Stadler Rail Everest Ransomware: SFr10m Demand Refused

Stadler Rail Everest Ransomware: SFr10m Demand Refused

The Stadler Rail Everest ransomware incident shows what a mature extortion response looks like: the Swiss train manufacturer confirmed that the Everest group stole supplier technical data through a shared data-exchange platform and demanded roughly SFr10m (about $12.3M) — and Stadler refused outright, filing a criminal complaint instead of negotiating. What Happened Stadler Rail, an…

Read More

Ransomware in Germany: From IT Incident to Insolvency Risk

Ransomware in Germany — idle production line symbolising a cyberattack-related operational shutdown

Ransomware in Germany is no longer an abstract IT concern — in 2026, it is one of the more concrete threats to whether a company survives at all. Two recent cases illustrate how differently this threat can play out. ZEGO Textilveredelungszentrum filed for insolvency following a cyberattack, without the attack type ever being publicly confirmed.…

Read More

GitLab Oj Spill RCE Exploit Goes Public

GitLab Oj Spill RCE Exploit Goes Public

The GitLab Oj Spill RCE is now public: a working exploit chain and full technical writeup were released on July 24 for a remote-code-execution flaw that GitLab quietly patched six weeks earlier, on June 10. If your self-managed GitLab instance is still on 18.10.7 or older, any developer who can push a commit can now…

Read More

Check Point SmartConsole CVE-2026-16232: Admin Bypass

Check Point SmartConsole CVE-2026-16232: Admin Bypass

Check Point SmartConsole CVE-2026-16232 is now on CISA’s Known Exploited Vulnerabilities list: an unauthenticated attacker can forge a login token and get full administrator access to the console that manages an organization’s entire firewall fleet. Check Point patched it on July 22 and confirmed a handful of customers were already targeted. The federal remediation deadline…

Read More

wp2shell WordPress RCE: Patch Now

wp2shell WordPress RCE

wp2shell WordPress RCE is now a two-CVE chain in CISA’s Known Exploited Vulnerabilities catalog — and it lets a completely unauthenticated attacker execute code on a default WordPress install with no plugins involved. If you run self-hosted WordPress and haven’t confirmed the July 17 auto-update landed, check today. What Happened wp2shell WordPress RCE combines two…

Read More