Geek-Guy.com

Category: Europe

Stay informed on the evolving cybersecurity landscape in Europe. Explore expert analysis on regional threat actors, data privacy regulations, and sovereign AI initiatives, specifically curated for security researchers and analysts monitoring European digital security trends.

Fake Booking.com lures and BSoD scams spread DCRat in European hospitality sector

PHALT#BLYX targets European hotels with fake Booking emails and BSoD lures, tricking staff into installing the DCRat remote access trojan. Researchers uncovered a late-December 2025 campaign, dubbed PHALT#BLYX, targeting European hotels with fake Booking-themed emails. Victims are redirected to bogus BSoD pages using ClickFix-style lures that prompt them to apply “fixes.” The multi-stage attack ultimately…

Fake Booking Emails Redirect Hotel Staff to Fake BSoD Pages Delivering DCRat

Source: Securonix Cybersecurity researchers have disclosed details of a new campaign dubbed PHALT#BLYX that has leveraged ClickFix-style lures to display fixes for fake blue screen of death (BSoD) errors in attacks targeting the European hospitality sector. The end goal of the multi-stage campaign is to deliver a remote access trojan known as DCRat, according to…

ESA disclosed a data breach, hackers breached external servers

ESA confirmed a data breach after a hacker offered to sell stolen data, confirming that external science servers were compromised. The European Space Agency (ESA) disclosed a data breach after a threat actor offered to sell data allegedly stolen from the organization.  A hacker who goes online with the moniker “888” announced on BreachForums the…

Equifax Europe CISO: Notorious breach spurred cybersecurity transformation

The 2017 Equifax breach was one of biggest security incidents of the 21st century. A textbook data leak case, the breach impacted more than 147 million people, spawning a number of scandals and controversies, with the credit reporting agency being criticized for a range of issues, from a lax security posture to their botched response. The high-profile incident…

CERN: how does the international research institution manage risk?

There are few research institutions in the world with the size and scope of the European Organization for Nuclear Research, CERN. Founded in 1954 by 12 European countries, the European Laboratory for Elementary Particle Physics is located in the Swiss town of Meyrin, in the canton of Geneva, although its facilities extend along the Franco-Swiss…

La Poste outage after a cyber attack disrupts digital banking and online services

La Poste said a major network incident took its systems offline, disrupting digital banking and online services for millions of users. The French national postal service La Poste confirmed a major cyber incident had knocked its information systems offline, disrupting digital banking and online services for millions of customers. Les services essentiels de la banque…

Apple fined $116 million in Italy

The Italian competition authority, Autorità Garante della Concorrenza e del Mercato, has fined Apple more than $116 million (€98.6 million) for abusing its dominant position in the market for app distribution to iOS users. The authority considers that Apple’s App Tracking Transparency (ATT) policy, introduced in 2021, inhibits competition. The policy requires third-party developers to obtain…

Infy Returns: Iran-linked hacking group shows renewed activity

Researchers report renewed activity by Iran-linked Infy (Prince of Persia), showing the hacking group remains active and dangerous after years of silence. SafeBreach researchers have spotted renewed activity from the Iran-linked APT group Infy, also known as Prince of Persia, nearly five years after its last known campaigns in Europe. SafeBreach warns the group remains…

Hackers exploit Microsoft OAuth device codes to hijack enterprise accounts

Cybercriminals and state-sponsored hackers are increasingly exploiting Microsoft’s legitimate OAuth 2.0 device authorization process to hijack enterprise accounts, bypassing multifactor authentication protections and gaining persistent access to sensitive organizational data, a report said. Researchers at Proofpoint tracked multiple threat clusters — both financially motivated and state-aligned — that were using device code phishing techniques to…

Russia was behind a destructive cyber attack on a water utility in 2024, Denmark says

Denmark has blamed Russia for a destructive cyberattack on a water utility, calling it part of Moscow’s hybrid campaign against Western critical infrastructure. Denmark has accused Russia of orchestrating destructive cyberattacks against a water utility in 2024, framing them as part of broader hybrid attacks on Western critical infrastructure. Denmark’s Defence Intelligence Service attributed a…

Iranian APT Prince of Persia returns with new malware and C2 infrastructure

Researchers have discovered new activity from a threat actor dubbed Prince of Persia that’s believed to be tied to the Iranian government. The group appeared to have gone dormant in 2022 after multiple security companies documented its operations and crippled its command-and-control infrastructure, but new evidence shows the attackers retooled and continued to target new…

Apple changes App Store in Japan

Imagine it’s possible to balance regulatory desires to limit Apple’s market power with the welfare of the company’s existing customer base. Imagine a regulatory environment characterized by mutual respect and a willingness to collaborate on solutions, a place where Apple is forced to change some of its business practices, but in ways that benefit both…

Apple changes App Store in Japan

Imagine it’s possible to balance regulatory desires to limit Apple’s market power with the welfare of the company’s existing customer base. Imagine a regulatory environment characterized by mutual respect and a willingness to collaborate on solutions, a place where Apple is forced to change some of its business practices, but in ways that benefit both…

Smashing Security podcast #448: The Kindle that got pwned

Think your Kindle is harmless? Think again! In this episode, we unpack a Black Hat Europe talk revealing how a boobytrapped audiobook could exploit the Amazon eBook reader – potentially letting an attacker break into your account and seize control of your credit card. Plus a blast from 2021’s “summer of ransomware” returns to haunt…

‘Ink Dragon’ threat group targets IIS servers to build stealthy global network

A Chinese-linked threat group identified as “Ink Dragon” is targeting common weaknesses in Internet Information Services (IIS) servers to build a global espionage network that is difficult to track or disrupt, security vendor Check Point has reported. Also nicknamed “Earth Alux,” (Trend Mico) and “REF7707” (Elastic Security Labs), the group’s activities date back to early…

GNV ferry fantastic under cyberattack probe amid remote hijack fears

French prosecutors probe a suspected cyberattack on GNV ferry Fantastic, raising concerns of a possible remote hijack. French prosecutors are investigating a suspected cyberattack on the GNV ferry Fantastic, raising fears of a potential remote hijack. The ferry Fantastic sails between Sète and North Africa, and French authorities are investigating a suspected attempt to compromise…

Apple in enterprise — industry execs on what works, and what they want in ’26

With Apple Silicon its current crown jewel, Apple has continued to rapidly build its presence in enterprise computing throughout 2025, generating significant market share gains as companies accelerate Apple deployments across their fleets. What’s driven Apple’s progress this year — and what should we expect from the company in the year ahead? To find out,…

French Interior Minister says hackers breached its email servers

The French interior minister confirmed that a cyberattack breached the Interior Ministry, compromising its email servers. The French Interior Minister Laurent Nunez announced on Friday that threat actors compromised email servers at the Ministry of the Interior. The attack was detected overnight between December 11 and 12, and according to the French interior minister, attackers…

Amazon Threat Intelligence identifies Russian cyber threat group targeting Western critical infrastructure

As we conclude 2025, Amazon Threat Intelligence is sharing insights about a years-long Russian state-sponsored campaign that represents a significant evolution in critical infrastructure targeting: a tactical pivot where what appear to be misconfigured customer network edge devices became the primary initial access vector, while vulnerability exploitation activity declined. This tactical adaptation enables the same…

Microsoft stellt neue Sicherheitsstrategie vor

Microsoft hat angekündigt, dass sein Bug-Bounty-Programm ausgeweitet werden soll. bluestork – shutterstock.com Cyberangriffe beschränken sich heutzutage nicht auf bestimmte Unternehmen, Produkte oder Dienstleistungen – sie finden dort statt, wo die Schwachstellen sind. Zudem werden die Attacken mit Hilfe von KI-Tools immer ausgefeilter. Vor diesem Hintergrund hat Microsoft seinen neuen Security-Ansatz „In Scope by Default“ auf…

Germany calls in Russian Ambassador over air traffic control hack claims

Germany summoned Russia’s ambassador over alleged cyberattacks on air traffic control and a disinformation campaign ahead of national elections. Germany summoned Russia’s ambassador after accusing Moscow of cyber attacks against its air traffic control authority and running a disinformation campaign ahead of February’s election. The German government announced it has clear evidence linking an August…

Trump directs Justice Department to challenge state AI laws

US President Donald Trump signed an executive order Thursday directing the Justice Department to challenge state artificial intelligence laws the administration says threaten US competitiveness. In his order, Trump is taking issue with state “requiring entities to embed ideological bias within models” — although the example he gave of embedding bias was “a new Colorado…

Is DORA Applicable in the US?

How DORA affects US ICT service providers DORA (the Digital Operational Resilience Act) is an EU regulation affecting financial entities that do business in the EU. These entities must ensure ICT third-party risk management, meaning that the DORA Regulation’s requirements trickle down to ICT service providers. If you’re offering ICT services to financial institutions in the…

10 Key EU GDPR Requirements

The EU GDPR (General Data Protection Regulation) places many obligations on organisations that process personal data – which is pretty much all of them.  Unsurprisingly, that can feel overwhelming. If you need a bit of help understanding what you need to do to comply with the Regulation, this blog provides a summary of ten key GDPR…

Polish Police arrest 3 Ukrainians for possessing advanced hacking tools

Poland arrested three Ukrainian nationals accused of using hacking devices to target IT systems and obtain sensitive defense-related data. Polish police arrested three Ukrainian nationals for allegedly trying to damage IT systems and obtaining sensitive defense-related data using advanced hacking equipment. The police arrested three Ukrainian men after finding Flipper hacking gear, spy-device detectors, SIM…

Vaillant CISO: NIS2 complexity and lack of clarity endanger its mission

CSO Germany: The energy sector is increasingly becoming a target for cybercriminals. Experts and the Federal Office for Information Security (BSI) believe that protection in this area must be significantly increased. How do you assess the current situation? Reiß: The geopolitical tensions we are currently witnessing are leading to an increased threat level. This naturally also affects the…

BlackFog Launches ADX Vision to Address Rising Shadow AI Risks

BlackFog, a developer of AI-based anti-data exfiltration technology, has launched ADX Vision — a new capability for its ADX Platform designed to secure all endpoints and the LLM interactions happening within them. Operating directly on the device, the new solution detects shadow AI activity, prevents unauthorized data movement in real-time, and enforces governance policies automatically,…

The new Apple thinks different?

The latest Apple leadership changes set the stage for a new approach from the company on a range of issues, including international relations, the environment, and beyond. If great artists steal, great leaders reflect the spirit of their age.  Apple’s current general counsel, Kate Adams, will leave late next year, following a transition to a new general…

End-to-end encryption is next frontline in governments’ data sovereignty war with hyperscalers

Data residency is no longer enough. As governments lose faith that storing data within their borders, but on someone else’s servers, provides real sovereignty, regulators are demanding something more fundamental: control over the encryption keys for their data. Privatim, a collective of Swiss local government data protection officers, last week called on their employers to…

EU ‘Chat Control’ proposals should be red flag to businesses everywhere

Data privacy campaigners have warned that any celebration of the news that the European Union (EU) has abandoned its plans to break end-to-end encryption in mobile messaging apps could be short-lived.  According to one expert, this announcement should be a “red flag” to organizations operating within Europe. There has been a long-standing threat to end-to-end…

EU ‘Chat Control’ proposals should be red flag to businesses everywhere

Data privacy campaigners have warned that any celebration of the news that the European Union (EU) has abandoned its plans to break end-to-end encryption in mobile messaging apps could be short-lived.  According to one expert, this announcement should be a “red flag” to organizations operating within Europe. There has been a long-standing threat to end-to-end…

Asahi says crooks stole data of approximately 2M customers and employees

Asahi says hackers stole data of approximately 2M customers and employees before a ransomware attack crippled its Japan operations. Threat actors hit Asahi with a ransomware attack in September, stealing personal data on about 2 million customers and employees and severely disrupting the company’s operations in Japan. Asahi Group Holdings, Ltd (commonly called Asahi) is…

The Broadcom VMware Acquisition: 2025 Recap on Channel Changes

Broadcom’s purchase of VMware is one of the most significant technology acquisitions in recent years. This acquisition reshapes the enterprise IT landscape by combining Broadcom’s hardware expertise with VMware’s cutting-edge virtualization and cloud solutions.  While Broadcom’s streamlined, profit-driven approach aims to enhance VMware’s efficiency, it has also raised concerns among customers and channel partners who…

Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’

A prolific cybercriminal group that calls itself “Scattered LAPSUS$ Hunters” has dominated headlines this year by regularly stealing data from and publicly mass extorting dozens of major corporations. But the tables seem to have turned somewhat for “Rey,” the moniker chosen by the technical operator and public face of the hacker group: Earlier this week,…

Sturnus: New Android banking trojan targets WhatsApp, Telegram, and Signal

The Android trojan Sturnus targets communications from secure messaging apps like WhatsApp, Telegram and Signal. Sturnus is a new Android banking trojan with full device-takeover abilities. It bypasses encrypted messaging by capturing on-screen content and can steal banking credentials, remotely control the device, and hide fraudulent actions from the user. ThreatFabric analysis shows Sturnus malware…

WrtHug Exploits Six ASUS WRT Flaws to Hijack Tens of Thousands of EoL Routers Worldwide

A newly discovered campaign has compromised tens of thousands of outdated or end-of-life (EoL) ASUS routers worldwide, predominantly in Taiwan, the U.S., and Russia, to rope them into a massive network. The router hijacking activity has been codenamed Operation WrtHug by SecurityScorecard’s STRIKE team. Southeast Asia and European countries are some of the other regions…

Multiple Vulnerabilities in GoSign Desktop lead to Remote Code Execution

Researchers found a critical vulnerability in GoSign Desktop: TLS Certificate Validation Disabled and Unsigned Update Mechanism. GoSign is an advanced and qualified electronic signature solution developed by Tinexta InfoCert S.p.A., used by public administrations, businesses, and professionals to manage approval workflows with traceability and security. The SaaS/web version of the product has received the “QC2”…

GRC Solutions Named Among the UK’s Top 20 Cyber Security Innovators

We’re delighted to announce that GRC Solutions – the new name for IT Governance – has been recognised as one of the UK’s leading cyber security companies, ranking 19th in TechRound’s Cybersecurity40 2025 list. The annual campaign celebrates the most innovative and forward-thinking cyber security organisations across the UK and Europe, highlighting those helping businesses…

Apple shows that App Store liberalization does nothing for users

In a reality attack destined no doubt to be completely ignored by ideologically deluded regulators and cash-hungry competitors, Apple has published an extensive report that proves the anticipated benefits of lower App Store commissions are not reaching European consumers at all.  Not only that, but even the developers who do benefit from this ham-fisted attempt at market liberalization aren’t…

Gartner: European IT leaders to boost spending on local clouds amid geopolitical worries

Western European organizations are ramping up investments in local and regional cloud providers because growing geopolitical tensions are raising concerns that access to global cloud services could be disrupted for political reasons. A survey of 214 CIOs and IT leaders in Western Europe, conducted by Gartner between May and June, found that more than 61% plan to increase their reliance…

EU-Kommission will DSGVO für KI und Cookie-Tracking lockern

srcset=”https://b2b-contenthub.com/wp-content/uploads/2025/11/shutterstock_2645792213.jpg?quality=50&strip=all 4032w, https://b2b-contenthub.com/wp-content/uploads/2025/11/shutterstock_2645792213.jpg?resize=300%2C168&quality=50&strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2025/11/shutterstock_2645792213.jpg?resize=768%2C432&quality=50&strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/11/shutterstock_2645792213.jpg?resize=1024%2C576&quality=50&strip=all 1024w, https://b2b-contenthub.com/wp-content/uploads/2025/11/shutterstock_2645792213.jpg?resize=1536%2C864&quality=50&strip=all 1536w, https://b2b-contenthub.com/wp-content/uploads/2025/11/shutterstock_2645792213.jpg?resize=2048%2C1152&quality=50&strip=all 2048w, https://b2b-contenthub.com/wp-content/uploads/2025/11/shutterstock_2645792213.jpg?resize=1240%2C697&quality=50&strip=all 1240w, https://b2b-contenthub.com/wp-content/uploads/2025/11/shutterstock_2645792213.jpg?resize=150%2C84&quality=50&strip=all 150w, https://b2b-contenthub.com/wp-content/uploads/2025/11/shutterstock_2645792213.jpg?resize=854%2C480&quality=50&strip=all 854w, https://b2b-contenthub.com/wp-content/uploads/2025/11/shutterstock_2645792213.jpg?resize=640%2C360&quality=50&strip=all 640w, https://b2b-contenthub.com/wp-content/uploads/2025/11/shutterstock_2645792213.jpg?resize=444%2C250&quality=50&strip=all 444w” width=”1024″ height=”576″ sizes=”auto, (max-width: 1024px) 100vw, 1024px”>Die vorgeschlagenen Änderungen der EU-Kommission durch das „Digital Omnibus”-Paket gefährden laut Datenschützern die DSGVO. Alicia97 – shutterstock.com Laut einem durchgesickerten Entwurf, über den die deutsche Interessenvertretung Netzpolitik.org…

Denmark and Norway investigate Yutong bus security flaw amid rising tech fears

Denmark and Norway probe a security flaw in Chinese-made Yutong buses, deepening European fears over reliance on Chinese tech and potential cyber risks. Bus operators in Denmark and Norway are urgently probing a security vulnerability in Chinese-made Yutong electric buses, raising concerns about Western dependence on Chinese technology. The issue highlights growing European fears that…

European Commission moves to loosen GDPR for AI and cookie tracking

The European Commission is preparing sweeping revisions to the General Data Protection Regulation (GDPR) that could redefine how enterprises handle personal data — from cookie tracking to AI model training — in what privacy advocates warn could weaken the EU’s privacy framework. According to a leaked draft reported by German advocacy group Netzpolitik.org, the Commission’s upcoming…

European Commission moves to loosen GDPR for AI and cookie tracking

The European Commission is preparing sweeping revisions to the General Data Protection Regulation (GDPR) that could redefine how enterprises handle personal data — from cookie tracking to AI model training — in what privacy advocates warn could weaken the EU’s privacy framework. According to a leaked draft reported by German advocacy group Netzpolitik.org, the Commission’s…

Apple’s war in Europe

Some say good government is less government. Others have a different point of view. But the least you should be able to expect from any kind of governance is that following one law doesn’t force you to break another. That is, unless you’re Apple and the laws are made in Europe. In a letter seen by Computerworld,…

Windows 10’s market share is more than hanging in there despite being at end of support

Statistics released Tuesday by web traffic analysis site Statcounter reveal a stark difference around the globe when it comes to Windows 11 adoption, with North America and South America far outpacing other regions, including Europe. The findings, which are based on statistics compiled daily, show that the Windows 11 market share in North America was…

Crowdstrike cybersecurity report highlights a spike in physical attacks on privileged users

While tracking cyberattacks since last year, a Crowdstrike report also found that physical attacks and kidnappings have increased dramatically, particularly in Europe. “In January 2025, threat actors kidnapped and attempted to extort the co-founder of Ledger, a prolific cryptocurrency wallet vendor, in France,” the Crowdstrike report said. “Although the threat actors in this case and…

How DORA fits with ISO 27001, NIS2 and the GDPR

Although DORA (the EU Digital Operational Resilience Act) has been in effect since January 2025, organisations that supply the EU’s financial services sector are under growing pressure to demonstrate compliance with its requirements. For most, this isn’t about starting from scratch but about mapping what’s already in place, identifying where DORA goes further and then…

Tech companies break records, spending more money than ever on lobbying the EU

Major US tech companies are spending more money than ever lobbying the EU to influence its digital rules, Politico reports. Artificial intelligence and rules such as the Digital Markets Act (DMA) and the Digital Services Act (DSA) will be a particular focus. A new analysis shows that 733 digital sector players together spend around €151…

Everest group claimed the hack of Sweden’s power grid operator Svenska kraftnät

Hackers hit Sweden’s power grid operator Svenska kraftnät, stealing data via a file transfer tool. The power grid was not affected. Hackers breached Sweden’s state-owned power grid operator Svenska kraftnät, stealing data from an isolated file transfer system. The power grid operations were not impacted by the cyber incident. The Swedish company on Monday disclosed…

Apple may turn off key privacy tool in Europe

In a victory for surveillance capitalism, Apple may be forced to leave its users in Europe vulnerable to rapacious ad data collection in response to “intense lobbying” by politicians in the region. Apple warns these lobbying efforts mean the App Tracking Transparency (ATT) feature, which helps prevent apps from tracking what you do across services and websites for advertising purposes,…

UN agreement on cybercrime criticized over risks to cybersecurity researchers

Cybersecurity researchers could face criminal charges for performing their legitimate work if the United Nations Convention against Cybercrime is ratified in a process beginning in Hanoi, Vietnam, this weekend, critics say. Tech industry group Cybersecurity Tech Accord said today that little has changed since it presented a detailed critique of the UN Convention against Cybercrime…

Lazarus group targets European drone makers in new espionage campaign

Cybersecurity researchers from ESET have identified a new Lazarus Group campaign targeting European defense contractors, particularly those involved in unmanned aerial vehicle (UAV) development. According to ESET findings, the threat actors used fake job offers and trojanized open-source software, as is customary in their Operation Dreamjob campaigns, to infiltrate their targets. “Some of these are…

North Korea’s Lazarus group attacked three companies involved in drone development

North Korea’s Lazarus threat group attacked three Europe-based companies with active operations in the defense sector last spring to potentially steal sensitive data about drone components and software, ESET researchers said in a report released Thursday. The attacks initiated by North Korea’s long-running advanced persistent threat group, which specializes in espionage, sabotage and financial gain,…

Lazarus targets European defense firms in UAV-themed Operation DreamJob

North Korean Lazarus hackers targeted 3 European defense firms via Operation DreamJob, using fake recruitment lures to hit UAV tech staff. North Korea-linked Lazarus APT group (aka Hidden Cobra) launched Operation DreamJob, compromising three European defense companies. Threat actors used fake recruiter profiles to lure employees into UAV technology roles, aiming to gain access to…