity into practical resilience across Europe’s evolving threat, technology, and regulatory landscape.

Stay secure,

The Make Sense SRL Team & CyberTania