Posts by Editorial Team
SME Squeeze: NIS2, AI Act, Ransomware Collide
On January 7, 2026, the ransomware group Akira hit Buhlmann Group, a Hamburg-based steel and metal trading company with roughly 2,000 employees and €428 million in annual revenue. The attackers made off with about 55GB of data — engineering drawings, HR files, financial records — before anyone at the company could respond. Buhlmann wasn’t an…
Read MoreVMware vCenter CVE-2026-59310: Germany Hit Hardest
VMware vCenter CVE-2026-59310, a maximum-severity path-traversal vulnerability scoring 9.8 on CVSS, is being actively exploited across 47 countries — and Germany is the single most-affected country of all of them. German incident-response firm QUIRSO uncovered the campaign live during an IR engagement, tracing 361 distinct victim IP addresses back to a directory-traversal flaw in vCenter’s…
Read MorePTC Windchill CVE-2026-12569 Extortion Hits Shell, Philips
The PTC Windchill CVE-2026-12569 extortion campaign run by the Clop ransomware group went fully public on August 12–13, when Clop named Shell, Philips, General Electric, Fiserv and roughly 45 other organizations on its leak site as victims of a data-theft operation running through the same PTC Windchill/FlexPLM flaw DIESEC has already covered twice this year.…
Read MoreSAP Commerce Cloud CVE-2026-58231: CVSS 10.0 RCE
SAP Commerce Cloud CVE-2026-58231, a maximum-severity (CVSS 10.0) flaw disclosed on SAP’s August 2026 Security Patch Day, lets an unauthenticated attacker with network access reach the Data Hub import endpoint and potentially execute arbitrary code — no login, no user interaction, just a crafted request to a component many DACH e-commerce and manufacturing storefronts run…
Read MoreTop 5 Cybersecurity News Stories August 14, 2026
This week’s Cybersecurity News Stories August 14, 2026 arrives during a week when defenders discovered something uncomfortable: the tools and infrastructure they depend on to manage, monitor, and protect their environments were themselves the target. A nation-state rootkit disabled Windows security callbacks at the kernel level. A heating plant lost control of its steam turbine…
Read More
