惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

阮一峰的网络日志
阮一峰的网络日志
J
Java Code Geeks
Martin Fowler
Martin Fowler
宝玉的分享
宝玉的分享
V
Visual Studio Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
M
MIT News - Artificial intelligence
U
Unit 42
博客园 - 三生石上(FineUI控件)
博客园 - 聂微东
The GitHub Blog
The GitHub Blog
I
InfoQ
WordPress大学
WordPress大学
H
Help Net Security
D
Docker
B
Blog
腾讯CDC
A
About on SuperTechFans
Recent Announcements
Recent Announcements
雷峰网
雷峰网
有赞技术团队
有赞技术团队
C
Check Point Blog
Y
Y Combinator Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC

Security Affairs

Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network 12-year-old Pack2TheRoot bug lets Linux users gain root privileges Signal phishing campaign targets Germany’s Bundestag President Julia Klöckner
Dutch Government just said no to an American firm buying ...
Pierluigi Paganini · 2026-05-27 · via Security Affairs

The Dutch government blocked Kyndryl’s €100M bid for Solvinity, citing national security concerns over critical digital infrastructure.

Dutch Government told Kyndryl it can’t buy Solvinity. That sentence doesn’t sound dramatic, but what it means is this: a European government just blocked an American IT company from acquiring the firm that runs DigiD, the platform Dutch residents use to book a doctor’s appointment, buy a house, file their taxes, and interact with virtually every public service in the country. The deal was worth roughly €100 million. The Dutch government said no anyway.

“The Dutch government is blocking a United States-based company’s attempts to acquire a key online identification IT supplier.” reads the post published by Politico.

Kyndryl announced the acquisition in November 2025. The reaction was immediate. Concerns spread that a critical piece of Dutch digital infrastructure would fall under foreign control, and the investment screening authority took those concerns seriously. State Secretary for Digital Economy Willemijn Aerdts wrote to parliament on Tuesday to confirm the government had adopted the authority’s advice in full. The purchase was seen as posing “a possible risk to the public interest”

The Dutch government was careful to frame the decision as principled rather than anti-American.

“The Netherlands attaches great value to the presence of foreign, especially U.S.-based tech companies, and their added value to the Dutch economy and digital infrastructure, but it maintains, at the same time, an independent investment screening framework aimed at protecting the public interest and which applies equally to all investors, independent of their country of origin.” states the letter to parliament.

The underlying concern is the US CLOUD Act. Passed in 2018, it gives American law enforcement and intelligence agencies the power to compel US companies to hand over data stored on servers anywhere in the world, regardless of the host country’s privacy laws. If Kyndryl owned Solvinity, the data behind the Dutch national identity system would theoretically be reachable by US authorities on demand. That’s not a hypothetical Europe wants to test right now.

Kyndryl didn’t take it quietly. The company called the decision “extremely disappointed” and went further: “The politicization of this process has overshadowed the clear and important benefits this transaction would have brought to Solvinity’s customers and Dutch citizens.”

It’s a pointed line. Whether the process was politicized or simply working as designed depends on where you sit.

The timing matters beyond the Netherlands. The decision lands a week before the European Commission unveils its tech sovereignty package, a set of proposals to cut Europe’s dependence on foreign technology across cloud, microchips, and AI. The Dutch block gives Brussels a concrete, live example to point to. What The Hague did with one screening authority this week, Brussels may soon ask every member state to replicate by law.

For any American technology company selling cloud or managed services to European public institutions, the message is plain. A signed deal and a clean antitrust review aren’t enough. The question regulators are now asking is simpler and harder: can you guarantee that your own government can’t reach into European data when it decides to? Most US companies can’t honestly answer yes.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Dutch Government)