Norway ’s shared government infrastructure suffered a third DDoS attack, disrupting digital services but showing no signs of data compromise. Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupted services used by citizens, businesses and public agencies. The incident began at 03:38 CEST on Monday, August 24, […]

Norway's shared digital government infrastructure has been subjected to a third distributed denial-of-service (DDoS) attack, causing widespread disruption to public services. The latest incident, which began at 03:38 CEST on Monday, August 24, targeted infrastructure operated by the Norwegian Digitalisation Agency (Digdir) and its service provider, Vivicta.
Digdir confirmed that several shared services experienced complete unavailability for short periods, while others suffered from connection failures, slow responses, and extended login times. The agency operates critical components of Norway's public-sector infrastructure, including ID-porten, MinID, Maskinporten, eFormidling, eInnsyn, the Contact and Reservation Register, and Ansattporten.
The impact of the attack extended beyond Digdir's direct services. Altinn, Norway's central platform for communication between citizens, businesses, and government, was also affected. Other public services relying on ID-porten experienced login problems, demonstrating how disruption to a shared authentication service can propagate throughout the digital government ecosystem. Previous attacks this summer similarly affected access to Helsenorge, NAV, and Skatteetaten.
Digdir has emphasized that the incident primarily concerns service availability and has found no indication of a successful intrusion or compromise of personal data. Director Frode Danielsen stated that there is no evidence the attack led to a security breach or that personal data was exposed. The agency has notified Norway's National Security Authority (NSM) and the Data Protection Authority (Datatilsynet) as part of its response.
This latest attack marks the third such incident in a short timeframe. Previous DDoS attacks against Digdir's services occurred in June and on August 3. The June incident specifically targeted ID-porten through Vivicta's network infrastructure, temporarily affecting services including ID-porten, MinID, Maskinporten, eInnsyn, and eFormidling. While Digdir and Vivicta have been able to mitigate these attacks and restore services, the repeated nature of the incidents suggests a persistent challenge for the wider public sector.
The ongoing campaign highlights how repeated attacks against shared infrastructure can create significant operational friction, forcing defenders to continuously adjust traffic controls, filtering rules, and protection measures. Digdir's status updates on August 24 reflected this dynamic, reporting initial improvements followed by complete outages for some solutions, and subsequent stabilization efforts.
There has been no official attribution for the attacks. While Norwegian media has speculated about potential Russian involvement, this remains unconfirmed. The motivation behind the DDoS campaign could range from political or financial objectives to simply demonstrating capability. Without technical evidence and an official attribution process, assigning responsibility to a specific state or group would be premature.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed