ZeroHour

Search: “outages”

40 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Boston Scientific Reveals Global Disruption After Cyber Incident

MedTech giant Boston Scientific disclosed a cyber incident causing IT outages and disruption across its global operations.

Boston Scientific revealed that a cyber incident triggered IT outages disrupting its worldwide operations. The medical device manufacturer has not yet confirmed whether data was accessed or whether ransomware is involved. Details on scope and impact remain limited as the investigation continues.

Infosecurity Magazine · 20d agoData breach

Georgia’s largest county confirms cyberattack causing widespread issues

Fulton County, Georgia — home to Atlanta and over 1 million residents — confirms a cyberattack that disrupted county phone, court, and tax systems.

Fulton County government disclosed a widespread IT outage caused by a cybersecurity incident discovered over the weekend, affecting phone systems, the court system, and the tax system, including firearm and marriage license transactions. County Chairman Robb Pitts said the incident is under active investigation by law enforcement, and the FBI confirmed its involvement. The Tax Commissioner office in downtown Atlanta was closed and library public computers were offline. No group has claimed responsibility, though the article notes recent ransomware attacks on other Georgia local governments, including Forsyth County (AlphV) and Augusta.

The Record · 8d agoData breach

Powering AI is an architecture problem

Sponsored analysis argues AI data centers need medium-voltage, inline power architecture after Virginia grid faults knocked over 3GW of load offline.

A sponsored MIT Technology Review piece recounts a July 22, 2026 transmission fault in Ashburn, Virginia that shed more than 3 GW of data center load, and a 2024 incident where one failed surge arrester dropped about 60 facilities and 1,500 MW. It argues legacy UPS-based power stacks fail at AI scale because campuses can swing 70% of load in milliseconds and trip offline during grid disturbances. The proposed fix moves protection to medium voltage (13.8 kV and above) in inline enclosures near substations, improving density, permitting timelines, and backup power economics. A full-scale system tested at the DOE National Laboratory of the Rockies cleared ERCOT large-load ride-through requirements.

MIT Technology Review · AI · 6d agoAI industry1

DDoS Attacks Cause Major Threema Outages

Sustained distributed denial-of-service attacks knocked Swiss secure messenger Threema offline for hours before upstream filtering restored service; On-Prem users unaffected.

Threema suffered a series of large-scale DDoS attacks that left its Swiss secure messaging service unavailable for about four hours Tuesday evening, with intermittent outages into Wednesday morning until restoration at 12:23 p.m. CEST. Attacks also targeted colocation partner Nine and kept changing patterns, complicating mitigation. Threema deployed additional upstream DDoS protection on August 14 and plans status page improvements; Threema On-Prem customers running their own infrastructure were unaffected.

Security Affairs · Aug 17, 2026Threat actor in the wild

Nobody Is Saying Why OpenAI and Anthropic Had Outages Today

OpenAI, Anthropic, and xAI chatbots suffered brief simultaneous outages; OpenAI cited a routing error and SpaceX a Memphis compute center outage.

ChatGPT and Codex were unavailable to some users from about 7:43 to 8:17 am PT Thursday due to a routing error, per OpenAI. Anthropic reported a partial outage with elevated errors on Claude Mythos 5.1, Claude Fable 5.1, and Claude Opus 5, resolved by 9:16 am PT, while declining to explain the cause. xAI attributed the Grok outage starting 6:30 am PT to an outage at SpaceX's Memphis compute center; no shared third-party infrastructure cause was confirmed despite Cloudflare, AWS, and Azure reporting no issues.

WIRED · Security · 12d agoAI industry1

Certificate failures can cost firms over $250,000

DigiCert survey finds certificate failures cost firms over $250,000 per incident, with 47-day TLS certificates set to multiply management workloads by 2029.

DigiCert's Certificate Management Outlook reports that 34% of companies experienced outages from expired certificates and 40% from mismanagement, with nearly one in four citing incidents costing over $250,000. The CA/Browser Forum's move to 47-day certificate lifespans by 2029 will require renewals eight times more often and 40 times as many domain validations. Over half of organizations manage more than 1,000 certificates, yet only 10% have automation in place, with budget constraints and legacy systems cited as key barriers.

Help Net Security · 2d agoIndustry

“Network outage” disrupts Westfield Public Schools in New Jersey as ransomware group posts samples

A ransomware group posted stolen data samples after a districtwide network outage disrupted Westfield Public Schools in New Jersey.

Westfield Public Schools in New Jersey experienced a districtwide network outage during the first week of school, disrupting communications and digital instruction while classrooms stayed open. The district initially attributed the disruption to networking hardware failure across all schools and offices. A ransomware group has since posted data samples, indicating extortion activity tied to the incident.

DataBreaches.net · 6d agoRansomware

Ransomware group claims attack on Missouri’s Cedar County Memorial Hospital after IT outage

Ransomware group claims attack on Cedar County Memorial Hospital in Missouri, forcing IT shutdown that disrupted EHRs and diverted emergency patients.

Cedar County Memorial Hospital in El Dorado Springs, Missouri shut down its IT networks on August 14 after a disruption left its electronic health record system, patient portal, and internet access unavailable. A ransomware group subsequently claimed responsibility for the attack. Diagnostic imaging was also disrupted, preventing transmission of images to radiologists, and the emergency department partially diverted trauma and critical patients.

DataBreaches.net · 23h agoRansomware

Four major AI models suffer rare overlapping downtime

OpenAI, Anthropic, xAI, and Google AI services suffered rare overlapping outages on Thursday, with most incidents resolved within hours.

Anthropic reported a partial outage with elevated errors on Claude Mythos 5.1, Claude Fable 5.1, and Claude Opus 5 starting at 9:23 am ET, identifying the cause within about 15 minutes and resolving it by 12:16 pm, with a brief Claude Sonnet 5 error spike after noon. OpenAI reported elevated errors across ChatGPT and Codex from 10:43 am, marking the issue resolved at 12:55 pm after a mitigation. xAI's Grok showed a user-facing error message as DownDetector reports surged from fewer than 10 to 1,365 by 9:45 am, and Google also experienced interruptions during the same window.

Ars Technica · AI · 12d agoAI industry

I Think the Military Commissary Freezers Were Hacked

Refrigeration failures at six-plus US military commissaries prompt speculation of a cyber attack on DeCA's remote monitoring systems; Pentagon acknowledges possible disruption.

The author documents near-simultaneous freezer and refrigeration failures at confirmed installations including Fort Huachuca, F.E. Warren AFB, Fort Irwin and Travis AFB on August 26-27, with freezers entering defrost mode that heated and spoiled food. DeCA's Remote Monitoring Control System controls defrost across roughly 182 locations, and an unverified comment attributed the Fort Huachuca failure to a network issue. Stars and Stripes and Military Times independently reported the multi-base failures, and the Pentagon acknowledged a 'possible refrigeration disruption,' though no evidence of hacking has been confirmed.

Lobsters · security · 13d agoData breach

CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate

CISA and partners issue a joint advisory pressing organizations toward transparent breach notification and incident response as cyber outages escalate.

Dark Reading reports on a new joint government advisory led by CISA that signals a regulatory shift. The advisory presses organizations to adopt more transparent breach notification protocols and incident response practices. The guidance comes as cyber outages escalate and reflects growing government expectation of disclosure over spin.

Dark Reading · 4d agoPolicy & legal1

Cyberattack causes network outage at Boston Scientific, disrupts global operations

Boston Scientific disclosed a cyberattack that caused a network outage, disrupting global operations including order processing and shipping.

The medical device maker detected the incident on August 25, activated incident response protocols with third-party cybersecurity experts, and told the SEC that access to systems supporting operations, including order processing and shipping, was disrupted. Boston Scientific employs about 59,000 people across 127 countries and posted more than $20 billion in net sales in 2025; it has not determined whether the incident is material and no group has claimed responsibility. The company joins a recent run of medtech attacks including Stryker, iRhythm, Novo Nordisk and Xsolis.

Help Net Security · 20d agoData breach

CISA Urges Service Providers to Provide Transparent Updates During Major IT and OT Outages

CISA and FBI issued guidance urging service providers to deliver timely, transparent communications during major IT and OT outages.

CISA, with the FBI and international partners, released 'Communicating Under Pressure: Best Practices for Service Providers', urging providers to prepare crisis-communication procedures, provide timely status updates during IT/OT outages, and maintain out-of-band communication channels. The guidance warns that disruptions to telecom, cloud, energy, and water services can cascade across critical infrastructure. It aligns with CISA's CI Fortify initiative supporting IT/OT isolation and recovery.

GBHackers · 5d agoAdvisory

Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras

Slovakia's NBU found an SMS-triggered backdoor in Russian-made NERO R-ONE traffic cameras, pausing a 279-unit deployment.

Slovakia's national security service NBU issued an alert against NERO R-ONE high-speed traffic cameras after finding a backdoor that grants shell and network access via SMS from hardcoded Russian phone numbers. The cameras are a rebranded version of the Russian CORDON PRO.M model by St. Petersburg firm Semicon, purchased via a Cyprus shell company under a €30 million EU-funded project. The report also found SecureBoot disabled, vulnerable web management, and unauthenticated live streams; the Interior Ministry paused deployment of 279 cameras pending independent assessment.

Risky Business News · 28d agoThreat actor in the wild1

DDoS Attack Hits Norwegian Government Services

A coordinated DDoS campaign disrupted Norwegian government online services, causing availability outages across public digital services.

A coordinated distributed denial-of-service campaign caused disruption to Norwegian government digital services, according to Infosecurity Magazine. The attack affected the availability of public-facing services, and no data compromise was indicated in initial reporting. The responsible group or motive was not named in the report.

Infosecurity Magazine · 21d agoThreat actor

When AI quietly breaks things, who pays?

Reed Smith partner David Halbreich explains how AI companies can avoid D&O/E&O coverage gaps around mergers, governance warranties, and claims timing.

In an interview, insurance recovery partner David Halbreich of Reed Smith outlines insurance pitfalls for AI companies under claims-made D&O and E&O policies. He highlights 'straddle' claims after mergers that fall between tail coverage and go-forward policies, potentially leaving policyholders with no coverage. He also warns that governance artifacts submitted in insurance applications, such as bias testing records and model cards, can become warranties carriers use to deny claims, and discusses who should answer AI-use questions and how business interruption coverage applies to cloud and compute vendor outages.

Help Net Security · 13d agoAI industry

Communicating Under Pressure: Best Practices for Service Providers

CISA, FBI, and international partners issued guidance on crisis communications for service providers during IT and OT outages, emphasizing clarity, transparency, and backup channels.

CISA, the FBI, and international partners published guidance on planning and executing clear, timely, audience-appropriate communications during IT and OT service outages, whether caused by cyber threat actors, human error, or natural hazards. The guidance stresses clarity, accountability, and transparency, and warns that outages at one organization can cascade across interconnected systems. It recommends critical infrastructure owners assume telecommunications may be unreliable and integrate backup communication methods into crisis plans, and points to CISA's CI Fortify initiative for OT isolation and recovery resources.

CISA Advisories · 13d agoAdvisory

Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited

Help Net Security's weekly digest highlights 274 compromised Zimbra servers, Gitea and Citrix NetScaler KEV additions, a PaperCut zero-day, and a suspected Iran-linked power plant attack.

The roundup reports at least 274 internet-facing Zimbra instances compromised via CVE-2026-73570, critical Gitea CVE-2026-60004 added to CISA's KEV catalog after exploitation began, and previously patched Citrix NetScaler flaw CVE-2026-8452 exploited in the wild. It also covers PaperCut NG/MF zero-day attacks, a suspected Iran-linked shutdown of a UK power plant, an FBI seizure of domains tied to a China-linked group that hit NASA, DOJ and the Senate, a cyberattack disrupting Boston Scientific, and the Manchester Airports Group breach. Additional items include Chameleon SEO poisoning phishing, Android car head unit proxy botnet malware, ReliaQuest social engineering by ShinyHunters, fake OpenAI Codex macOS malware, and AI-related workforce and supply chain interviews.

Cyber Incident Disrupts Student Services at UT San Antonio

UT San Antonio pulled IT systems offline after a cyber incident, disrupting student registration and tuition payments days before the term begins.

UT San Antonio reported a cyber incident and took IT systems offline as a precaution, disrupting student registration and tuition payment services. The outage comes days before the term is due to resume. The nature of the incident, whether data was accessed, and whether ransomware is involved have not been confirmed.

Infosecurity Magazine · 28d agoData breach

Afraidgate: Major Exploit Kit Campaign Switches from CryptXXX Ransomware Back to Locky

The Afraidgate exploit kit campaign stopped distributing CryptXXX and now delivers the .zepto Locky variant exclusively through Neutrino EK since July 2016.

By mid-July 2016, the Afraidgate campaign switched from CryptXXX ransomware to consistently delivering the .zepto (Zepto) variant of Locky, using the Neutrino exploit kit after Angler EK disappeared in early June 2016. The campaign starts from compromised websites with injected scripts that redirect to Afraidgate domains and then Neutrino EK landing pages on .top domains. Zepto emerged after the Necurs botnet returned from a three-week outage, bringing new anti-sandboxing and evasion techniques.

Palo Alto Unit 42 · Aug 17, 2026Ransomware in the wild

Suspected Iran-linked attack knocked UK power plant offline for days

Suspected Iranian hackers knocked a small UK power plant offline for four days in July 2026, with no noticeable impact on the national grid.

Sources told The Telegraph that a British power plant was offline for four days in July 2026 following a suspected Iranian cyberattack, reported to the National Cyber Security Centre. The UK energy minister said the incident affected a small-scale energy generator with no noticeable effect on the power supply, and energy CEOs were briefed and given further advice afterward. The attack followed warnings about Iranian cyber activity against US energy, water, and government networks, including a coordinated attack on 30+ US community water utilities.

Help Net Security · 23d agoThreat actor

Citrix UniconOS dual boot turns Windows endpoints into their own recovery device

Citrix released UniconOS dual boot in Release 7 2607, turning Windows endpoints into self-recovery devices after ransomware, failed updates or OS corruption.

Citrix announced dual boot in UniconOS Release 7 2607, which installs an isolated, hardened recovery environment alongside Windows in a separate partition protected by secure boot. If Windows is unavailable, users reboot into UniconOS and reconnect to applications via Citrix DaaS and SecurAccess with Chrome Enterprise. The capability is aimed at reducing reliance on spare hardware and central reimaging during ransomware or update failures, with automatic enrollment in UniconOS Management for fleet-wide boot policies.

Help Net Security · 22d agoTools

Wake-Up Call for CNI After Iranian Attack Shuts Down UK Power Plant

A cyber-attack attributed to Iran shut down a UK power plant, exposing the frailty of critical national infrastructure, security experts warn.

Security experts say an Iranian cyber-attack forced a UK power plant offline, describing the incident as a wake-up call for critical national infrastructure operators. The attack caused physical operational disruption at an energy facility. Technical details about the intrusion path and the affected operator remain limited in initial reporting.

Infosecurity Magazine · 23d agoThreat actor in the wild

Risky Bulletin: Academics find source code overlaps between Geedge and China's Great Firewall

Academics linked Chinese vendor Geedge Networks' Tiangou Secure Gateway source code to one of the Great Firewall's three traffic filtering capabilities.

US researchers presenting at USENIX Security reconstructed Geedge Networks' Tiangou Secure Gateway firmware from over 100,000 leaked files, including Git repositories with commit history, and matched its filtering behavior to sections of China's Great Firewall. They found only 1 of 3 characterized DNS injectors matched Geedge code, noted the system relies on memory-unsafe C components and copied third-party code, and said its bugs could aid future circumvention tools. Geedge also exports censorship tools to Kazakhstan, Ethiopia, Pakistan, and Myanmar. The newsletter additionally rounds up multiple breaches.

Risky Business News · 26d agoResearch2

A battery storage cyberattack would look exactly like a badly tuned controller

Risk modeling suggests a few hundred compromised grid-scale batteries dispatched through cloud optimizers could trigger blackouts in Texas or Great Britain.

Centrii analysis estimates 1,500 compromised one-megawatt units (5.4% of ERCOT's ~28 GW fleet) or 400 units (about 29% of Great Britain's ~1,400-unit fleet) could destabilize the grids, with modeled damage of $12-65 billion in Texas and a national blackout costing £2-10 billion in Britain. The study puts the probability of a major attack affecting at least one million people by 2031 at 92.1%, dropping to 61.4% with IEC 62443 certification and quarterly drills, based on 10,000 Monte Carlo runs. Because hostile battery swings are phased like legitimate frequency response, control rooms would see nothing unusual; Centrii proposes hunting for a reverse-governor signature where inverter output feeds oscillations. Spain's April 2025 blackout took an expert panel until March 2026 to rule out cyberattack, partly because key plants had no recordings.

Help Net Security · 14d agoResearch

Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)

Cloudflare's Automatic Key Exchange probes origins to lead with preferred key exchange, cutting HelloRetryRequests from 52% to 3.7% and enabling automatic post-quantum origin connections.

Cloudflare announced Automatic Key Exchange, an extension of Automatic SSL/TLS that probes each origin's supported key agreement algorithms and leads with the preferred one, favoring the post-quantum hybrid X25519MLKEM768. Rollover across roughly 45 billion daily origin connections cut HelloRetryRequests from about 52% to 3.7%, saving more than 150 ms of p90 handshake latency. Hundreds of thousands of domains now receive post-quantum origin connections without manual configuration, supporting Cloudflare's goal of quantum-safe encryption by 2029 to counter harvest-now-decrypt-later attacks.

Cloudflare Blog · 7d agoResearch

Possible cyber incident disrupts Monroe schools in Wisconsin

Possible cyber incident forced the School District of Monroe in Wisconsin to cut internet access, knocking out phones and canceling an ACT testing session.

The School District of Monroe in Wisconsin disconnected its network after a possible network security issue. Students powered down computers, school phone service failed, and a scheduled ACT testing session was canceled. Classes continued while the district investigates the incident. No data theft or attacker claims have been confirmed so far.

DataBreaches.net · 1d agoData breach

McKesson copes with fallout from data theft extortion attack

McKesson discloses a data theft extortion attack by ShinyHunters affecting oncology and medical-surgical customers, with a reported $55 million demand.

McKesson disclosed that attackers gained access to some of its third-party applications and stole data associated with a subset of customers in its oncology, multispecialty, and medical-surgical business units; the intrusion ran for four days from August 21 and was discovered August 25. ShinyHunters claimed responsibility and listed McKesson on its data-leak site, reportedly demanding more than $55 million with a September 1 deadline. Flashpoint analysts say the group typically uses social engineering and identity weaknesses with valid credentials to access cloud-hosted environments, making the intrusion hard to detect. McKesson, which distributes about one-third of pharmaceuticals used in North America with $403.4 billion in annual revenue, says operations continue and it has reasonable assurance of no ongoing unauthorized activity.

CyberScoop · 15d agoData breach in the wild

Beyond the Perimeter: Building Resilience Against Cloud and SaaS Supply-Chain Attacks

ShinyHunters exploited an Oracle PeopleSoft zero-day to steal data and extort roughly 100 organizations, including the Council of Europe, for up to $2.3M.

Between May and early June 2026, the ShinyHunters group exploited a critical zero-day in Oracle PeopleSoft across about 100 organizations and 300 instances worldwide, per reports cited by The Register. Stolen records included employee and student personal data, payroll, tax, financial and health information, plus immigration and passport documents. AgentCypher.ai estimates extortion demands of $400,000 to $2.3 million per victim, typically in Bitcoin; the Council of Europe refused to pay. The article uses the incident to argue for Zero Trust, supply-chain risk management, rapid patching, encrypted distributed backups and defined recovery-time objectives.

Cyber Security News · 4d agoData breach in the wild1

Is Someone Hacking DoD Refrigerators?

Refrigeration outages hit commissaries at seven US military installations, with hacking suspected but not confirmed by the Pentagon.

Refrigeration disruptions were reported at Defense Commissary Agency commissaries at Fort Irwin, F.E. Warren AFB, Fort Huachuca, Naval Station Newport, Columbus AFB, Travis AFB, and Naval Air Station Lemoore. A defense official acknowledged awareness of a possible refrigeration disruption, but the services and Pentagon declined to provide details. The post is speculative, arguing the coincidence of outages suggests possible hacking, though no evidence or attribution is provided.

Schneier on Security · 15d agoData breach

Cisco bundles fixes for multiple vulnerabilities, some critical, into one patch

Cisco patched seven IOS XR vulnerabilities, two rated CVSS 9.8, allowing unauthenticated remote code execution and root access on carrier routers; no exploitation observed.

Cisco released fixes for seven internally discovered vulnerabilities in IOS XR, its Linux-based network operating system for carrier-grade routers. Two flaws, CVE-2026-20274 and CVE-2026-20279, are rated CVSS 9.8 (critical) and involve lifetime resource control issues that can enable unauthenticated remote code execution with root access; the other five are rated 8.2-8.8 and cover buffer overflows, access control failures, and out-of-bounds access. All IOS XR releases including IOS XR7 are affected regardless of configuration, no workarounds exist, and remediation requires software maintenance upgrades (SMUs) or fixed releases 26.2.2/26.3.1. Cisco says the flaws are not known to be actively exploited, but experts urge immediate patching of internet-facing and core routing systems, citing parallels with Salt Typhoon tradecraft.

Troy Hunt

Troy Hunt warns ShinyHunters' Carhartt breach claim of 50GB and millions of records is unverified, while Sri Lanka joins Have I Been Pwned.

Troy Hunt's blog roundup centers on a cautionary tale about data breach claims: ShinyHunters claims it compromised Carhartt and stole over 50GB of compressed data containing millions of customer records, employee information and loyalty data, but Hunt stresses criminal claims require verification. The feed also covers Sri Lanka CERT becoming the 48th government onboarded to Have I Been Pwned's free government monitoring service, following Nepal as the 47th. Other commentary addresses ransomware economics, Brinks Home's lawyer-heavy extortion FAQ, and the Origin Energy breach in Australia.

Troy Hunt · 9d agoData breach

Cyberattack forces UT San Antonio to delay start of fall semester

UT San Antonio delayed fall semester start by three days after a weekend cyberattack was caught at the network edge before core systems.

The University of Texas at San Antonio, which serves more than 42,000 students, moved its fall semester start from August 19 to August 24 after a weekend cyberattack on its academic network. Officials said the intrusion attempt was caught at the edge of the network before reaching core systems and that no evidence of data theft has been found. The university took systems and services offline for review, causing phone system outages and password reset tool delays. The incident follows the Instructure Canvas breach during spring finals week that exposed data tied to millions of students and staff worldwide.

Help Net Security · 28d agoExploit / PoC

OpenAI targets small utilities with $1 billion cyber defense initiative

OpenAI commits $1 billion to Daybreak for Frontline Defenders, subsidizing frontier cyber AI access and training for small utilities, governments, and critical infrastructure operators.

OpenAI President Greg Brockman announced Daybreak for Frontline Defenders, a $1 billion global commitment expanding subsidized access to Daybreak cyber models, training, and technical support. Daybreak for America will target small water and electricity providers, local governments, and banks, including a pilot with the MS-ISAC for state, local, tribal, and territorial defenders. The Daybreak Defense Network brings more than 35 enterprise partner products into the program, and attendees at OpenAI's utility summit represent 40 states serving over half the US population. Security experts welcomed the effort but cautioned that OT environments still need human-led implementation and testing before AI tooling can be safely rolled out.

CSO Online · 12d agoAI industry1

Florida water agency latest to confirm cyber incident as feds warn of nation

A ransomware gang hit Florida's St. Johns River Water Management District as CISA warned of IRGC-linked CyberAv3ngers attacks on exposed Unitronics water-sector PLCs.

The St. Johns River Water Management District, which oversees Florida drinking-water supply planning, confirmed suspicious activity in its IT environment and said containment measures were implemented; a ransomware gang claimed the attack and shared samples of stolen data. Separately, CISA, FBI, NSA, EPA and Israel's INCD warned that IRGC-affiliated CyberAv3ngers are actively compromising Israeli-made Unitronics Vision Series PLCs in the water sector using default credentials since at least November 22. The group, motivated by opposition to Israel-linked products, defaces controller interfaces and could cause deeper cyber-physical effects. Shadowserver found at least 539 Unitronics PLC instances still exposed online, and CNN reported fewer than 10 US water facilities faced recent attacks.

The Record · 8d agoRansomware in the wild 3 sources

Chinese and Russian spies stepping up cyberattacks, German companies report

Bitkom survey finds nearly 40% of attacked German companies attribute incidents to foreign intelligence services, mainly China and Russia, costing up to $240B.

A Bitkom survey of 1,003 German companies with at least 10 employees found nearly four in 10 firms hit by data theft, espionage, or sabotage attributed at least one incident to a foreign intelligence service, up from 28% last year and 7% in 2023. China was the most cited source, named by more than half of affected companies, followed by Russia and Iran at roughly one in ten. Bitkom estimated cyberattacks cost German businesses $186-240 billion over the past year, with ransomware the most common attack type, affecting one in four companies. Recent incidents cited include breaches at Lidl, billing provider Unimed, and the Dresden State Art Collections.

The Record · 19d agoThreat actor

N-able patches max severity N-central flaw amid ongoing attacks

N-able ships an emergency hotfix for a maximum-severity RCE flaw in its N-central RMM platform that attackers are actively exploiting.

N-able has released an emergency hotfix for a maximum-severity remote code execution vulnerability affecting its N-central remote monitoring and management (RMM) platform. The company urges customers to apply the fix immediately because attacks against N-central instances are ongoing. N-central is widely used by managed service providers, so a compromise of one deployment can expose many downstream customer environments.

BleepingComputer · 9d agoExploit / PoC in the wild

Top 10 Best Application Control & Allowlisting Tools in 2026

Roundup ranks 2026 application allowlisting tools, scoring ThreatLocker 8.8/10, Airlock Digital 8.5/10 and free Microsoft WDAC among top default-deny options.

This is a scored buyer's guide to ten application control and allowlisting tools for 2026, with ThreatLocker ranked first (8.8/10), Airlock Digital second (8.5/10) and Microsoft's built-in WDAC/AppLocker third (7.2/10). It notes ransomware has renewed interest in default-deny execution controls and that CISA and other agencies list application control among the most effective yet under-deployed mitigations. The evaluation is research-based with no lab testing, weighting policy automation at 30% and operability at 25%.

Cyber Security News · 7d agoIndustry1

Panzer Ransomware Targets Italian Manufacturers and Telecom Firms With ESXi-Ready RaaS

New Panzer ransomware-as-a-service operation lists Italian firms Doimo Cucine and NTE Italia as victims, offering encryptors for Windows, Linux, FreeBSD, and ESXi.

Panzer, a ransomware-as-a-service operation that surfaced August 5, listed a kitchen manufacturer in Treviso (Doimo Cucine) and a telecommunications engineering firm in Catanzaro (NTE Italia) among alleged victims, claiming 30 GB and 16 GB of stolen data respectively. The group advertises encryptors for Windows, Linux, FreeBSD, and VMware ESXi, a Tox-based affiliate recruitment process with screening, an affiliate dashboard, and an 80/20 revenue split. Neither victim had publicly confirmed the incidents when researcher Andrea Fortuna's report was published, and the group's first access method and payload have not been independently analyzed. Panzer posted victims across 11 countries as claimed Italian ransomware incidents reached 212 by September 6, already above 2025's full-year total of 169.

Cyber Security News · 8d agoRansomware in the wild

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Sophos found F5 BIG-IP APM malware that injects a PHP web shell into Apache's memory, evading disk scans, linked to exploited CVE-2025-53521.

Sophos's September 7 analysis describes malware tied to F5's c05d5254 activity that hooks apr_dso_load, modifies the libphp PHP module in memory, and injects a PHP web shell when Apache loads apm_css.php3, full_wt.php3 or webtop_popup_css.php3, leaving on-disk files clean. A separate installer infects /usr/sbin/httpd and umount, runs before Apache starts, disables SELinux (per ESET's related PoisonedRefresh analysis), and opens a local socket at /run/bigtlog.pipe for shell access. The activity is linked to CVE-2025-53521 in BIG-IP APM, rated 9.8 CVSS 3.1, patched in October 2025, added to CISA KEV on March 27, 2026.

The Hacker News · 7d agoMalware in the wildCVE-2025-53521