惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

C
Check Point Blog
罗磊的独立博客
量子位
Microsoft Azure Blog
Microsoft Azure Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
J
Java Code Geeks
M
MIT News - Artificial intelligence
月光博客
月光博客
IT之家
IT之家
D
DataBreaches.Net
A
About on SuperTechFans
博客园 - 三生石上(FineUI控件)
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Last Week in AI
Last Week in AI
D
Docker
The GitHub Blog
The GitHub Blog
B
Blog
V
Visual Studio Blog
博客园 - Franky
N
Netflix TechBlog - Medium
博客园 - 【当耐特】
Martin Fowler
Martin Fowler
博客园 - 聂微东
U
Unit 42

The Register - Security: Cyber-crime

Election interlopers register 5K+ domains, hope to catch some voting phish Palo Alto VPN bug graduates from advisory to active exploitation ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak Carnival confirms ShinyHunters cruised off with 6M customer records after April breach CrowdStrike, Google shatter Glassworm botnet MyPillow must decide whether to be firm or soft as ransomware crims demand pay A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Shai-Hulud copycat worm infects yet another npm package Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Cache-poisoning caper turns TanStack npm packages toxic 'CopyFail' attackers start cashing in on Linux flaw Cushman & Wakefield confirms vishing cyberattack ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Critical cPanel exploited: 'Millions' of sites could be hit Pro-Iran group turns Ubuntu DDoS into shakedown French prosecutors link 15-year-old to gov mega-breach UK business breach rate stuck at 43%... blame the phishing What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Chinese spy group caught lurking in Poland, Asia networks Don’t pay VECT a ransom - your big files are likely gone Pitney Bowes the latest victim of ShinyHunters’ breach-spree Ongoing supply-chain attack targets security, dev tools Medical and utility tech companies admit digital breakins Burglar alarm biz gets burgled, ShinyHunters pursues ransom Crime crew impersonates help desk, abuses Teams chats ShinyHunters claim they have cruise giant Carnival’s booty
European Commission admits breach of public web systems
2026-03-30 · via The Register - Security: Cyber-crime

Cyber-crime

European Commission admits attackers broke into public web systems, but says little else

Brussels notifying 'Union entities' whose data may've been snatched in websites breach

The European Commission has admitted that attackers broke into its public-facing web infrastructure and siphoned off data in a bare-bones disclosure that answers the what but ducks most of the how.

The intrusion was spotted on March 24 and hit cloud systems hosting the Commission's Europa websites, the front door for everything from policy pages to public information. Officials say they contained the incident quickly and that the sites stayed online, so there was no obvious outage while someone was poking around the back end.

What that someone actually got is another matter. The Commission says data may have been exfiltrated, but leaves it there. There are no details about what kind of data was taken, how much, or who might be affected. There's also no word on initial access, how long the attackers had access, or who might be responsible.

REG AD

"Early findings of our ongoing investigation suggest that data have been taken from those websites," the EC said. "The Commission is duly notifying the Union entities who might have been affected by the incident. The Commission's services are still investigating the full impact of the incident."

REG AD

For an institution that often emphasizes breach transparency, it's a pretty thin statement. The European Commission did not respond to The Register's questions.

While the EC isn't saying much, reports claim a threat actor may have gained access to the Commission's AWS cloud environment and exfiltrated more than 350 GB of data

One line the Commission is keen to stress is that internal systems were not affected, at least based on what it knows so far. If that assessment holds, it suggests reasonable separation between public web services and the core network, limiting how far an attacker could go once inside.

Even so, this is the Commission's second security headache in quick succession. Just last month, Brussels admitted that Commission-issued mobile phones had been compromised, an intrusion that "may have resulted in access to staff names and mobile numbers of some of its staff members."

The EC's barely there statement leans on the usual line about Europe facing constant cyber pressure, with references to NIS2 and other initiatives. That may be true, but it doesn't explain how this one happened – or why there's so little detail about it. ®