Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack
2026-08-26T02:51:38Z•66fe6dd9566950b83f1146b4e0a9baee8545423ccfbbb8c70ceb693069275b21
CVE-2026-15981CVE-2026-21962CVE-2026-61979CISA KEVDDoSOracleSEO poisoningWebLogicWordPressactive exploitationauthentication bypasscredential theftcritical vulnerabilitygovernment infrastructureinfostealermalwareminiOrange SAMLpasskeysphishingprivacy regulationransomware
What happened
Security Affairs coverage reports a new DDoS attack against Norway’s shared digital government infrastructure; major privacy and regulatory actions involving Uber and TikTok; active exploitation of critical authentication bypasses in the miniOrange SAML 2.0 Single Sign On WordPress plugin (CVE-2026-61979 and CVE-2026-15981); a maximum-severity unauthenticated Oracle HTTP Server/WebLogic Proxy Plug-in flaw added to CISA’s KEV catalog (CVE-2026-21962); malware distribution through fake Minecraft and GTA VI sites; cyber risks in Slovak road speed cameras; an advanced phishing toolkit that enrolls
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 66fe6dd9566950b83f1146b4e0a9baee8545423ccfbbb8c70ceb693069275b21
- Enrichment time
- 2026-08-26T02:51:38Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.