Weekly Backlog Week 31/2026
🧠Editorial This edition primarily focuses on digital sovereignty—from both a technical and …

Hugging Face operates the world’s largest directory for open-source AI models. Millions of developers and companies use the platform daily.
The company has now disclosed an unusual security incident: For the first time, an attack has been documented that, according to Hugging Face, was entirely conducted by an autonomous AI agent system. The agent exploited vulnerabilities in data processing, gained access to internal systems, collected credentials, and independently navigated through multiple clusters.
Publicly available models, datasets, or the software supply chain have not been manipulated according to current findings. The incident was limited to parts of the internal infrastructure. Investigations are ongoing.
Equally interesting, however, was the subsequent analysis.
Hugging Face initially attempted to investigate the attack using leading commercial AI models. This failed. The models blocked the analysis because they classified exploits and command-and-control artifacts as potentially abusive. Only a locally operated open-weight model from Z.ai could support the forensic evaluation.
The real wake-up call is therefore not the attack itself.
It shows that security tools are only as useful in an emergency as their operators are allowed to use them. Those who become entirely dependent on the rules of external AI providers risk being restricted at the crucial moment.
Especially for Europe, this is another argument for open, self-operable AI models. Digital sovereignty is not only decided at chips or data centers—but also with the tools we use to defend ourselves.
đź”— https://thehackernews.com/2026/07/worlds-largest-ai-model-repository.html
SonicWall has confirmed that two previously unknown vulnerabilities in the SMA-1000 VPN appliances have already been exploited before security updates were available. Security researchers from Volexity believe the attacks began at the end of June.
The attackers combined both zero days into an attack chain that granted them root privileges on the affected systems. They then installed specially developed malware, set up backdoors, and collected credentials. Particularly concerning: The VPN appliance itself became the starting point for the attack on the corporate network.
Only devices in the SMA-1000 series are affected. SonicWall provides security updates and recommends that compromised systems not only be patched but also thoroughly forensically examined.
The incident once again highlights a fundamental problem.
VPN gateways, firewalls, and other perimeter systems are supposed to protect companies. At the same time, they have become some of the most attractive targets for attacks. Compromising these systems bypasses many classic security mechanisms with a single successful attack.
Therefore, it is no longer sufficient to simply update security products regularly. They must be continuously monitored, checked for anomalies, and treated as potentially compromised if in doubt.
The greatest danger today often lies not in whether a security product is attacked—but in the fact that no one notices when it has already happened.
đź”—https://thehackernews.com/2026/07/sonicwall-sma-zero-days-exploited.html
Since Donald Trump’s second term, digital sovereignty has been one of the most frequently mentioned political goals in Europe. New AI initiatives, billions for data centers, and ambitious strategies are intended to reduce dependency on the USA.
However, a new analysis by Forrester comes to a sobering conclusion: By 2030, Europe will make little progress in digital sovereignty. In the forecast model, Germany improves only from 34 to 36 percent. France reaches 35 percent. The USA stands at 79 percent, and China even at 82 percent.
The reason is simple.
Digital sovereignty does not arise from building data centers alone. What matters are the technologies running in them: semiconductors, software, AI models, and the associated supply chains.
This is exactly where Europe remains dependent.
In modern chips, the USA and Asia dominate. In cloud platforms, hyperscalers control the market. In AI, the most powerful models predominantly come from the USA or increasingly from China. Even European digitization projects often rely on technologies developed and controlled outside Europe.
Those who do not master these key technologies themselves cannot buy digital sovereignty.
Europe therefore needs more than funding programs and strategy papers. It needs consistent investments in open source, European software, its own AI models, semiconductor competence, and an independent digital infrastructure.
As long as we primarily finance infrastructure operated with non-European technology, we do not create digital sovereignty. We merely shift our dependencies.
An alleged member of the hacker group Scattered Spider tried to cover their tracks with a VPN. Apparently, that was not enough.
According to a now-published US indictment, the FBI was able to identify the suspect using Microsoft data. The decisive factor was the so-called Global Device Identifier (GDID)—a unique identifier assigned to every Windows installation. Together with other telemetry data, the use of the device could be linked to various online services and times.
For law enforcement, this is a success.
For Windows users, however, the case raises fundamental questions.
Most users probably do not yet know the term GDID or what information Windows collects as part of its telemetry and under what circumstances it can be released to investigative authorities. Only the publication of the court documents made these connections visible.
This is not about defending an alleged cybercriminal. If telemetry data helps solve serious crimes, that is fundamentally understandable.
The real debate begins at another point.
Anyone using an operating system should be able to understand what data is collected, how long it is stored, and what it can be used for. Transparency should not only arise when it appears in an indictment.
Digital sovereignty means not only having control over infrastructure. It also means knowing what data your own software generates—and who can ultimately access it.
đź”—https://ca.news.yahoo.com/hacker-arrest-just-revealed-microsoft-195114716.html

Discusses power and dependency structures in hybrid clouds and their contribution to digital sovereignty.
đź”— https://www.cloudahead.de/machen-hybride-clouds-souveraen
An analytical look at capital flows in AI business models; discussion of platform power, return cycles, and geopolitical implications.
đź”— https://www.metacheles.de/kreislauf-invest-wie-big-techs-ki-umsaetze-sich-im-kreis-drehen/
EU cloud sovereignty: Framework enables objective evaluation of cloud offerings; shows impacts on hyperscalers, regulation, and infrastructure sovereignty in practice.
With Kiro, AWS has introduced an AI-powered development assistant that helps programmers write and edit code. Security researchers have now discovered a vulnerability that showed the risk when AI agents are allowed to independently use tools and make system changes.
The attack was surprisingly simple: A developer only had to ask Kiro to summarize the content of a prepared webpage. The source code of the page contained invisible instructions intended not for humans but specifically for the AI agent. Kiro interpreted these instructions as legitimate work orders, changed its own configuration, and could then execute arbitrary code on the developer’s computer. AWS has since fixed the vulnerability.
Remarkable is not so much the specific programming error as the attack method. The webpage contained no classic malware but a Prompt Injection. This does not exploit a software gap but manipulates the language model itself. For the AI agent, the hidden instructions were not data but commands.
The incident makes it clear that AI agents represent a new security class. As soon as they are allowed to change files, execute shell commands, or control development environments, classic protection mechanisms are no longer sufficient. The integrity of the model alone is not a security guarantee.
Companies should therefore treat AI agents like highly privileged software: with minimal permissions, clear security boundaries, and independent control mechanisms. The more autonomy an agent receives, the greater the attack surface becomes.
đź”— https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html
đź’šIn Our Own Matter:
A Year of Pseudo-Sovereignty.
A year ago, Microsoft opened its Cloud Region Austria. Since then, much has been said about digital sovereignty. About data retention in Austria. About compliance. About resilience.
The problem is: None of this makes Europe more sovereign.
An Azure data center in Austria remains Azure. The platform belongs to Microsoft. The software comes from Microsoft. Microsoft decides on further development. The economic value creation ends up with Microsoft.
Europe provides the location. Microsoft retains control.
This is precisely the fallacy in European digital policy. We celebrate infrastructure while leaving the actual dependency untouched.
Digital sovereignty does not arise where servers stand. It arises where operating systems, cloud platforms, AI models, and software are developed.
Those who do not own the key technologies themselves remain dependent—regardless of whether the data center is in Vienna, Frankfurt, or Dublin.
Therefore, a Microsoft cloud in Austria is not a milestone of European sovereignty.
It is a milestone for Microsoft.
As long as Europe confuses the success of American hyperscalers with its own digital sovereignty, nothing will change in our technological dependency. We build the infrastructure for foreign ecosystems—and call it progress.
Digital sovereignty only begins when Europe strengthens its own platforms, strategically promotes open source, and…
🧠Editorial This edition primarily focuses on digital sovereignty—from both a technical and …
đź“°Tech-News: The First Documented AI Agent Hack is Here Hugging Face operates the world’s …
🧠Editorial This week had it all: open databases, open GitHub repositories, open questions about …