Critical

DDoS Attacks Cause Major Threema Outages

Security Affairs
Actively Exploited

Overview

Threema, a secure messaging service from Switzerland, experienced significant outages due to large-scale DDoS attacks. These attacks disrupted communication for many users, but organizations using Threema On-Prem were not impacted because their deployments operate on their own infrastructure. The incidents raise concerns about the reliability of online communication services, especially for users who depend on secure messaging for sensitive conversations. As DDoS attacks become more common, companies need to consider additional protective measures to safeguard their services from similar disruptions in the future.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Threema messaging service, Threema On-Prem users
  • Timeline: Ongoing since the attacks occurred recently

Original Article Summary

Large DDoS attacks disrupted Threema, causing severe communication outages. Threema On-Prem users were unaffected by the attacks. Threema suffered multiple large-scale DDoS attacks that disrupted its secure messaging service and caused severe communication issues. Organizations using Threema On-Prem were not affected, as their deployments run on their own infrastructure. Threema is a Swiss paid secure […]

Impact

Threema messaging service, Threema On-Prem users

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since the attacks occurred recently

Remediation

Not specified

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to DDoS.

Related Coverage

Anthropic confirms Claude is down in major outage affecting multiple services

BleepingComputer

Anthropic's AI service, Claude, is currently facing a significant outage that is affecting users' ability to log in and causing slow performance across various Anthropic services. This issue has raised concerns among users who rely on these services for their work. The outage has not been linked to any specific cybersecurity incident, but it highlights the vulnerabilities of cloud-based services and the potential impact on businesses that depend on them. Users are advised to check for updates from Anthropic as the company works to resolve the situation. This incident serves as a reminder of how technical failures can disrupt access to essential tools.

Aug 16, 2026

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110

Security Affairs

The latest edition of the Security Affairs Malware newsletter features significant developments in malware tactics, particularly focusing on the Kimsuky group. Researchers report that Kimsuky has integrated artificial intelligence into its operations, employing AI-generated decoy documents to mislead targets and utilizing a local language model for enhanced attack capabilities. Additionally, the newsletter discusses the evolution of the Kimwolf botnet, now at version 7, which poses a growing risk to various organizations. Agencies like CISA and the FBI are urging companies to stay vigilant against these emerging threats. The evolution of these malware tactics underscores the need for organizations to bolster their cybersecurity measures to protect sensitive information.

Aug 16, 2026

Large-scale DDoS attacks disrupted Threema secure messaging service

BleepingComputer

Threema, a secure messaging platform, experienced significant disruptions earlier this week due to multiple distributed denial-of-service (DDoS) attacks. These attacks overwhelmed Threema's servers, causing service outages and making it difficult for users to send messages. While the company worked to restore normal operations, the incident raised concerns about the security of communication platforms and the potential for similar attacks in the future. Such disruptions can affect users' ability to securely communicate, particularly in sensitive situations where privacy is paramount. This event serves as a reminder of the vulnerabilities that even well-regarded secure services can face from malicious actors.

Aug 16, 2026

Mustang Panda Upgrades CoolClient With a Kernel Rootkit

Security Affairs

Mustang Panda, also known as HoneyMyte, has enhanced its CoolClient backdoor by deploying a signed kernel-mode driver that can conceal processes, files, and network activity. This upgrade makes it significantly harder for security software to detect and remove the malware from infected Windows systems. Kaspersky's recent analysis indicates that this new variant of CoolClient deepens the malware's integration into the operating system, raising concerns for users and organizations relying on Windows. The implications are serious, as this could allow attackers to maintain prolonged access to compromised systems while evading detection. Users and organizations need to remain vigilant and implement security measures to protect against this evolving threat.

Aug 16, 2026

Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers

Security Affairs

France's tax agency has reported a significant cyberattack that compromised the personal data of approximately 678,000 taxpayers. The breach, which occurred in late June, involved hackers stealing sensitive information including income and tax details. This incident has prompted the agency to launch a criminal investigation to identify the perpetrators and assess the extent of the breach. The exposure of such sensitive data raises serious concerns about identity theft and privacy for those affected. As authorities work to secure the system and protect citizens, this attack serves as a reminder of the ongoing risks posed by cybercriminals targeting government institutions.

Aug 16, 2026

Security Affairs newsletter Round 590 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs

A recent cybersecurity concern involves attackers purchasing expired domain names and using them to distribute malware. This tactic allows them to exploit the trust users have in familiar web addresses, potentially leading to security breaches and data theft. Companies and individuals who own domains should monitor their registrations closely to avoid falling victim to this scheme. Additionally, organizations need to educate users about the risks associated with clicking on links from unknown or expired domains. The implications of this practice are significant as it not only affects the victims directly but also undermines overall internet security trust. Staying vigilant and proactive in domain management is essential to mitigate these risks.

Aug 16, 2026