Today in European Digital
Berlin's ransomware leak shows disclosure rules aren't defense

Google patched twelve Chrome vulnerabilities this week, among them a V8 flaw already under active attack, six days before the EU's Cyber Resilience Act forces manufacturers to report exploited flaws within 24 hours. Call it coincidence or a vendor reading the deadline correctly: either way, the patch landed with the urgency the new rule is meant to enforce. The same week, Berlin's public administration found the limits of what any disclosure rule can do. The city refused a two million euro ransom, and hackers leaked six terabytes of its data anyway, including infrastructure maps and the personal details of citizens and staff.
These are not the same failure. The Cyber Resilience Act governs what happens after a vulnerability is found: report it fast, patch it fast, tell the regulator. Berlin's case is about what happens once an attacker is already inside and has already taken the data. No reporting deadline retrieves six terabytes from the dark web, and no amount of regulatory maturity substitutes for the harder, slower work of keeping attackers out and holding usable backups when they get in anyway. As Pplware reports, Berlin chose not to fund the people who took its data, which is the right call and, on its own, not a cybersecurity strategy.
A disclosure deadline does not retrieve six terabytes from the dark web.
A second story this week is about control rather than crime. CISPE, the European cloud industry association, told the Commission that Broadcom's strategy for enterprise AI is designed to lock customers into its own stack, as Heise reports. This is not CISPE's first complaint about the company: in March it called Broadcom's purge of VMware's independent partners a "death sentence" for European cloud providers. Six months on, the fight has moved from who gets to resell virtualisation software to who gets to build the enterprise AI layer on top of it, and it is the same European digital sovereignty question this column keeps returning to, now one level higher in the stack.
Consumers…
If your personal data touched Berlin's public administration, in the exposed infrastructure maps or the staff and citizen records now on the dark web, treat unexpected calls or emails referencing your details with more suspicion than usual for the coming months. That is the one direct consumer exposure from either story this week; the Broadcom fight plays out one layer up, in the enterprise cloud contracts that keep the consumer-facing services you use running, not in anything you buy or click on directly.
Businesses…
Six days is not much runway if the Cyber Resilience Act's 24-hour exploited-vulnerability reporting duty is not already built into your incident response process, and Google's patch, landing just ahead of that date, is a reasonable signal that vendors are already treating the deadline as a real constraint rather than a formality. Separately, any business running enterprise workloads on Broadcom's VMware stack should read CISPE's complaint as a warning about where that dependency is heading next: from licensing terms to AI infrastructure control. OVHcloud and other European cloud providers are not a drop-in replacement for an existing VMware estate, but they are the concrete alternative to point a migration plan at before the decision gets made for you.
Government…
Berlin's refusal to pay is consistent with the harder line European public administrations have increasingly taken on ransom demands, and it is the right policy on its own terms: paying finances the next attack. But the leak that followed it is a reminder that the policy only holds up when paired with prevention and recovery capacity that most public administrations, Berlin included, still do not visibly have. The Cyber Resilience Act gives national authorities like Germany's BSI new enforcement teeth over vendors; under that law specifically, it gives them no authority over an administration's own security posture, which remains a separate and unfinished job.
Why this matters for European digital sovereignty
Today pairs the two tracks this column keeps distinguishing between: the regulatory one, which is advancing on schedule, and the infrastructural one, which no rulebook reaches. The Cyber Resilience Act's 24-hour reporting duty is real teeth, not aspiration, arriving in six days and already shaping how Google discloses. But Berlin's leak is proof that mandatory disclosure of future vulnerabilities does nothing for data an attacker already took before any deadline existed. Digital sovereignty on the cybersecurity front means owning detection and backup capacity, not only the paperwork that follows a breach. CISPE's escalation against Broadcom is the same argument one layer up the stack: a European cloud lobby that filed a formal complaint over VMware licensing in March is now warning that the same company is positioning itself to gatekeep enterprise AI too, a second attempt at controlling a layer no single vendor should own outright. Both stories point to the same unfinished European task: rules alone do not create resilient infrastructure or a competitive cloud market. Enforcement, investment and genuine European alternatives such as OVHcloud are what actually close that gap.
Sources
- Google patched a Chrome V8 zero-day exploited in the wild days before the EU Cyber Resilience Act's 24-hour exploited-vulnerability reporting duty takes effect · The Next Web
- CISPE warned that Broadcom's enterprise AI strategy is designed to control customer choice, prompting formal EU complaints · Heise Online
- Berlin's public administration refused a two million euro ransom demand and had six terabytes of data leaked on the dark web anyway · Pplware
This daily debrief is published every evening. Source links lead to the original reporting.
European Alternatives You Might Like
Pixelfed
Pixelfed is a decentralized, open-source social media platform for sharing images. Users can upload and share photos, follow other users, and interact through likes, comments, and shares. Utilizing the ActivityPub protocol, Pixelfed allows for federation, enabling users to interact with individuals on other compatible platforms. It is designed for photographers and anyone seeking a privacy-focused, community-driven alternative to centralized image-sharing services.

Element (Matrix)
Element is a secure, decentralized communication platform built on the Matrix protocol. It allows users to send end-to-end encrypted messages, share files, and participate in group chats. Key features include voice and video calls, bridging with other communication platforms like Slack and Discord, and the ability to host your own server for enhanced privacy and control. Element is suitable for individuals, teams, and organizations seeking secure and private communication, and is particularly beneficial for those who value data sovereignty and open-source solutions.
SoundCloud
SoundCloud is a digital audio distribution platform where users can upload, promote, and share their original music and audio. Key features include music streaming, direct messaging, commenting, and the ability to follow artists and playlists. This platform is primarily used by independent musicians, DJs, and podcasters to share their work, connect with listeners, and build an audience. SoundCloud offers a vast library of user-generated content, providing access to a wide range of music and audio not always available on other streaming services.
Ecosia
Ecosia is a search engine that utilizes ad revenue to fund tree-planting initiatives. Users can perform web searches using the same technology as Bing, accessing search results, images, videos, and news. A counter displays the number of trees planted through user searches, and the company reports on its financial activities, including its impact on the environment and carbon neutrality. Ecosia's primary benefit is its commitment to environmental sustainability, appealing to users who want to support reforestation efforts while browsing the internet.
