ZeroHour

Search: “Norwegian public services”

27 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Large DDoS attack knocks Norwegian public services offline

A large DDoS attack on Norwegian IT partner Vivicta disrupted 10 government services, including ID-porten used by over 4.5 million users, for 30+ hours.

Norway's Digitalisation Agency (Digdir) said a distributed denial-of-service attack that began Monday targeted the infrastructure of its IT partner Vivicta and lasted around 30 hours at varying intensity, with some services still affected Tuesday. Disrupted services included ID-porten, a national digital identity gateway used by more than 4.5 million people, which many government services and parts of the health sector, such as online pharmacies and the electronic prescription system, rely on for authentication. Digdir said attackers did not gain access to sensitive information, and it was the third DDoS incident since June, reportedly two to three times larger than the previous one. Attribution and possible links between the incidents remain unclear.

The Record · 22d agoThreat actor

DDoS Attack Hits Norwegian Government Services

A coordinated DDoS campaign disrupted Norwegian government online services, causing availability outages across public digital services.

A coordinated distributed denial-of-service campaign caused disruption to Norwegian government digital services, according to Infosecurity Magazine. The attack affected the availability of public-facing services, and no data compromise was indicated in initial reporting. The responsible group or motive was not named in the report.

Infosecurity Magazine · 21d agoThreat actor

Cyber Security News

Microsoft's September Patch Tuesday fixes nearly 1,000 vulnerabilities; CISA warns two of the flaws are being actively exploited.

Microsoft's September 2026 Patch Tuesday release addresses close to 1,000 vulnerabilities, with CISA warning that two of the bugs are being actively exploited. The Record's homepage digest also lists briefs including a US offer of $10 million for information on an Iranian hacker accused of attacking critical infrastructure and a leak of health data on more than 9.5 million people from the Aesto record system. Additional briefs cover a Russian suspect's extradition to the US for bank account takeovers, US-British coordination on scam center takedowns, G7 guidance on quantum cyber threats, a large DDoS attack on Norwegian public services, and Slovenian casinos reopening after a cyberattack.

The Record · 7d agoVulnerability in the wild

Norway announces investigations into telecom Telenor’s work with Myanmar junta

Norwegian police opened crimes-against-humanity and sanctions investigations into Telenor's data handovers to Myanmar's junta, raiding its Oslo headquarters.

Norway's National Criminal Investigation Service is investigating Telenor for complicity in crimes against humanity for repeatedly handing over historical customer traffic data to Myanmar's military regime between the February 2021 coup and the March 2022 subsidiary sale. The Police Security Service is separately probing sanctions violations because the sale to M1 Group included sanctioned surveillance equipment transferred without foreign ministry permission. The subsequent resale passed historical call data of over 18 million people to junta-linked owners, and a class action on behalf of 1,200 people alleges the data enabled arrests, torture, and at least one execution.

The Record · 1d agoPolicy & legal

Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

Grindr will pay £26 million ($35.1M) to settle U.K. claims from 10,000+ users over pre-2020 sharing of HIV status and other sensitive data.

Grindr agreed to pay £26 million ($35.1 million) to settle a U.K. lawsuit brought on behalf of more than 10,000 claimants over sharing users' HIV status, last tested date, and other personal data with third parties for advertising before 2020, when the app was owned by China's Kunlun. The settlement, disclosed in a September 2 SEC filing, includes no findings or admission of liability, with £13 million due by December 31, 2026 and the rest by March 31, 2027. Norway's data protection authority previously fined Grindr £8.6 million (reduced to £5.5 million) under GDPR, a decision upheld on appeal last October.

The Hacker News · 8d agoPolicy & legal

Risky Bulletin: Russia starts blocking DoH and DoT

Russian users report blocks on DoH and DoT servers, including Cloudflare 1.1.1.1 and Google 8.8.8.8, in an apparent censorship crackdown.

Russian internet users began reporting failures connecting to DNS-over-HTTPS and DNS-over-TLS servers, suggesting a government crackdown on the two privacy protocols. The blocks reportedly cover Cloudflare's 1.1.1.1 and Google's 8.8.8.8 resolvers; Roskomnadzor has not officially confirmed the action. The agency tested a similar block in March on Beeline's network and had named DoH for blocking as early as 2021. The bulletin also briefly notes state-sponsored phishing of EU officials, a DDoS against Norway's Digdir, the ReliaQuest/ShinyHunters dispute, and older ransomware and breach disclosures.

Risky Business News · 22d agoPolicy & legal1

Operational Resilience: IT Security Risks with Reduced Staffing | Huntress

Huntress blog advises security teams on managing change, risk, and incident response during reduced-staffing holiday periods.

The article discusses how holiday-period staffing reductions change organizational risk profiles around change management, monitoring, and incident response capability. It argues against blanket change freezes when critical vulnerabilities with high exploitation probability demand patching, and stresses retaining decision-making authority, escalation paths, and recovery knowledge. It concludes by promoting Huntress Managed Response, which lets the Huntress SOC take predefined containment actions on confirmed threats without customer intervention.

Huntress · 1d agoIndustry

North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring

Researchers expose DPRK remote IT worker infiltration tactics, including forged identities and AI-assisted interview behavior.

A joint investigation by Mauro Eldritch, Heiner García, and ANY.RUN hired suspected DPRK developers linked to Lazarus Group into controlled sandboxes, revealing forged IDs, remote-access tools, AI-assisted workflows, and VPN/VPS infrastructure. The FBI is investigating a North Korean remote IT worker who reportedly worked for a U.S. federal agency. The article outlines verification steps and indicators including VPS and AstrillVPN exit node IPs.

The Hacker News · Aug 15, 2026Threat actor in the wild

Red Flags That Expose Fake North Korean IT Workers

Researchers outline red flags for spotting North Korean operatives posing as remote IT workers as their tactics improve.

Dark Reading describes indicators that help organizations identify North Korean operatives working undercover as IT workers. Researchers say these operatives are improving their tactics, but detection methods still exist. Catching them early helps employers avoid infiltration, data theft, and damage.

Dark Reading · 21d agoPhishing & fraud

North Korean remote workers are broadening their job hunt beyond IT

Huntress links suspected North Korean remote workers to sales, marketing, and healthcare jobs using stolen identities, VPNs, proxies, and KVM hardware.

Huntress investigations identified suspected DPRK remote workers hired beyond IT in sales, marketing, and healthcare/financial organizations, sometimes actually performing the work they were hired for. Fraudulent documents included passports from the same city issued one day apart, ID cards with identical validity dates, and electricity bills built from the same online template with matching typos. A financial-services case found a PiKVM and Guermok USB capture card on a new hire's laptop within hours of delivery, suggesting a laptop farm, and another hire used a police mugshot with the photo digitally swapped. Researchers urge rigorous background checks and identity verification at the interview stage.

Help Net Security · 20d agoPhishing & fraud in the wild

Local governments in four states dealing with cyberattacks that have shut down services

Ransomware and cyberattacks disrupted local governments in California, Oklahoma, South Dakota, Texas and Wisconsin, taking Suisun City's 911 offline.

Suisun City, California (population 30,000) shut down its IT network after malicious software hit 911 routing, police and fire dispatch; the city declared a state of emergency and the FBI is investigating. Coweta, Oklahoma confirmed a ransomware attack affecting all computers and digital services, with off-site backups slated for restoration. Mitchell (South Dakota), Coryell County (Texas) and Washburn County (Wisconsin) also disclosed cyberattacks that shut down networks and disrupted phone and payment systems.

The Record · Aug 11, 2026Ransomware in the wild

“Network outage” disrupts Westfield Public Schools in New Jersey as ransomware group posts samples

A ransomware group posted stolen data samples after a districtwide network outage disrupted Westfield Public Schools in New Jersey.

Westfield Public Schools in New Jersey experienced a districtwide network outage during the first week of school, disrupting communications and digital instruction while classrooms stayed open. The district initially attributed the disruption to networking hardware failure across all schools and offices. A ransomware group has since posted data samples, indicating extortion activity tied to the incident.

DataBreaches.net · 7d agoRansomware

Ransomware group claims attack on Missouri’s Cedar County Memorial Hospital after IT outage

Ransomware group claims attack on Cedar County Memorial Hospital in Missouri, forcing IT shutdown that disrupted EHRs and diverted emergency patients.

Cedar County Memorial Hospital in El Dorado Springs, Missouri shut down its IT networks on August 14 after a disruption left its electronic health record system, patient portal, and internet access unavailable. A ransomware group subsequently claimed responsibility for the attack. Diagnostic imaging was also disrupted, preventing transmission of images to radiologists, and the emergency department partially diverted trauma and critical patients.

DataBreaches.net · 1d agoRansomware

France Establishes New Government-Focused Cyber Incident Response Unit

France created REACTIV, an ANSSI-led interministerial cyber incident response unit for state services, after the DGFiP breach exposed up to 678,000 taxpayers.

ANSSI announced REACTIV (Interministerial Response & Action against Data Breaches) on September 7, a dedicated incident response capability for French state services. It lets ANSSI require ministries to take urgent protective measures for citizens' data and lead centralized technical crisis communications during attacks on state services. The move follows the DGFiP tax authority attack that exposed data of 350,000 to 678,000 taxpayers, after which the Prime Minister ordered an extensive audit of ANSSI. Two suspects aged 16 and 18 from the ZeroBytes hacking group were arrested in late August.

Infosecurity Magazine · 8d agoPolicy & legal

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)

N-able shipped an emergency hotfix for CVE-2026-86218, a pre-auth RCE zero-day in N-central RMM observed exploited in the wild.

N-able released Hotfix 4 for N-central 2026.3 on September 5 (build 2026.3.1.14), fixing CVE-2026-86218, a critical pre-authenticated remote code execution flaw in its RMM platform popular with MSPs. A private customer notice marked urgent said the zero-day 'has been observed being exploited in the wild,' while the public advisory said there were no confirmed production exploits. Huntress also flagged two high-severity vulnerabilities, CVE-2026-86206 and CVE-2026-86207, which allow authentication bypass and unrestricted access; they were patched the same weekend and were discovered by Rapid7's Stephen Fewer. N-able advised auditing N-central user accounts for unexpected users.

Insights into Suspected DPRK Workers

Huntress details incidents involving suspected DPRK remote workers (Famous Chollima) in partner environments and shares detection indicators.

Huntress analyzed several incidents involving suspected North Korean remote workers, associated with the activity cluster known as Famous Chollima. The report describes indicators defenders can use to detect and prevent DPRK worker infiltration in customer environments. The scheme centers on operatives obtaining remote jobs at Western companies under assumed identities.

Huntress · 22d agoThreat actor in the wild

Back-to-back N-able bugs send admins on a patching spree

CVE-2026-86218, a CVSS 10.0 pre-auth RCE in N-able N-central, is being exploited in the wild; Hotfix 4 mitigates it immediately.

N-able disclosed CVE-2026-86218 on September 6, a pre-authentication remote code execution flaw with CVSS 10.0 in its N-central RMM platform, and both N-able and Huntress report it is being exploited in the wild. It follows Huntress's disclosure of an exploit chain combining CVE-2026-86206 and CVE-2026-86207 that bypasses access controls to create unauthorized administrative accounts, investigated after a September 4 compromise of a fully patched customer environment. N-able has applied mitigations to all hosted N-central instances; on-premises customers must upgrade to Hotfix 4 (build 2026.3.1.14) immediately.

CSO Online · 9d agoExploit / PoC in the wildCVE-2026-86218CVE-2026-86206CVE-2026-86207+2 CVEs

NIST Seeks Public Input on AI-Ready NVD Modernization

NIST is seeking public comment on modernizing the National Vulnerability Database to support AI-powered vulnerability research.

The US National Institute of Standards and Technology announced it is soliciting public input on modernizing the National Vulnerability Database. The initiative aims to make the NVD AI-ready to support AI-powered vulnerability research and analysis.

Infosecurity Magazine · Aug 12, 2026Policy & legal

N-able Patches Critical Zero-Day in N-central

N-able patches critical unauthenticated RCE zero-day CVE-2026-86218 in N-central, exploited in the wild; on-premises admins must apply hotfix 2026.3 HF4.

N-able released an urgent hotfix (2026.3 HF4) for CVE-2026-86218 (CVSS 10), an unauthenticated RCE in N-central exploited as a zero-day. Scanning/exploitation attempts observed from IP range 23.234.64.0/18 starting September 4; admins should check logs for scanning and unrecognized new accounts. The hotfix supersedes patches for CVE-2026-86206 and CVE-2026-86207, which Huntress observed potentially chained in the wild to bypass authentication in production environments.

Canada: Nipigon hospital hit by ransomware attack

Nipigon District Memorial Hospital in Ontario, Canada confirmed a ransomware attack disrupted its IT systems, possibly affecting some patient services.

Nipigon District Memorial Hospital in Nipigon, Ontario announced that a ransomware attack affected its information technology systems. The hospital described the event as a 'cyber security incident' and warned that some patient services may be impacted while it responds. Nipigon Mayor Suzanne Kukko commented on the incident to local media. No threat actor was named and no data exposure or leak was confirmed at the time of disclosure.

DataBreaches.net · 7h agoRansomware in the wild

Japan’s Digital Agency Breach Exposes 240,000+ Users’ Personal Records to Hackers

Attackers exploited a patched VPN appliance flaw to breach Japan's Digital Agency shared government platform, exposing about 246,000 personal records.

Japan's Digital Agency disclosed on September 11 that attackers exploited a VPN appliance vulnerability to access the Government Solution Service (GSS), a shared IT platform across ministries, exposing roughly 246,000 personal records. The attacker was active since late May using a maintenance staffer's credentials, with suspicious activity detected June 25 and containment on July 9. Exposed data covers about 189,000 employees/public officials and 57,000 contractors; no My Number, bank, or pension data was included. The VPN flaw was medium severity with a patch already available, and the 78-day detection-to-disclosure gap has drawn scrutiny.

Cyber Security News · 1d agoData breach in the wild 2 sources

N-able patches max severity N-central flaw amid ongoing attacks

N-able ships an emergency hotfix for a maximum-severity RCE flaw in its N-central RMM platform that attackers are actively exploiting.

N-able has released an emergency hotfix for a maximum-severity remote code execution vulnerability affecting its N-central remote monitoring and management (RMM) platform. The company urges customers to apply the fix immediately because attacks against N-central instances are ongoing. N-central is widely used by managed service providers, so a compromise of one deployment can expose many downstream customer environments.

BleepingComputer · 9d agoExploit / PoC in the wild

Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras

Slovakia's NBU found an SMS-triggered backdoor in Russian-made NERO R-ONE traffic cameras, pausing a 279-unit deployment.

Slovakia's national security service NBU issued an alert against NERO R-ONE high-speed traffic cameras after finding a backdoor that grants shell and network access via SMS from hardcoded Russian phone numbers. The cameras are a rebranded version of the Russian CORDON PRO.M model by St. Petersburg firm Semicon, purchased via a Cyprus shell company under a €30 million EU-funded project. The report also found SecureBoot disabled, vulnerable web management, and unauthenticated live streams; the Interior Ministry paused deployment of 279 cameras pending independent assessment.

Risky Business News · 29d agoThreat actor in the wild1

Korea raises data breach fines to 10% of revenue

South Korea's privacy regulator will impose fines up to 10% of revenue for data breaches leaking personal data of 10 million or more people.

South Korea's privacy regulator is sharply raising penalties for data breaches, with fines reaching 10% of a company's revenue. The higher fines take effect Friday for companies found to have leaked personal data of 10 million or more people through intent or gross negligence. The regulator aims to push companies to treat data protection as a preventive investment rather than a routine cost of doing business.

DataBreaches.net · 6d agoPolicy & legal

Cyber Op Targets South Korean Media & Automotive Sectors

Likely North Korean APT compromised load balancers at South Korean media and automotive firms using a previously undocumented Linux espionage toolkit.

A cyber operation attributed to a likely North Korean APT group targeted South Korean media and automotive sectors. The attackers deployed a previously undocumented Linux espionage toolkit to compromise load balancers, gaining access to communications and enabling further network exploitation. Specific victims, toolkit names, and indicators of compromise were not disclosed in the report summary.

Dark Reading · 1d agoThreat actor in the wild

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Rapid7 uncovered a DPRK-linked Linux toolkit using a HAProxy-embedded ted backdoor, SSH keylogger, and curlRAT against South Korean media and automotive firms.

Rapid7 Labs identified a previously undocumented framework attributed with medium confidence to DPRK actors, targeting South Korean automotive and media organizations likely since early 2025. The toolkit embeds a backdoor compiled into HAProxy 2.8.12 using its filter API, plus trojanized crond, agetty, atd, sshd, and polkitd, an SSH keylogger storing credentials under /var/lib/sshd/, and a curl-based RAT with a watchdog thread. It enables remote command execution, malicious script injection into served webpages (a watering-hole loop), credential harvesting, and long-term surveillance. Hardcoded C2s are associated with APT37 via ThreatFox, and exposed groupware portals and mail servers align with Kimsuky tradecraft; the initial access vector and any CVE remain unconfirmed.

Rapid7 Blog · 12d agoThreat actor in the wild1