September 2026 Cybersecurity Roundup

September 2026 Cybersecurity Roundup: Berlin's Rhysida leak, Keio, Landsberg, 220M exposed travel records, plus 4 exploited CVEs.

This September 2026 Cybersecurity Roundup covers a month in which ransomware kept disrupting public services and critical infrastructure, while flaws in widely used network appliances created serious exposures of their own. Attacks hit German government and utility networks, and a misconfigured database exposed 220 million Vietnam-linked travel records. Below are the month’s key cyberattacks and…

Read More

TerminalFix ClickFix Attack Campaign Hits Germany

A TerminalFix ClickFix attack campaign compromised a German state institution, BSI confirms — heise links it to Berlin's Rhysida actor cluster.

A TerminalFix ClickFix attack campaign has compromised a German state institution’s network, Germany’s Federal Office for Information Security (BSI) confirmed on September 4. TerminalFix is an evolution of the ClickFix social-engineering technique: a fake CAPTCHA tricks a user into pasting a command, but instead of the old single-machine Run-dialog trick, it opens Windows Terminal and…

Read More

Berlin Ransomware Attack: State Refuses to Pay

Berlin ransomware attack 2026 — Rhysida extortion of German state government network

A Berlin ransomware attack has put Germany’s capital in the position every public-sector CISO dreads: a confirmed data breach, a seven-figure ransom demand, and an election three weeks away. The ransomware group Rhysida claims it stole 5.79 terabytes from Berlin’s state administrative network and is demanding 30 Bitcoin, roughly €2.05 million, with a seven-day auction…

Read More