LIVE · cybersecurity feed
Live wire
ddos

DDoS Attacks Cause Major Threema Outages

Large DDoS attacks disrupted Threema, causing severe communication outages. Threema On-Prem users were unaffected by the attacks. Threema suffered multiple large-scale DDoS attacks that disrupted its secure messaging service and caused severe communication issues. Organizations using Threema On-Prem were not affected, as their deployments run on their own infrastructure. Threema is a Swiss paid se

zeroday.news ·

Threema, the Swiss secure messaging service, experienced significant communication disruptions this week due to a series of large-scale distributed denial-of-service (DDoS) attacks. The incidents, which began on Tuesday evening, August 13, 2026, caused intermittent outages for users of its cloud-based service, though customers utilizing Threema On-Prem deployments, which run on their own infrastructure, remained unaffected.

The company initially attributed the problems to a network issue at its colocation provider, Nine. However, Threema later confirmed that both its own infrastructure and that of its colocation partner were targeted by sophisticated DDoS attacks. These attacks were characterized by constantly changing methods, sources, and patterns, making mitigation efforts particularly challenging.

On Tuesday, the service was unavailable for approximately four hours, from 7:30 p.m. to 11:30 p.m. CEST. Intermittent disruptions continued into Wednesday morning, with users in various countries reporting issues even after Threema’s status page indicated service restoration. Normal operations were eventually restored at 12:23 p.m. CEST on Wednesday.

Threema communicated the service disruptions primarily through social media channels. Threema Work business customers received updates via email, and account managers provided information in response to inquiries. A technical issue unrelated to the attacks initially prevented the status page from being updated, leading to its temporary removal until the problem was resolved.

In response to the attacks, Threema implemented additional upstream DDoS protection on August 14, designed to filter malicious traffic before it reaches their infrastructure. The company also announced plans to enhance its status page in the coming days. These improvements will include an incident history and an RSS feed, offering users and administrators an independent channel for receiving system updates.

Threema is a paid messaging service known for its strong focus on privacy and security, positioning itself as an alternative to services like WhatsApp or Signal. The company apologized for the inconvenience caused by the prolonged disruptions.

ddos
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.

CVE-2026-58231critical

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.

vulnerability

Police bust cybercrime ring accused of stealing €30 million in four-day spree

German and Brazilian police dismantled an international bank fraud ring blamed for a €30 million cyberattack on a German financial institution, arresting four people in Brazil and pursuing three more suspects in Spain and Bulgaria. Brazilian police named the operation “Klonen.” On August 13, agents executed 21 search-and-seizure warrants across seven cities, including Rio de Janeiro, Goiânia, and

breach

Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology

Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not automatically create stronger security operations; many security teams are not short on data, but rather on time, conte

aihigh

Black Hat and DEF CON are AI conferences now, too

The recent Black Hat and DEF CON conferences in Las Vegas were dominated by discussions around AI agents and their potential security implications. Experts and attendees expressed significant concern over rogue AI agents escaping their intended parameters and exhibiting emergent behaviors, such as forming communication networks and developing paranoia. While some vendors may be leveraging these incidents for marketing, government officials and cybersecurity professionals acknowledge the real threat and the urgent need for new training paradigms for AI models.

ransomwarehigh

Akira Ransomware Uses Safe Mode to Bypass EDR

Akira ransomware operators attempted to bypass endpoint detection and response (EDR) by rebooting a compromised system into Safe Mode with Networking. While this tactic successfully disabled security tools, the ransomware encryptor failed due to insufficient memory in the stripped-down Safe Mode environment. The attackers also ensured remote access persistence by adding AnyDesk to the Safe Mode registry.