Threats Affecting Norway
View all threats affecting or targeting Norway. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Norway
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2025-68137 is a high-severity buffer overflow vulnerability in the EVerest everest-core EV charging software stack versions prior to 2025.10.0. It arises from an integer overflow in the SdpPacket::parse_header() function, causing incorrect buffer length calculations that lead to either an infinite loop or a stack buffer overflow depending on the server configuration (TCP or TLS). This vulnerability can result in full compromise of confidentiality, integrity, and availability without requiring authentication or user interaction. The flaw is fixed in version 2025.10.0. European organizations operating EV charging infrastructure using affected versions are at risk of service disruption and potential remote code execution. Mitigation requires immediate upgrade to the patched version and careful network segmentation of EV charging systems. Join the discussion | CVE Database V5 | 09/02/2026, 00:00:00 UTC Added: 01/21/2026, 19:35:56 UTC |
A pro-Russian hacker group named Server Killers claimed responsibility for a major denial-of-service cyberattack targeting Norway's public digital services managed by the Norwegian Digitalization Agency (Digdir). The attack, ongoing for three days, aimed to disrupt services including a unified login system for citizens. Despite the attack's scale, the agency maintained service availability nearly continuously. The group declared cyber war on Norway following Norway's renewed security cooperation with Ukraine. Norwegian officials have not commented on the claim. This incident is part of broader malign cyber activities linked to Russia targeting European countries amid geopolitical tensions. Join the discussion | SecurityWeek | 08/27/2026, 08:00:00 UTC Added: 08/27/2026, 16:52:30 UTC |
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure, impacting public sector services since Monday. The attack has caused significant service interruptions but no specific technical details or exploited vulnerabilities have been disclosed. Join the discussion | Bleeping Computer | 08/25/2026, 15:52:36 UTC Added: 08/25/2026, 16:22:17 UTC |
0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18300. Join the discussion | Zero Day Initiative | 08/21/2026, 00:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
Erlang is a programming language and runtime system for building massively scalable soft real-time systems with requirements on high availability. OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang. Packet size is not verified properly for SFTP packets. As a result when multiple SSH packets (conforming to max SSH packet size) are received by ssh, they might be combined into an SFTP packet which will exceed the max allowed packet size and potentially cause large amount of memory to be allocated. Note that situation described above can only happen for successfully authenticated users after completing the SSH handshake. This issue has been patched in OTP versions 27.2.4, 26.2.5.9, and 25.3.2.18. There are no known workarounds for this vulnerability. Join the discussion | CVE Database V5 | 08/20/2026, 00:00:00 UTC Added: 11/03/2025, 20:49:00 UTC |
Kratos is a mature Phishing-as-a-Service operation targeting Microsoft 365 users across the United States, Europe, and other regions. The platform enables attackers to steal credentials through trusted platforms, anti-bot verification, and convincing login pages. Researchers traced three generations of the kit and uncovered 1,484 previously unattributed detonations. The operation targets organizations across more than 20 countries with particularly strong concentration in the US, Spain, and Southern Europe. Kratos includes an operator panel allowing deployment of phishing domains, configurable Telegram or email delivery, geographic restrictions, and multiple anti-bot systems. The kit has evolved through three page generations (V0, V1, V2) with different exfiltration code. Activity has been visible since January 2026, with the operator panel active since September 2025. Join the discussion | AlienVault OTX General | 07/14/2026, 16:36:39 UTC Added: 07/16/2026, 10:17:37 UTC |
A misconfigured Python HTTP server on a Budapest VPS exposed the complete operational infrastructure of three distinct phishing operators. The investigation uncovered codemado, an Egyptian threat actor operating since 2018, running a full AiTM platform with custom tools including MaDoO Blaster; saroula01, deploying OAuth Device Code Flow attacks that accumulated 218 victims across 12 countries over a year; and mail-argenta, a Nigerian operator identified through infostealer logs containing his own credentials. All three actors leveraged customized Evilginx forks and AI-assisted development to build MFA-bypass infrastructure from public GitHub repositories. The campaigns targeted Microsoft 365 accounts primarily, with codemado maintaining ties to RockyBelling's "The Quarry" cybercrime ecosystem. The exposed server contained phishing configurations, credential logs, RMM installers, combolists, and Telegram session files, revealing sustained operations from at least January 2025 through May 2026. Join the discussion | AlienVault OTX General | 07/13/2026, 10:36:53 UTC Added: 07/13/2026, 11:03:04 UTC |
A malware-as-a-service campaign named Weedhack targets Minecraft users by distributing malicious Java JAR files via SEO poisoning and YouTube videos. The malware steals credentials, system information, and can remotely control infected systems. It is notable for its ease of access, free tier, and appeal to younger users, with infections primarily in the U. S.and several other countries. Additionally, a large CountLoader campaign spreads cryptocurrency clipper malware via cracked software, and a separate campaign distributes cryptocurrency miners through pirated content sites. These campaigns leverage sophisticated persistence and evasion techniques and have been active since early 2026. Join the discussion | Reddit Cybersecurity | 06/03/2026, 07:35:27 UTC Added: 06/03/2026, 07:48:26 UTC |
A reflected cross-site scripting (XSS) vulnerability in the dashboard search functionality of the VertiGIS FM solution allows attackers to craft a malicious URL, that if visited by an authenticated victim, will execute arbitrary JavaScript in the victim's context. Such a URL could be delivered through various means, for instance, by sending a link or by tricking victims to visit a page crafted by the attacker. Join the discussion | CVE Database V5 | 04/01/2026, 13:12:24 UTC Added: 04/01/2026, 13:38:38 UTC |
0 An arbitrary file overwrite vulnerability in Tinybeans Private Family Album App v5.9.5-prod allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. Join the discussion | CVE Database V5 | 04/01/2026, 00:00:00 UTC Added: 04/01/2026, 14:08:53 UTC |
Showing 1 to 10 of 719 results