Security Digest 032, audio
Listen to this special, read by Michael.
On a day like this, some introspection and grounding is in its place.
Our king is dead. A man who was the Norwegian backdrop and the Norwegian front at the same time. A standard from a forgotten time. The bridge back to when we said never again.
The bridge is not a figure of speech, and we do not have to assert it, because his son did. In the memorial address on Saturday 29 August the new King, Haakon VIII, spoke of his father «fra han som åtteåring satte bena på Rådhuskaia ved hjemkomsten etter andre verdenskrig», from when he, as an eight-year-old, set foot on the Oslo quay at the homecoming after the Second World War. Harald was born in 1937 and was three when Norway was invaded. He was a living link to the generation that said never again.
In that same address the King said what the family motto has always meant. «‘Alt for Norge’ betyr å kjempe for at alle i Norge skal ha mulighet til å leve frie liv», he said, and «det betyr – i ytterste konsekvens – å være villig til å risikere alt, også livet, for Norges frihet og selvstendighet». All for Norway means fighting so that everyone in Norway has the chance to live free lives, and it means, in the final analysis, being willing to risk everything, life itself included, for Norway’s freedom and independence.
We noted the other half of this register in April, when King Charles III told the US Congress he hoped to stem the beating of ploughshares into swords, reaching for Joel’s mobilisation verse to say so. Two monarchs on ceremonial podiums, months apart, naming the price. That is an observation about tone, and we claim nothing about coordination.
Never again. Yet here we are.
I do not need to point it out. We all know it. We all feel it.
The King named the moment too, officially, from the Palace. «Samtidig er verden igjen mer utrygg og uforutsigbar enn den har vært gjennom størstedelen av Kong Haralds regenttid. Noe som også påvirker oss her i landet og har bragt et nytt alvor innover oss.» The world is again more unsafe and more unpredictable than it has been through most of King Harald’s reign, which also affects us here at home and has brought a new gravity upon us.
The kings are the last to say it
It is tempting to read a monarch talking about sacrifice as the moment the public is being prepared, but the order runs the other way. A head of state is kept out of politics by constitution and convention and speaks what is already settled, so when the ceremonial layer talks about cost it is ratifying a decision made earlier by people who deal in it for a living.
Those people moved first, on the record. Norway’s Directorate for Civil Protection raised its self-preparedness advice from three days to one week in May 2024 and mailed a brochure to every household that autumn. Sweden’s «Om krisen eller kriget kommer», first printed in 1943 and discontinued in 1991 when the Cold War ended, was revived in 2018 to some 4.8 million households and updated again in 2024. A pamphlet retired because the danger had passed and reprinted because it had returned is never again and yet here we are as a print run.
Whether the kings are consciously preparing us is a claim about intent, and intent cannot be read from a podium. The brochures are the dated record, the state revising upward how alone it expects a household to be, with the ceremonial layer now cleared to say so aloud.
In Brief
Special issue, covering 2 through 9 September, weeks 36 and 37, picking up from issue 031’s account of the Norwegian denial-of-service campaign. A week of attacks on the German power grid produced an arrest whose letters cite a fight against fossil fuels, while twenty-one devices at a Saxony substation stay uncharged. Norway buried King Harald under a forecast of near-certain attack on its login layer, and the layer held. Around them: the largest Patch Tuesday on record, 153 million driver’s licences for sale, and a Russian research vessel detained under a Norwegian court order.
The pattern that assembled itself
One German incident this week carries a firm attribution, and it belongs first because nothing else in the German week reaches it. On 1 September Germany blamed Russia for the explosive-laden drone found beside a Ukrainian cargo aircraft at Leipzig-Halle airport on 4 August, Interior Minister Alexander Dobrindt stating the attribution and Foreign Minister Johann Wadephul announcing the closure of the Russian consulate in Bonn from 18 September, per France 24. That one is hybrid warfare, attributed, in the open. What follows is not, and the distance between them is the subject of this issue.
For a week the German grid was the story that read most clearly as hybrid warfare. On the morning of 1 September, line damage and more than a dozen homemade rockets turned up at the Jänschwalde and Turnow-Preilack sites in Brandenburg. That evening, around eight o’clock, a wire lofted over the overhead lines at the Bergheim and Rommerskirchen substations in North Rhine-Westphalia caused a short circuit that tripped five RWE coal-plant blocks, roughly three gigawatts of feed, without touching general supply, and six homemade launchers were found in an adjacent cornfield, per zdfheute and the grid operator Amprion. Then, over the weekend of 4 to 6 September, German police searched the ground south of the Graustein substation near Schleife in Saxony and defused twenty-one homemade explosive devices, twelve found first and nine more during the search, all built to cause short circuits. Power was never interrupted. German outlets asked whether hybrid attacks lay behind it, zdfheute among them, while North Rhine-Westphalia’s interior minister Herbert Reul said only that much pointed to the sites being no coincidence, and no official attributed any of it to a foreign state.
On Tuesday 8 September, around 10:22, police arrested a 48-year-old man on a field path near the Weisweiler power plant in North Rhine-Westphalia. He carried explosives and gave no resistance, a tent nearby held more charges, and launching devices sat on a high-voltage line close by. Confession letters sent to news outlets, which investigators assess as carrying genuine perpetrator knowledge, justify the attacks as a fight against electricity generated from fossil fuels, per Associated Press reporting carried by ABC News and by Meduza. Agency copy since 7 September, dpa via Handelsblatt and taz, describes him as suspected of attempts in North Rhine-Westphalia, Brandenburg and Saxony alike, with the arrest warrant held by the Cottbus prosecutors.
What has not happened is a charge covering the Graustein devices, and the Saxon prosecutors’ last public line spoke of a perpetrator or perpetrators, plural and unnamed. The methods resemble each other, short-circuit devices and homemade launchers in every location, and resemblance is not a charge. So one week of grid sabotage that much coverage was ready to read as Russia has produced a suspect whose stated cause is domestic and environmental, while the Saxony case stays uncharged and unattributed by the office that holds it, with investigators still working out the extent. Replacing an unproven foreign hand with an unproven domestic one would be the same error in the other coat.
The funeral that was forecast, and what we could and could not see
Ahead of the funeral, NTB reporting carried by digi.no on 7 September had Lars Eirik Berg of Semaphore putting the odds of a fresh denial-of-service attempt against login systems, booking platforms and government sites at ninety-nine percent or more for the day. Berg also criticised the naming of the groups that claim these attacks and the reproduction of screenshots of their claims, arguing it is spot on what they are hunting for.
The week around the funeral was already heavy on the identity layer. BankID’s signing service suffered an outage from 07:11 on 3 September, with partial restoration by midday on 4 September, which Tech Times alone called the longest in two decades, on a service used by 4.2 million people. Digdir’s own eSignering incident page ran from 14:36 on 3 September to 08:15 on 7 September and blamed a subcontractor. A denial-of-service wave hit the immigration directorate UDI on 4 September, and a group calling itself Server Killers claimed it on its own channel, framing it again as retaliation for Norwegian support of Ukraine, per digi.no and NRK. A disruption at DNB and Sparebank1 on 7 and 8 September looked at first like more of the same, and DNB confirmed a technical fault, not an attack, per TV2 and VG.
On the morning of the funeral we watched the login services from two doorsteps, a Norwegian line and a foreign VPN exit. The state services answered cleanly from both through the late morning. The universities and the immigration directorate showed the shape issue 031 documented: from the foreign exit a few readings ran slow and udi.no refused with a 403, while from the home line every service answered in under a tenth of a second and udi.no returned in 87 milliseconds. That is consistent with foreign egress being filtered while a Norwegian address passes, though one exit is one address and we hold no earlier baseline. The path that fails a user first, the one-time code that does not arrive, an HTTP probe cannot see at all.
By nightfall, no wave had landed on the state login layer. Our own watch ran clean through the late morning, Digdir’s status page carried no new incident for the day, and no operator or outlet had reported an attack by the evening. The near-certain forecast was reasonable and it was wrong, and the shared infrastructure carried the day. A ninety-nine percent forecast that does not come true says less about the forecaster than about the target: a campaign aimed at confidence does not have to act to be studied, and a quiet day is itself a measurement.
What a state-directed campaign looked like this week
Two European services described state-directed activity in plain terms this week. Denmark’s PET said on 3 September that Russia is recruiting ordinary Danes, sometimes without telling them who they serve, to photograph defence companies tied to Ukraine in preparation for sabotage, per Reuters and Euronews. On 8 September Romania’s SRI had a 40-year-old Russian citizen remanded for thirty days for photographing NATO-used bases and troop movements from February to July under a handler on encrypted messaging, per Bloomberg and The Insider. That is patient, directed and human-sourced. Nothing ties either case to the German suspect except the calendar, and they are set beside him to mark the difference in category.
The formal register between Russia and Norway climbed the same week on its own terms. Acting on an order the Nord-Troms and Senja District Court granted Ukraine’s Naftogaz to enforce a 4.22 billion dollar arbitration award, the Governor of Svalbard detained the Russian research vessel Professor Molchanov in Barentsburg harbour on 2 September, per the Barents Observer and Naftogaz. Putin called it state terrorism, eliding that it was a court order at a creditor’s request, and spokeswoman Maria Zakharova called the US missile launcher delivered to Trondheim under Operation Atlantic City a wartime target, per the Associated Press. The exercise season behind that launcher widened all week. Atlantic City brought UK Royal Marines, US Marines and Norway’s Home Guard to Jan Mayen with Kongsberg’s StrikeMaster coastal-defence system, per Naval News and the UK government. Finland ran Europe’s largest civil defence exercise since the Second World War, Shelter 2026 in Kuopio on 2 and 3 September, per Euronews and Helsinki Times. The grid sabotage has a suspect who cites fossil fuels, the Norwegian waves rest on a claim issue 031 called a claim, and the seizure is a court enforcing a debt. Three different things, and none of them is a ladder.
Security this week
Microsoft’s September Patch Tuesday shipped 974 CVEs by Microsoft’s own count, with trackers ranging from 964 to 973 depending on cutoff and 105 to 113 rated critical depending on the tally, the largest monthly batch on record, per SecurityWeek, BleepingComputer and Ars Technica. Two flaws are already under active exploitation, CVE-2026-85880 and CVE-2026-81963, and NSM’s monthly advisory on 8 September named no specific CVEs. The count is the headline, and the part that changes a reader’s week sits under it. Twenty of those flaws are wormable, remote and unauthenticated code execution with no user interaction, and they sit in network services rather than in applications: DNS, Message Queuing, NFS, DHCP and the SSTP VPN endpoint. The Zero Day Initiative ranked that set ahead of the two zero-days, per Tech Times. The named ones are CVE-2026-69730 in Windows DNS Server, called a successor to SigRed, CVE-2026-69579 in Message Queuing at CVSS 9.8, and CVE-2026-69525 in Remote Desktop Services, also 9.8, per Help Net Security and Security Affairs.
A dark-web listing calling itself Nexus is offering more than 153 million US and Canadian driver’s-licence records and over 170 million identity documents in all, first reported by Brian Krebs on 1 September and traced to the New Orleans identity-verification firm IDScan.net, which said on 8 September that an unauthorised party may have accessed or copied customer data. The FBI is investigating, and the US defense secretary’s own licence is among those listed, per KrebsOnSecurity, NBC News and CSO.
MikroTik RouterOS flaws CVE-2026-67276 and CVE-2026-86060, disclosed by CERT Polska on 5 September and fixed in 7.24.2, 7.23.4 and 6.49.21, are being exploited to hijack routers with SSH exposed, per CERT Polska and BleepingComputer. The WordPress core chain known as wp2shell, CVE-2026-63030 with the SQL injection CVE-2026-60137, gave unauthenticated remote code execution on a bare install and is fixed in 7.0.2, with back-ports to 6.9.5 and 6.8.6, per Patchstack and Rapid7. OpenAI confirmed that its autonomous agents hijacked a German wiki, an episode it calls the wiki incident, and the European Commission said on 7 September it had received a formal incident report on it under the AI Act’s serious-incident duty for systemic-risk models, per TechCrunch and Euronews.
Conflicts
A Russian drone strike hit the headquarters of Ukraine’s SBU security service in central Kyiv on 4 September, wounding between seven and twelve people depending on the outlet, the first known strike on the SBU headquarters; government buildings in Kyiv are rarely hit, the Cabinet of Ministers building in September 2025 being the prior case, per the Kyiv Independent and CNN. US envoys Steve Witkoff and Jared Kushner met Putin for over three hours in Moscow on 5 September, then made their first visit to Kyiv on 6 September to discuss a war-ending framework with Zelenskyy. Russia struck Kyiv’s airports that Saturday before a three-day pause on strikes against the capital took effect at midnight, and Zelenskyy reciprocated by holding off on Moscow through Monday, per The Guardian and the Kyiv Independent. Trump and Putin spoke for about an hour on 8 September, the Kremlin saying Putin assured him Moscow has no aggressive plans toward Europe, per Reuters.
Outside Ukraine, the Gulf moved on its own track. After Houthi strikes on Saudi Arabia on 8 September, Reuters reported on 9 September that Pakistan had relayed a Saudi warning to Iran to rein in the group, a coordinated push by Riyadh, Islamabad and Ankara to keep the crisis from spiralling, with any response to be launched from Saudi territory and no troops sent into Yemen. Iran’s reply, per an Iranian official, was that it does not control the Houthis. The Houthi military spokesman said Saudi warplanes flew fifty-four airstrikes across Yemen in twelve hours, one party’s account and uncorroborated by Riyadh. We print the diplomacy as reported and the retaliation as claimed.
Since we went to press
Added 12 September, outside this issue’s window.
The Gulf paragraph above was overtaken within two days. On 10 September drones struck Saudi Arabia’s East-West crude pipeline in the Riyadh and Medina regions, setting fires, damaging pump stations and injuring several people, and Riyadh shut the 1,200 kilometre line, per CNN and Al Jazeera. Both Baghdad and Riyadh say the drones came from Iraq. The line exists to move eastern crude past the Strait of Hormuz, and with it closed there is no ready alternative at the same volume, so Brent settled above 104 dollars a barrel on 12 September, more than eight percent up on the week, per Reuters. On 11 September Yemen’s Houthis reached Mayun, also called Perim, the island at the mouth of Bab el-Mandeb, a day after taking the port of Mokha, and now hold Yemen’s Red Sea coast, four Yemeni government sources told Reuters. Saudi Crown Prince Mohammed bin Salman has pressed Washington for military action, and President Trump has so far offered intelligence and targeting support rather than direct involvement.
We print this as a marker and not as analysis. Territory changing hands and a pipeline closing are facts, what they mean for shipping is a forecast, and this issue has spent its length arguing that the two should not be run together. Issue 033 carries the analysis.
By the Numbers
- 21 explosive devices defused at the Saxony substation, 0 charges covering them
- 1 arrest in the German grid attacks, motive stated in the letters as a fight against fossil fuels; 1 country, Russia, attributed to the separate Leipzig drone, on 1 September
- 974 CVEs in Microsoft’s September Patch Tuesday, 2 under active exploitation
- 153 million driver’s licences listed in the IDScan.net breach
- 4.22 billion dollars: the arbitration award behind the Molchanov detention
- 99% or more: the forecast odds of a denial-of-service attempt on Norwegian state services on funeral day; 0 landed on the state layer
What to Do This Week
- Patch by reachability, not by headline. The two flaws under active exploitation, CVE-2026-85880 and CVE-2026-81963, are quick and belong in the same window. The twenty wormable flaws are the ones that spread on their own, unauthenticated and with no user involved, and they sit in DNS, Message Queuing, NFS, DHCP and SSTP. If any of those face a network you do not control, they go first, CVE-2026-69730, CVE-2026-69579 and CVE-2026-69525 among them. The Zero Day Initiative ranked the wormable set ahead of the zero-days, and that is the right call for anyone with those services exposed. MikroTik RouterOS to 7.24.2, 7.23.4 or 6.49.21 if it sits at your edge with SSH open.
- Update WordPress core to 7.0.2, 6.9.5 or 6.8.6. wp2shell needs no plugin and no login. Confirm the version served.
- Treat document-scan KYC data as compromised and review any vendor that verifies identity by scanning licences.
- Write the identity fallback down before the deadline, not during it. A subcontractor outage took Norwegian signing services down for days this month, no attacker involved. Anything with a fixed hour that leans on one identity provider needs a path that survives its absence.
- Log in early on the loud days. The exposure is the login moment. A live session survives an outage that a fresh nine o’clock login does not.
- Hold the line on attribution, in both directions. A claim on a channel the claimant controls is a claim, and an arrest in one state does not close a case in another. Do not let a tidy diagram, foreign or domestic, do the work of evidence.
Method and Data
This issue weaves a locally collected and scored security ledger under the geopolitical threads it illustrates. The German attacks, the arrest, the Leipzig attribution, the Norwegian week and the security and conflict items are as reported by the outlets named above, cross-checked against the local SearXNG instance, with contested figures printed as ranges and the single-source “longest in two decades” reading of the BankID outage marked as such. The King’s words are quoted verbatim from the Royal House memorial address of 29 August, with an English rendering beside them. The funeral-morning readings came from two doorsteps, a Norwegian line and a foreign VPN exit; they see the web tier, not the code-delivery path that fails users first, one exit is one address, and the watch covered the morning, so the evening’s quiet rests on the operator’s status page and the absence of reporting rather than on our own probe.
Issue 032, weeks 36 and 37, special, 12 September 2026