TerminalFix ClickFix Attack Campaign Hits Germany

A TerminalFix ClickFix attack campaign compromised a German state institution, BSI confirms — heise links it to Berlin's Rhysida actor cluster.

A TerminalFix ClickFix attack campaign has compromised a German state institution’s network, Germany’s Federal Office for Information Security (BSI) confirmed on September 4. TerminalFix is an evolution of the ClickFix social-engineering technique: a fake CAPTCHA tricks a user into pasting a command, but instead of the old single-machine Run-dialog trick, it opens Windows Terminal and…

Read More

SonicWall SMA1000 RCE Vulnerability: Patch Now

SonicWall SMA1000 RCE vulnerability

A new SonicWall SMA1000 RCE vulnerability is under active exploitation: an unauthenticated server-side request forgery chained with an OS command injection lets an attacker take full root-level control of the appliance with no login required. CISA added both flaws to its Known Exploited Vulnerabilities catalog on September 2, with a federal deadline of September 5,…

Read More

Identity Theft in Germany: What SMEs Need to Know

Identity theft and stolen credentials drive most cybercrime in Germany

Germany’s cybercrime problem has a number attached to it: an estimated €202.4 billion in damage to the German economy for the 2025 reporting period, around 4.5 percent of GDP, according to the Federal Criminal Police Office’s (BKA) latest Bundeslagebild Cybercrime report. Behind much of that damage sits a quieter but persistent issue: identity theft in…

Read More

SME Squeeze: NIS2, AI Act, Ransomware Collide

Three regulatory and threat deadlines create an SME squeeze in Germany

On January 7, 2026, the ransomware group Akira hit Buhlmann Group, a Hamburg-based steel and metal trading company with roughly 2,000 employees and €428 million in annual revenue. The attackers made off with about 55GB of data — engineering drawings, HR files, financial records — before anyone at the company could respond. Buhlmann wasn’t an…

Read More