This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
Cyber Weather 2026 | April
In April's overview: false reports about cloud storage limits and payment issues, urgent updates of bank account data, eSignature requests for shipment delivery, data breaches at booking.com and Rituals, impersonation of Apple Pay support service, and thousands of compromised TP-Link routers. A notable trend in April was the spread of fake notifications mimicking popular email service providers (iCloud, Google, Inbox), such as urgent updates to payment details or increasing mailbox storage limits. Users who haven't done so are advised to install manufacturer-provided patches as soon as possible, following instructions on support.cpanel.net. In April, a high-severity security vulnerability in the Linux kernel was discovered - CVE-2026-31431 with a CVSS score of 7.8. Additional information: https://copy.fail/ In an international operation coordinated by Europol called “Power OFF,” law enforcement agencies across the European Union targeted malicious “DDoS-for-hire” platforms that overload websites, making them temporarily inaccessible. According to The Guardian, hackers may have accessed some client data, including names, email addresses, phone numbers, and reservation details. As reported by cysecurity.news, the goal of these schemes was not to hack the iPhone itself but to induce users to panic and voluntarily disclose sensitive information—such as Apple ID data, verification codes, banking information, or even transfer money to supposedly “secure” accounts.