Large-scale DDoS attack on IT partner Vivicta knocks Norwegian digital identity and healthcare services offline
Authorities in Norway have reported a sustained, large-scale distributed denial-of-service (DDoS) attack against Vivicta, the IT infrastructure partner of the Norwegian Digitalisation Agency (Digdir), disrupting critical public systems for more than 30 hours. The high-volume assault impacted ten digital services, most notably ID-porten; the nation’s central digital identity gateway used by over 4.5 million citizens to authenticate via BankID and MinID across thousands of public portals.
The outage caused cascading operational disruptions across Norway’s healthcare infrastructure, crippling electronic prescription systems and online pharmacy access reliant on ID-porten for federated authentication. Marking the third DDoS incident to hit Digdir-associated infrastructure since June, officials noted the latest attack is two to three times larger than previous events, though no sensitive data was accessed or exfiltrated. The incident highlights the severe availability risks tied to upstream third-party IT dependencies, demonstrating how volumetric DDoS attacks targeting single centralized identity hubs can paralyze national infrastructure and essential public services without requiring system compromise.
EU Cyber Resilience Act enforces strict incident reporting and lifecycle vulnerability management for connected products
The European Union’s Cyber Resilience Act (CRA) is approaching its first critical implementation milestone on 11 September, when mandatory reporting requirements under Article 14 take effect for manufacturers of hardware and software products with digital elements. Under the new horizontal regulation, organizations distributing commercial connected technologies in the EU must report actively exploited vulnerabilities and severe security incidents to designated Computer Security Incident Response Teams (CSIRTs) and ENISA within strict timeframes, submitting an early warning within 24 hours and a detailed notification within 72 hours.
The legislation legally mandates secure-by-design product development, requiring vendors to maintain machine-readable Software Bills of Materials (SBOMs), implement coordinated vulnerability disclosure policies, and guarantee security updates for the expected product lifetime (with a mandatory five-year minimum floor and ten-year technical documentation retention). Ahead of full compliance enforcement on 11 December 2027, non-compliant entities face severe regulatory penalties of up to €15 million or 2.5% of total worldwide annual turnover, alongside potential product recalls and EU market access restrictions. The framework fundamentally shifts supply-chain security by compelling SOC, product security, and incident response teams to tightly integrate rapid vulnerability triage, upstream component tracking, and multi-agency regulatory disclosures into standard operating procedures.
Microsoft Teams Silent Phishing
In August 2026, researchers at Expel published an analysis of a newly observed, highly modular malware family named SynkLoader. Distributed through targeted Microsoft Teams phishing campaigns impersonating corporate IT support, SynkLoader introduces several novel techniques. Most notably PhishLocker, a fake full-screen Windows 11 lock screen designed to harvest credentials without tripping endpoint detection alarms such a Sophos EDR.
Some recommended technical mitigations are Phishing-Resistant MFA for login. This includes FIDO2 to prevent stolen credentials and keys from granting access to SSO portals. On the other hand, user awareness of unexpected appearing lockscreens is important. The user can press Ctrl-Alt-Del or Alt-Tab to invoke interrupts that cannot be faked in this case by PhishLocker.
ATF confirms “major incident” after recent Qilin breach claims
The UK’s Alcohol and Tobacco Fraud (ATF) authority has confirmed that it is dealing with a “major incident” following claims by the Qilin ransomware group that it successfully breached the organisation’s systems. While officials have not yet disclosed the full extent of the impact, the confirmation signals that the incident is being treated as a serious cybersecurity event, with investigations underway to determine what data or services may have been affected. The development highlights the ongoing threat posed by ransomware groups targeting public sector and government-related organisations, where operational disruption and potential data exposure can have significant consequences. Authorities are expected to continue assessing the situation and implement measures to contain any risks while maintaining critical services.
Analyst Insight
These developments highlight the growing convergence of cyber threats targeting critical services, trusted identities, and interconnected supply chains. The large-scale DDoS attack against Vivicta demonstrates how adversaries can significantly disrupt national infrastructure by targeting upstream service providers, with the prolonged outage of Norway’s ID-porten platform causing widespread disruption across healthcare and public services despite no underlying system compromise.
The approaching implementation milestones of the EU Cyber Resilience Act further reflect the increasing regulatory focus on improving supply-chain security, vulnerability management, and incident transparency, placing greater responsibility on manufacturers to adopt secure-by-design principles and maintain robust incident reporting capabilities. Meanwhile, the emergence of SynkLoader illustrates the continued evolution of social engineering and credential theft techniques, with threat actors leveraging trusted collaboration platforms such as Microsoft Teams and sophisticated fake lock-screen mechanisms to harvest credentials and bypass traditional security controls.
Finally, the ATF’s confirmation of a major incident following Qilin ransomware claims reinforces the ongoing threat posed by ransomware groups targeting public sector organisations, where service disruption, data theft, and extortion remain primary objectives. Collectively, these incidents emphasise the need for organisations to strengthen identity security through phishing-resistant authentication, enhance resilience against availability attacks affecting critical third-party providers, improve visibility across software supply chains, and maintain mature detection, incident response, and recovery capabilities to mitigate both operational and strategic cyber risks.
