View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Pro-Russian group claims DDoS attack on Norway’s public digital

🚨 ACTIVE EXPLOITATION

  • Pro-Russian group claims DDoS attack on Norway’s public digital services
    A DDoS attack disrupted Norway’s shared government digital services.
    • Norwegian citizens, businesses, public agencies and some health services were affected.
    • The attack disrupted Digdir services including ID-porten, MinID and eSignering; ID-porten serves more than 4.5 million users.
    • Attackers flooded Digdir and provider Vivicta infrastructure with massive traffic, causing outages, slow responses and login failures.
    • Pro-Russian group Server Killers claimed responsibility, but Norwegian officials had not confirmed the attribution.
    • Digdir reported no evidence of system compromise or personal-data exposure.
      📎 Coverage: apnews.com · 👁 via SecurityWeek

💥 BREACHES & INCIDENTS

  • ATF confirms standalone system breach after Qilin ransomware claim
    ATF confirmed a major incident involving a compromised standalone system.
    • The incident affects the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF).
    • A standalone ATF system was compromised; the enterprise network, eForms system and other systems show no indicated impact.
    • Qilin listed ATF on its dark-web leak portal but provided no evidence of stolen data.
    • ATF has not attributed the incident to Qilin, and the intrusion method and data accessed remain undisclosed.
      📎 Coverage: bleepingcomputer.com · 👁 via BleepingComputer

🕵️ RESEARCH & DEEP DIVES

  • Russian-Linked Groups Use Fake Google Drive Pages to Hijack Accounts
    Russian-linked groups are hijacking targeted accounts through fake cloud-storage pages and diplomatic lures.

    • Targets include academics, diplomats, defense and aerospace personnel, government users, nonprofits, and think tanks in Europe and the United States.
    • UNC6293, UNC7005, and UNC5976 abuse Google OAuth, app-password, and WhatsApp device-linking workflows rather than software vulnerabilities.
    • UNC5976 uses file-sharing-themed domains and fake Google Drive pages to redirect victims through legitimate Google sign-in and capture OAuth tokens.
    • UNC7005 uses diplomatic and conference invitations to link attacker-controlled WhatsApp devices and deploy JavaScript that records calls.
    • UNC7005 has also delivered Vidar, Atomic (AMOS), and other infostealers to Windows and macOS users.
      📎 Coverage: theregister.com · 👁 via Cyber Security News, cryptika.com (discovered)
  • ESET Identifies GuardBreaker LLM Safety-Evasion Technique in Ukraine Attack
    ESET observed Russia-aligned UAC-0099 using GuardBreaker to disrupt AI malware analysis.

    • The campaign targeted a victim in Ukraine; UAC-0099 typically targets transportation and energy sectors.
    • A malicious VBS script downloaded and installed MATCHBOIL malware used by UAC-0099.
    • The script embedded nuclear-weapon text as a comment to trigger LLM safety mechanisms and halt analysis of the remaining code.
      📄 Source: cert.gov.ua · 📎 Coverage: infosec.exchange · 👁 via @ESETresearch@infosec.exchange
  • RPC-Triage maps and ranks Windows RPC attack surfaces from PE files
    RPC-Triage is an open-source tool for statically analyzing Windows RPC attack surfaces.

    • Windows RPC security researchers and assessors are the target users.
    • The tool analyzes PE files to recover RPC, MIDL, and NDR internals, endpoints, security state, and method-level input signals.
    • It works offline without PDBs, live endpoint-mapper access, or target execution.
    • An AHP/Saaty-based model ranks interfaces and provides scoring receipts plus questionable-extraction markers.
      📄 Source: github.com · 📎 Coverage: reddit.com · 👁 via r/cybersecurity

📋 ADVISORIES

  • 📄 Source for US Seizes QTFY Infrastructure Used in Chinese Espionage Campaignlumen.com

  • 📄 Source for GPUThor Rowhammer Bypasses ECC on NVIDIA GDDR6 GPUs for Root Accessdiscourse.org

🔓 CVEs & KEV

  • CVE-2026-18431 — CVSS 9.8 — Avada through 7.16 and Fusion Builder through 3.16 - Unauthenticated Remote Code Execut...

  • CVE-2026-77693 — CVSS 8.7 — Order Tip for WooCommerce before 1.6.0 - Shop Manager+ Arbitrary File Deletion via...

  • CVE-2026-75797 — CVSS 7.7 — AI Engine 3.3.3 - 3.7.1 - Subscriber+ Arbitrary File Read via 'url' Parameter...

  • CVE-2026-74928 — CVSS 7.5 — WP Project Manager 2.1.0 - 4.0.6 - Unauthenticated Subscriber Account Creatio...

  • CVE-2026-78146 — CVSS 6.5 — Noptin before 4.3.3 - Unauthenticated Subscriber PII and confirm_key Disclosure vi...

  • CVE-2026-3002 — CVSS 6.4 — Gutenverse through 4.0.2 - Authenticated (Contributor+) Stored Cross-Site Scriptin...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check