Swiss Federal SharePoint Breach Hits 200 Accounts

The Swiss Federal SharePoint Breach compromised 200 accounts at Switzerland's national IT agency, likely via a July Patch Tuesday flaw.

The Swiss federal SharePoint breach compromised roughly 200 accounts at Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT/FOITT), the agency confirmed in early August 2026. It is the first time DIESEC’s ongoing SharePoint vulnerability coverage has connected to a confirmed, named breach inside a DACH government body — not just a vendor advisory.…

Read More

N-central CVE-2026-18577 Auth Bypass — CISA 3-Day Deadline

N-central CVE-2026-18577 Auth Bypass — CISA 3-Day Deadline

N-central CVE-2026-18577 auth bypass is being actively exploited to seize administrative control of N-able N-central servers — a remote monitoring and management (RMM) platform managed service providers (MSPs) use to run client networks. CISA gave federal civilian agencies just three days to patch, with the deadline landing August 6, 2026. What Happened N-able disclosed that…

Read More

Keyv npm Supply Chain Attack Hits 2 Billion Installs

Keyv npm Supply Chain Attack Hits 2 Billion Installs

The Keyv npm supply chain attack compromised a single GitHub maintainer account and used it to push a credential-stealing worm into hundreds of widely used caching packages. By August 5, trackers put the count at 868 packages and 1,381 versions, spanning a combined 2 billion-plus monthly installs — the largest software supply-chain incident DIESEC has…

Read More

Microsoft Teams Vishing Ransomware Hits in 17 Hours

A Microsoft Teams vishing ransomware campaign, STAC4749, breached dozens of firms via fake IT-helpdesk calls, encrypting networks within 17 hours.

A Microsoft Teams vishing ransomware campaign has hit dozens of North American organizations since February 2026, using two-minute fake IT-helpdesk phone calls to gain a foothold that, in the fastest confirmed case, ended in full Chaos ransomware encryption within 17 hours of first contact. What Happened Security vendor Sophos tracked the campaign to a financially…

Read More

Stadler Rail Everest Ransomware: SFr10m Demand Refused

Stadler Rail Everest Ransomware: SFr10m Demand Refused

The Stadler Rail Everest ransomware incident shows what a mature extortion response looks like: the Swiss train manufacturer confirmed that the Everest group stole supplier technical data through a shared data-exchange platform and demanded roughly SFr10m (about $12.3M) — and Stadler refused outright, filing a criminal complaint instead of negotiating. What Happened Stadler Rail, an…

Read More