Large DDoS attacks disrupted Threema, causing severe communication outages. Threema On-Prem users were unaffected by the attacks. Threema suffered multiple large-scale DDoS attacks that disrupted its secure messaging service and caused severe communication issues. Organizations using Threema On-Prem were not affected, as their deployments run on their own infrastructure. Threema is a Swiss paid se

Threema, the Swiss secure messaging service, experienced significant communication disruptions this week due to a series of large-scale distributed denial-of-service (DDoS) attacks. The incidents, which began on Tuesday evening, August 13, 2026, caused intermittent outages for users of its cloud-based service, though customers utilizing Threema On-Prem deployments, which run on their own infrastructure, remained unaffected.
The company initially attributed the problems to a network issue at its colocation provider, Nine. However, Threema later confirmed that both its own infrastructure and that of its colocation partner were targeted by sophisticated DDoS attacks. These attacks were characterized by constantly changing methods, sources, and patterns, making mitigation efforts particularly challenging.
On Tuesday, the service was unavailable for approximately four hours, from 7:30 p.m. to 11:30 p.m. CEST. Intermittent disruptions continued into Wednesday morning, with users in various countries reporting issues even after Threema’s status page indicated service restoration. Normal operations were eventually restored at 12:23 p.m. CEST on Wednesday.
Threema communicated the service disruptions primarily through social media channels. Threema Work business customers received updates via email, and account managers provided information in response to inquiries. A technical issue unrelated to the attacks initially prevented the status page from being updated, leading to its temporary removal until the problem was resolved.
In response to the attacks, Threema implemented additional upstream DDoS protection on August 14, designed to filter malicious traffic before it reaches their infrastructure. The company also announced plans to enhance its status page in the coming days. These improvements will include an incident history and an RSS feed, offering users and administrators an independent channel for receiving system updates.
Threema is a paid messaging service known for its strong focus on privacy and security, positioning itself as an alternative to services like WhatsApp or Signal. The company apologized for the inconvenience caused by the prolonged disruptions.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a