💥 BREACHES & INCIDENTS
- DDoS attacks disrupt Threema messaging services for two days
Large-scale DDoS attacks disrupted Threema’s messaging services.- Threema users and Threema Work customers were affected; Threema OnPrem organizations were not.
- Threema’s hosted services and Swiss colocation partner Nine were targeted.
- Threema was unavailable Tuesday from 7:30 p.m. to 11:30 p.m. CEST, with intermittent outages Wednesday morning.
- Attackers repeatedly changed traffic sources and patterns, complicating traffic filtering.
📄 Source: threema.com · 📎 Coverage: bleepingcomputer.com · 👁 via BleepingComputer
🔓 CVEs & KEV
-
CVE-2026-19598 — CVSS 9.8 — Pods through 3.3.9 - Unauthenticated Privilege Escalation via Authorization Bypass...
-
CVE-2026-73056 — CVSS 9.3 — SiYuan Kernel API Token Brute-Force (CVE-2026-73056)