惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
GbyAI
GbyAI
Stack Overflow Blog
Stack Overflow Blog
Recent Announcements
Recent Announcements
D
DataBreaches.Net
量子位
C
Cybersecurity and Infrastructure Security Agency CISA
G
Google Developers Blog
小众软件
小众软件
Application and Cybersecurity Blog
Application and Cybersecurity Blog
MyScale Blog
MyScale Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Cisco Talos Blog
Cisco Talos Blog
P
Proofpoint News Feed
V
Vulnerabilities – Threatpost
Security Latest
Security Latest
T
Tenable Blog
Vercel News
Vercel News
AWS News Blog
AWS News Blog
Forbes - Security
Forbes - Security
M
MIT News - Artificial intelligence
S
Security Affairs
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Hacker News - Newest:
Hacker News - Newest: "LLM"
美团技术团队
L
Lohrmann on Cybersecurity
博客园 - 司徒正美
Last Week in AI
Last Week in AI
罗磊的独立博客
Project Zero
Project Zero
Cyberwarzone
Cyberwarzone
S
Schneier on Security
S
Secure Thoughts
T
Threatpost
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Google DeepMind News
Google DeepMind News
B
Blog RSS Feed
Y
Y Combinator Blog
F
Full Disclosure
N
Netflix TechBlog - Medium
博客园 - 叶小钗
A
Arctic Wolf
腾讯CDC
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
T
The Exploit Database - CXSecurity.com
Jina AI
Jina AI
Apple Machine Learning Research
Apple Machine Learning Research
C
Check Point Blog
C
CERT Recently Published Vulnerability Notes
www.infosecurity-magazine.com
www.infosecurity-magazine.com

Security Affairs

Agent’s claims on WhatsApp access spark security concerns Meta accused of violating DSA by failing to safeguard minors Large-scale Roblox hacking operation shut down by Ukrainian authorities CVE-2026-42208: LiteLLM bug exploited 36 hours after its disclosure Internet censorship index reveals Russia’s lead and widespread content blocking All supported cPanel versions hit by critical auth bug, now patched U.S. CISA adds Microsoft Windows Shell and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog ShinyHunters exploit Anodot incident to target Vimeo CVE-2026-3854 GitHub flaw enables remote code execution Signal Phishing Campaign Targets German Officials in Suspected Russian Operation Microsoft fixes Entra ID flaw enabling privilege escalation New Android spyware Morpheus linked to Italian surveillance firm NCSC launches SilentGlass, a plug-in device to secure HDMI and DisplayPort links Medtronic discloses security incident after ShinyHunters claimed theft of 9M+ records Chinese spy posed as researcher in spear-phishing campaign targeting NASA to steal defense software LINKEDIN BROWSERGATE Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting Fast16: Pre-Stuxnet malware that targeted precision engineering software Italy moves to extradite Chinese national to the U.S. over hacking charges U.S. utility giant Itron discloses a security breach Critical bug in CrowdStrike LogScale let attackers access files GopherWhisper: new China-linked APT targets Mongolia with Go-based malware SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 94 Trigona ransomware adopts custom tool to steal data and evade detection Security Affairs newsletter Round 574 by Pierluigi Paganini – INTERNATIONAL EDITION U.S. CISA adds SimpleHelp, Samsung, and D-Link flaws to its Known Exploited Vulnerabilities catalog Over 400,000 sites at risk as hackers exploit Breeze Cache plugin flaw (CVE-2026-3844) CISA reports persistent FIRESTARTER backdoor on Cisco ASA device in federal network 12-year-old Pack2TheRoot bug lets Linux users gain root privileges Signal phishing campaign targets Germany’s Bundestag President Julia Klöckner China-linked threat actors use consumer device botnets to evade detection, warn UK and partners Luxury cosmetics giant Rituals discloses data breach impacting member personal details iOS Flaw Let Deleted Notifications Linger, Apple Issues Fix RAMP Uncovered: Anatomy of Russia’s Ransomware Marketplace U.S. CISA adds a flaw in Microsoft Defender to its Known Exploited Vulnerabilities catalog Microsoft Graph API misused by new GoGra Linux malware for hidden communication DDoS wave continues as Mastodon hit after Bluesky incident Mirai Botnet exploits CVE-2025-29635 to target legacy D-Link routers Microsoft out-of-band updates fixed critical ASP.NET Core privilege escalation flaw Critical BRIDGE:BREAK flaws impact Lantronix and Silex Technology converters Venezuela energy sector targeted by highly destructive Lotus wiper Ransomware negotiator caught secretly assisting BlackCat extortion scheme North Korea’s Lazarus APT stole $290M from Kelp DAO The US NSA is using Anthropic’s Claude Mythos despite supply chain risk U.S. CISA adds Cisco Catalyst, Kentico Xperience, PaperCut NG/MF, Synacor ZCS, Quest KACE SMA, and JetBrains TeamCity flaws to its Known Exploited Vulnerabilities catalog Bluesky hit by 24-hour DDoS attack as pro-Iran group claims responsibility France’s ANTS ID System website hit by cyberattack, possible data breach Scattered Spider member Tyler Buchanan pleads guilty to major crypto theft CVE-2023-33538 under attack for a year, but exploitation still unsuccessful Third-party AI hack triggers Vercel breach, internal environments accessed AI Model Claude Opus turns bugs into exploits for just $2,283 Cyber attacks fuel surge in cargo theft across logistics industry SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 93 Security Affairs newsletter Round 573 by Pierluigi Paganini – INTERNATIONAL EDITION Hidden VMs: how hackers leverage QEMU to stealthily steal data and spread malware Nexcorium Mirai variant exploits TBK DVR flaw to launch DDoS attacks Microsoft Defender under attack as three zero-days, two of them still unpatched, enable elevated access Kyrgyzstan-based crypto exchange Grinex shuts down after $13.7M cyber heist, blames Western Intelligence DraftKings hacker sentenced to prison, ordered to pay $1.4 Million Operation PowerOFF: 53 DDoS domains seized and 3 Million criminal accounts uncovered Inside ZionSiphon: politically driven malware aims at Israeli water systems U.S. CISA adds a flaw in Apache ActiveMQ to its Known Exploited Vulnerabilities catalog Cisco fixed four critical flaws in Identity Services and Webex Cookeville Regional Medical Center hospital data breach impacts 337,917 people AI platform n8n abused for stealthy phishing and malware delivery From clinics to government: UAC-0247 expands cyber campaign across Ukraine Sweden reports cyberattack attempt on heating plant amid rising energy threats CVE-2026-33032: severe nginx-ui bug grants unauthenticated server access U.S. CISA adds Microsoft SharePoint Server, and Microsoft Office Excel flaws to its Known Exploited Vulnerabilities catalog Mirax malware campaign hits 220K accounts, enables full remote control PHP Composer flaws enable remote command execution via Perforce VCS Microsoft Patch Tuesday for April 2026 fixed actively exploited SharePoint zero-day Personal data of 1 million gym members compromised in Basic-Fit security incident US, UK and Canada disrupt $45M crypto theft in Operation Atlantic ShinyHunters claim the hack of Rockstar Games breach and started leaking data Attackers target unpatched ShowDoc servers via CVE-2025-0520 U.S. CISA adds Adobe, Fortinet, Microsoft Exchange Server, and Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog Fake Claude AI installer abuses DLL sideloading to deploy PlugX Hackers access Booking.com user data, company secures systems iPhone forensics expose Signal messages after app removal in U.S. case Citizen Lab: Webloc tracked 500M devices for global law enforcement Iran-linked group Handala claims to have breached three major UAE organizations CPUID watering hole attack spreads STX RAT malware Adobe fixes actively exploited Acrobat Reader flaw CVE-2026-34621 Hackers claim control over Venice San Marco anti-flood pumps SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 92 Security Affairs newsletter Round 572 by Pierluigi Paganini – INTERNATIONAL EDITION Censys finds 5,219 devices exposed to attacks by Iranian APTs, majority in U.S. GlassWorm evolves with Zig dropper to infect multiple developer tools CVE-2026-39987: Marimo RCE exploited in hours after disclosure Ransomware attack on ChipSoft knocks EHR services offline across hospitals in the Netherlands and Belgium UAT-10362 linked to LucidRook attacks targeting Taiwan-based institutions EngageLab SDK flaw opens door to private data on 50M Android devices Bitcoin Depot hack leads to $3.6M Bitcoin theft via stolen credentials Eurail data breach impacted 308,777 people Malicious PDF reveals active Adobe Reader zero-day in the wild Masjesu botnet targets IoT devices while evading high-profile networks The alleged breach of China’s National Supercomputing Center can have serious geopolitical consequences Internet-Exposed ICS Devices Raise Alarm for Critical Sectors U.S. CISA adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog
One Railway Radio Outage Stopped Trains Across Germany and Nobody Knew Why
https://www.facebook.com/sec.affairs · 2026-06-24 · via Security Affairs

A nationwide GSM-R outage stopped trains across Germany, exposing how one aging communications system can still bring an entire rail network to a halt

At 10:30 PM on Tuesday June 23, Deutsche Bahn told passengers something that had never happened before for technical reasons: all trains across Germany were being held at their stations.

The company confirmed the outage was caused by a nationwide failure of its GSM-R system, the Global System for Mobile Communication for Railways, which handles internal communication across the entire rail network. Without that link, running trains safely isn’t possible, so nothing moved.

“All trains are suspended in Germany’s most populous state, North Rhine-Westphalia.” reported the German media outlet DW.

That line alone gives you the scale. Berlin’s public transport authorities confirmed that municipal, regional, and long-distance Deutsche Bahn trains were all affected. The Berlin S-Bahn suspended all trains on all lines. Stuttgart halted everything on its network.

Deutsche Bahn CEO Evelyn Palla spoke to Bild newspaper in the early hours and was candid about where things stood:

“We are now trying to get the trains into stations so that travelers can disembark. And then we have to fix the problem, which we don’t yet know.” Deutsche Bahn CEO Evelyn Palla said.

That quote is doing a lot of work. The head of one of Europe’s largest rail operators, publicly admitting she didn’t yet know what had broken her entire network.

Engineers identified the cause of the disruption within roughly ninety minutes of the first announcement, and the network came back online just before 1 a.m. Deutsche Bahn said technicians were working around the clock and later confirmed the fix was successful. The company apologized to passengers and said it would issue taxi and hotel vouchers to those affected, with replacement buses arranged where possible.

The Stuttgart S-Bahn’s statement to passengers during the outage captures exactly the kind of uncertainty that cascaded across every station in the country.

“At present, all S-Bahn trains across the entire network are being held at platforms.” said authorities in Stuttgart. “Please check your journey in the travel information system for alternative transport options. We will inform you as soon as we have new information and can assess how long the disruption will last.”

Which is the polite way of saying: we have no idea how long this will last.

GSM-R is a railway-specific version of 2G mobile technology, deployed across Europe since 2000 as the standard for voice and data communications between drivers and control centers. Deutsche Bahn has already signed with Nokia to replace it with a 5G system using the Future Railway Mobile Communication System standard. That replacement hasn’t arrived yet, which means the network that failed Tuesday night is still the one everything depends on. No evidence of a cyberattack or physical infrastructure damage has emerged. The exact technical cause of the failure has not been publicly disclosed. Deutsche Bahn is already notorious for frequent delays and cancellations. A complete nationwide technical halt, in calm weather, with no external cause, is a different category of problem from a late train.

At this time, the situation appears normal; however, as of 6:30 AM, DB warned “some isolated disruptions may still occur” and advised passengers they’ll need to check that their connections will run on time.

The Register confirmed that there is no evidence that the outage was caused by a cyberattack or by physical infrastructure damage such as cut cables. The incident nevertheless raises questions about resilience, as critical infrastructure networks are expected to include multiple layers of redundancy to prevent widespread disruptions. The organization praised its IT team, stating that its experts worked tirelessly and successfully restored services.

In August 2023, Poland’s Internal Security Agency (ABW) and national police launched an investigation into a hacking attack on the state’s railway network. According to the Polish Press Agency, the attack disrupted the traffic overnight.

Stanisław Zaryn, deputy coordinator of special services, told the news agency that Polish authorities were investigating the unauthorized usage of the system used to control rail traffic.

Since the beginning of the Russian invasion of Ukraine, Poland’s railway system has represented a crucial transit infrastructure for Western countries’ support of Ukraine.

Zaryn explained that the attacks are part of a broader activity conducted by Russia to destabilize Poland.

In April 2024, the Czech transport minister Martin Kupka warned that Russia conducted ‘thousands’ of attempts to sabotage European railways.

The Czech Republic’s transport minister told the Financial Times that the attacks aim to destabilize the EU and sabotage critical infrastructure.

Kupka confirmed that Russia-linked threat actors have conducted “thousands of attempts to weaken our systems” since the beginning of the Russian invasion of Ukraine.

The state-sponsored hackers also targeted signaling systems and networks of the Czech national railway operator České dráhy, Kupka said.

The Czech cyber defense was able to detect and neutralize these attacks; however, the minister highlighted that sabotaging railways could cause serious accidents.

At the end of October 2022, a cyberattack caused trains in Denmark to stop; it hit a third-party IT service provider. The attack hit the Danish company Supeo, which provides enterprise asset management solutions to railway companies, transportation infrastructure operators, and public passenger authorities.

DSB is the largest train operating company in Denmark.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)