Weekly Cybersecurity Digest [August, Week 4]
Posted on September 1, 2026
Dear Valued Clients,
Welcome to this week’s cybersecurity digest from Make Sense. Across Europe, recent incidents show how cyber risk continues to affect the digital services people and organisations rely on every day, from airports and government platforms to tourism businesses and developer infrastructure.
A major breach at Manchester Airports Group exposed information linked to millions of travellers, Norway faced sustained disruption across shared public digital services, and a cyberattack forced several Slovenian casinos offline. At the same time, German companies are reporting stronger pressure from foreign intelligence services, while upcoming EU Cyber Resilience Act obligations and renewed scrutiny of fraudulent online advertising are putting vulnerability visibility, platform accountability, and incident readiness firmly on the agenda.
✅ Top Stories of the Week
i. Manchester Airports Group Breach Affects 8.7 Million Customers
Manchester Airports Group confirmed that attackers accessed customer data associated with Manchester, London Stansted, and East Midlands airports, affecting around 8.7 million people. Information linked to Wi-Fi registrations and bookings for parking, lounges, and Fast Track services included email addresses, phone numbers, vehicle registrations, and postcodes, although payment data and airport operations were unaffected. The scale of the breach demonstrates how relatively routine customer-service data can create significant phishing and impersonation exposure when aggregated across millions of travellers. [Read more via The Register]
ii. Pro-Russian Hackers Claim Major DDoS Attack on Norwegian Public Services
Norway’s Digitalisation Agency experienced what it described as the largest attack ever against its services after sustained DDoS activity disrupted access to several government platforms, including shared login services used by citizens. The pro-Russian Server Killers group claimed responsibility following Norway’s renewed support for Ukraine, although Norwegian officials had not confirmed the attribution. The incident shows how availability attacks against shared digital infrastructure can affect many public services simultaneously without requiring data theft or deeper system compromise. [Read more via SecurityWeek]
iii. Cyberattack Forces Slovenian Casinos Offline
Slovenian tourism and gaming group Hit began restoring operations after a cyberattack forced six casinos to close for roughly three days and disrupted supporting systems across its business. Some gaming functions and loyalty services remained unavailable during recovery, while employees and hotel operations were also affected. The incident highlights how attacks against central IT infrastructure can quickly translate into physical-site closures, lost revenue, and wider operational disruption. [Read more via The Record]
✅ Industry Trends & Insights
German Companies Report Rising Cyber Threat From Foreign Intelligence Services
A Bitkom study found that 37% of German companies hit by cyberattacks attributed at least one incident in the past year to a foreign intelligence service, up from 28% a year earlier and 7% in 2023. China and Russia remained the most frequently suspected sources, while companies also reported growing concern about AI-enabled attacks such as deepfakes and automated fraud. The findings illustrate how cybercrime, espionage, and geopolitical activity are becoming increasingly difficult for organisations to separate in day-to-day risk management. [Read more via Reuters]
JetBrains Cadence Breach Highlights Developer Credential Risk
JetBrains confirmed that attackers exploited a critical TeamCity vulnerability to compromise its Cadence cloud development service, exposing user information and potentially sensitive credentials contained in a historical server backup. The company advised affected users to rotate cloud, source-control, package-registry, and other secrets that may have been accessible through the service. The incident demonstrates how development platforms can become high-value concentration points because one compromised environment may provide credentials capable of reaching many external systems. [Read more via JetBrains]
✅ Regulatory & Policy Updates
Cyber Resilience Act Reporting Deadline Approaches for Digital Products
From September 11, manufacturers of products with digital elements sold in the EU will need to report actively exploited vulnerabilities within 24 hours of becoming aware of them, followed by a fuller notification within 72 hours. These reporting duties begin well before the Cyber Resilience Act’s broader product-security requirements become fully applicable. For manufacturers, the immediate challenge is therefore not only vulnerability remediation but having clear product ownership, escalation processes, and evidence of when exploitation became known. [Read more via The Hacker News]
Poland Urges EU to Fine Meta €250 Million Over Scam Advertising
Poland asked the European Commission to impose a €250 million fine on Meta for allegedly failing to act adequately against fraudulent advertisements. Importantly for a cybersecurity digest, Poland’s request relies partly on testing by CERT Polska, which identified 122 fraudulent ads and found that most reported examples remained online. [Read more via Reuters]
✅ Cyber IQ Challenge + Proactive Security Hacks
Quick Quiz: A development platform used by your organisation is breached and may have exposed credentials used to access other systems. What should be the priority?
A) Change the password for the development platform only
B) Wait until attackers are confirmed inside connected systems
C) Identify and rotate all potentially exposed credentials and review connected environments for suspicious activity
D) Delete the affected development projects immediately
(Answer below)
Smart Security Moves of the Week:
- Prepare customers for targeted phishing: Following large contact-data breaches, warn affected users that attackers may combine legitimate travel, booking, or service information to create convincing scams.
- Test DDoS resilience: Identify public services that depend on shared authentication, network, or cloud infrastructure and confirm how essential access will continue during sustained availability attacks.
- Map developer secrets: Review where cloud credentials, repository tokens, deployment keys, package-registry credentials, and API secrets are accessible within development and CI/CD platforms.
- Treat state-backed activity as business risk: Include espionage, intellectual-property theft, influence operations, and politically motivated disruption in enterprise threat scenarios where appropriate.
- Prepare for CRA reporting: Manufacturers in scope should establish ownership and escalation processes now so actively exploited vulnerabilities can be assessed and reported within the required timeframe.
Answer: C) Identify and rotate all potentially exposed credentials and review connected environments for suspicious activity.
A compromised development environment can provide attackers with access far beyond the original platform. Credential rotation should therefore cover every connected system that may have trusted secrets stored or used in the affected environment.
✅ Conclusion
This week’s developments demonstrate how cyber risk can spread through both shared infrastructure and ordinary operational dependencies. Airport customer systems can expose millions of identities without disrupting flights, DDoS attacks can pressure multiple government services through common digital platforms, and the compromise of developer infrastructure can create risk across cloud environments, repositories, and deployment systems.
The wider threat environment is also becoming more strategic. German organisations are reporting increased pressure from foreign intelligence services, while fraud campaigns and malicious advertising continue to test how responsibility is shared between users, organisations, technology providers, and large online platforms.
European policy is responding by demanding greater visibility and accountability. With Cyber Resilience Act vulnerability reporting beginning on September 11, manufacturers will increasingly need to know when exploitation becomes known, which products are affected, and who is responsible for acting. Poland’s request for EU action against Meta also shows that platform responsibility for persistent online scams is becoming part of the wider European security discussion.
Final reflection: If a trusted platform used by your organisation were compromised or abused today, could you quickly identify every system, credential, dataset, and business process that depends on it — and who is responsible for responding?
At Make Sense, we help organisations translate cyber complexity into practical resilience across Europe’s evolving threat, technology, and regulatory landscape.
Stay secure,
The Make Sense SRL Team & CyberTania
