Berlin Ransomware Attack: State Refuses to Pay

Berlin ransomware attack 2026 — Rhysida extortion of German state government network

A Berlin ransomware attack has put Germany’s capital in the position every public-sector CISO dreads: a confirmed data breach, a seven-figure ransom demand, and an election three weeks away. The ransomware group Rhysida claims it stole 5.79 terabytes from Berlin’s state administrative network and is demanding 30 Bitcoin, roughly €2.05 million, with a seven-day auction…

Read More

miniOrange SAML SSO Bypass Vulnerability

A miniOrange SAML SSO bypass (CVE-2026-61979, CVE-2026-15981) lets attackers forge admin logins on WordPress — and most scanners miss it.

A miniOrange SAML SSO bypass is under active exploitation against WordPress sites, and most vulnerability scanners cannot detect whether a given site is actually affected. Two chained authentication bugs, CVE-2026-61979 and CVE-2026-15981 (CVSS 9.8 each), let an unauthenticated attacker forge a SAML login and access wp-admin as any existing user, including administrators. DigitalOcean confirmed exploitation…

Read More

GitLab GraphQL code injection vulnerability

A GitLab GraphQL code injection vulnerability (CVE-2026-19478, CVSS 9.4) was exploited within minutes of disclosure. What happened and how to patch now.

A GitLab GraphQL code injection vulnerability is now under active exploitation, reproduced and attacked within minutes of GitLab’s August 17, 2026 disclosure of CVE-2026-19478. The unauthenticated flaw (CVSS 9.4) lets an attacker delete public projects, forge fake fix records, or lock out maintainers on any unpatched self-managed GitLab instance. GitLab.com and GitLab Dedicated were already…

Read More

Zimbra Command Injection Vulnerability Actively Exploited

A Zimbra command injection vulnerability is under active exploitation against on-premises mail servers; the CISA federal deadline already passed.

A Zimbra command injection vulnerability is under confirmed active exploitation against on-premises mail servers, and CISA’s federal remediation deadline of August 24 has already passed. Tracked as CVE-2026-73570, the flaw lets an unauthenticated attacker execute arbitrary shell commands on any unpatched Zimbra Collaboration Suite instance with SNMP notifications enabled — a configuration many administrators never…

Read More

Windows Defender Zero-Day Vulnerability Has No Patch

Windows Defender zero-day vulnerability

A Windows Defender zero-day vulnerability disclosed on August 12, 2026 lets a low-privileged local attacker bypass Microsoft’s own patch for an earlier Defender flaw and escalate straight to SYSTEM. Tracked as CVE-2026-69414 and nicknamed ShieldBreak, the flaw still has no fix ten days after Microsoft assigned the CVE. Any Windows endpoint running default Defender is…

Read More