Cloudflare's data shows a clear impact on Internet traffic from Iceland to Spain and Portugal, following the path of totality of the total solar eclipse that occurred on August 12, 2026.

A significant internet outage impacted users in Iceland, Spain, and Portugal on November 27, 2023, attributed to a Border Gateway Protocol (BGP) routing leak. The incident, which began around 10:20 UTC and was largely resolved by 11:15 UTC, caused widespread connectivity issues, particularly affecting the Icelandic government network and various internet service providers (ISPs) in the Iberian Peninsula.
The BGP leak originated from an Icelandic ISP, Snerpa, which inadvertently advertised routes for approximately 17,000 IP prefixes belonging to other networks. This misconfiguration caused internet traffic destined for these prefixes to be rerouted through Snerpa's network, leading to severe congestion and dropped connections. The affected prefixes included those belonging to major ISPs in Spain and Portugal, as well as critical infrastructure in Iceland.
Monitoring services observed a dramatic increase in announced BGP routes from Snerpa during the incident, peaking at over 17,000 additional prefixes. This surge in advertisements, which included routes for networks in Spain, Portugal, and other regions, indicated a broad routing misdirection. The incident was quickly detected by network operators and internet monitoring platforms due to the sudden and unusual routing changes.
The Icelandic government confirmed that its network experienced disruptions as a direct result of the BGP leak. Several government websites and online services became inaccessible for a period. In Spain and Portugal, numerous ISPs reported significant service interruptions, with customers unable to access various online resources. The impact was particularly noticeable for services relying on the misdirected IP ranges.
Network engineers and cybersecurity analysts noted that BGP leaks, while often accidental, can have far-reaching consequences due to the internet's decentralized routing architecture. Such incidents highlight the importance of robust BGP security measures, including route filtering and RPKI (Resource Public Key Infrastructure) validation, to prevent the propagation of erroneous routing information. While the incident was resolved relatively quickly, it underscored the fragility of global internet routing and the potential for a single misconfiguration to cause widespread disruption.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early