This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
Cybersecurity Outlook 2026 | August
However, in future social engineering and fraud campaigns, using data of physical and legal persons obtained from the CSDD cyber incident, scammers can make them significantly more convincing and personalized, for example by indicating the recipient's name, surname, personal code, or specific vehicle registration number. Investment fraud remains one of the most prevalent forms of scams. This free protection solution is available to every resident and organization in Latvia and helps block access to known fraudulent and malicious sites, thereby significantly reducing cybersecurity risks. Timely updates are one of the simplest and most effective ways to reduce attack risks. More details: https://cert.lv/lv/2026/08/kritiska-ievainojamiba-wordpress-spraudni-elementor-pro-cve-2026-32475. A code injection vulnerability (CVE-2026-19478) with a CVSS score of 9.4 has been identified in the GitLab CE/EE platform, actively exploited in cyberattacks. More details: https://cert.lv/lv/2026/08/kritiska-ievainojamiba-gitlab-platforma-cve-2026-19478. Ubiquiti has released security updates addressing multiple vulnerabilities in UniFi products, including three critical ones with CVSS score 10.0. More details: https://cert.lv/lv/2026/08/bridinajums-ubiquiti-iekartu-lietotajiem. A vulnerability (CVE-2026-65643) has been found in the cPanel & WHM domain parking feature. More details: https://cert.lv/lv/2026/08/ievainojamiba-cpanel-whm-programmatura. Red Hat's identity access management solution KeyCloak (Red Hat Build of Keycloak) has a critical vulnerability (CVE-2026-18963) with a CVSS score of 9.1, allowing unauthenticated users to reset any system user's password. During inspections of NERO R-ONE cameras and devices from the CORDON series associated with the Russian manufacturer “Simicon,” discrepancies between documented and actual device configurations, unclear hardware and software origins, weak security mechanisms, and pre-configured remote access functionalities were identified.