New: EU CAPTCHA – GDPR-compliant bot protection. Try it free for 3 months!
Home>
Trending Topics Cybersicherheit – June 2026
SECURITY INSIGHTS | July 1, 2026
Myra's monthly security highlights provide IT executives and security professionals with the most relevant topics from the world of cybersecurity. Current trends, defense strategies, and reports on cyberattacks, attack campaigns, and more are presented here in a clear and concise format.


What seems secure today may already be compromised tomorrow. AI is accelerating this cycle in ways that fundamentally challenge classical defense strategies. The Five Eyes alliance and Germany’s BSI agree: the time horizon for new AI-powered offensive capabilities is measured in months, not years. At the same time, the Claude Fable 5 case shows that even the most secure AI models can be jailbroken within days of release. AI is therefore not only a tool for defenders — it has long since become a lever for attackers who find and exploit vulnerabilities faster than ever before.
Those who rely on AI systems create dependencies — and these dependencies are not only technical in nature, but increasingly geopolitical. When the U.S. Department of Commerce ordered Anthropic in June to shut down its models worldwide within 90 minutes, it affected the company’s customers around the globe — without warning, without exception. EU Digital Commissioner Virkkunen put it plainly: no one should hold the “kill switch” to Europe’s critical infrastructure. The conclusion is clear: Europe needs its own AI capabilities and a digital sovereignty that does not rest on the goodwill of third-party states.
Resilience, however, does not begin with the next strategy paper — it begins with consistent action today. Around 10,500 NIS2-obligated companies in Germany ignored the expired registration deadline. As a result, the BSI has granted a final extension until the end of July. Attackers grant no such extensions. The “FortiBleed” attack campaign, which compromised 74,000 firewalls worldwide, demonstrates clearly what happens when known vulnerabilities are not patched in time. Meanwhile, the breach at V-Bank via a third-party IT service provider is a reminder that resilience must encompass the entire supply chain — not just an organization’s own systems.
IT Security Trends
New Federal Data Protection Commissioner: Prof. Dr. Moritz Hennemann elected
The German Bundestag has elected Prof. Dr. Moritz Hennemann, with 391 votes, as the new Federal Commissioner for Data Protection and Freedom of Information (BfDI). The Freiburg law professor specializing in information and internet law is regarded as pragmatic and innovation-friendly — and has at times been critical of the GDPR. He succeeds Prof. Dr. Louisa Specht-Riemenschneider, who stepped down for health reasons. His official appointment by the Federal President is still pending.
Five Eyes: AI is transforming cyber risks — the window for action is months, not years
The cybersecurity agencies of the Five Eyes alliance warn in a joint statement: AI models are dramatically shortening the time horizon for new offensive capabilities. Attackers benefit from speed, reach, and automation, while defenders remain bound by operational constraints. Germany’s BSI joined the warning. The statement is explicitly addressed to executive leadership: cybersecurity is “a matter for the C-suite.”
EU Commissioner criticizes U.S. export restrictions on AI models
EU Digital Commissioner Henna Virkkunen has sharply criticized U.S. export restrictions on Anthropic’s models: such measures are “not the right approach” and must be coordinated with international partners. No one should hold the “kill switch” to Europe’s critical infrastructure, Virkkunen stated. In response, the Commission is advancing the Tech Sovereignty Package.
BSI warns of growing cyberthreat posed by high-performance AI models
Germany’s BSI classifies powerful AI models such as Claude Mythos as a serious cybersecurity threat: they lower the barrier to entry for attacks, accelerate vulnerability analysis, and enable partially autonomous attack paths. BSI President Claudia Plattner expects “sweeping changes across the entire vulnerability landscape.” IT teams will have less and less time to respond to emerging threats.
NIS2: BSI sets deadline extension to end of July — fines on the horizon
The statutory NIS2 registration deadline expired on March 6, 2026 — approximately 10,500 of the roughly 29,000 obligated companies have yet to register. The BSI has now granted an extension until July 31, 2026. Non-compliance carries fines of up to €500,000 and personal liability for senior management. Industry experts are calling for more consistent enforcement to prevent NIS2 from becoming a “paper tiger.”
Domestic intelligence service: universities are too complacent about espionage
Domestic intelligence chief Sinan Selen warns that awareness of academic espionage at universities lags significantly behind that of the private sector. China is reportedly using both cyberattacks and human sources embedded via exchange programs. In May 2026, a German couple was suspected of operating on behalf of a Chinese intelligence service at German universities. The structural openness of academic institutions makes protection particularly challenging.
Cybercrime
FortiBleed: Admin passwords of 74,000 firewalls compromised worldwide
In a highly automated campaign, threat actors compromised administrator credentials for approximately 74,000 Fortinet FortiGate firewalls across 194 countries. Configuration data was extracted and password hashes were cracked using GPU clusters. Affected organizations include companies and government agencies worldwide. Patches have been available since April 2026 — affected organizations should immediately reset passwords and enforce MFA.
V-Bank: attackers breach systems via IT service provider — data exfiltrated
Germany’s largest custodian bank for independent asset managers was attacked via a compromised third-party IT service provider. Personal data belonging to customers and business partners was stolen; account access credentials and funds are not believed to be affected at this time. Supply chain attacks represent a growing risk in the financial sector.
Saarland University: data of over 40,000 students stolen
A vulnerability in the Moodle learning platform of Saarland University was exploited to steal profile data belonging to more than 40,000 students. Passwords are reportedly not affected, according to the university. The relevant data protection authority has been notified and a criminal complaint has been filed. Open university platforms remain an attractive target for attackers — particularly for extortion attempts, which is also suspected as a possible motive in this case.
Lapsus$ claims data theft at IKEA franchisee Ingka Group
The extortion group Lapsus$ claims to have stolen 180 GB of internal data from Ingka Group — including source code repositories, supply chain systems, and cloud infrastructure data. IKEA has not yet confirmed the incident. Analysts rate the risk as critical: exposed source code gives attackers a detailed blueprint for targeted follow-on attacks.
Ransomware: Germany is Europe’s hotspot — trail leads to Russia
According to the Hasso Plattner Institute, Germany is the most heavily ransomware-affected country in Europe. Germany’s Federal Criminal Police Office (BKA) recorded 1,041 cases in 2025. Attack trails frequently lead to Russia, where cybercriminals face little risk of prosecution. The boundaries between cybercrime and state-tolerated operations are increasingly blurred.
U.S. orders Anthropic to shut down AI models worldwide
On June 12, 2026, the U.S. Department of Commerce ordered Anthropic to deactivate Claude Fable 5 and Mythos 5 globally within 90 minutes — citing an alleged jailbreak with security-relevant abuse potential. Since separating access by nationality in real time was technically not feasible, the models were taken offline for all customers worldwide. The incident exposes Europe’s structural dependence on U.S. AI providers.
Best Practice, Defense & Mitigation
A year after Federal Interior Minister Dobrindt’s announcement, the planned Cyberdome remains largely undefined. The Potsdam Conference on National Cybersecurity offered a first glimpse of its contours: a detection network spanning ten federal states and expanded intervention powers for Germany’s BKA and BSI. A full implementation concept is not planned until the end of 2026, with a cabinet decision to follow. Concrete steps toward realization are still absent.
Fable 5 jailbroken within days: AI security needs depth, not illusions
Shortly after its release, security researchers succeeded in bypassing the Claude Fable 5 classifier using Unicode substitutions and narrative embedding. Security expert Bruce Schneier notes that complete jailbreak resistance is currently unachievable for AI models — a view Anthropic itself shares. The takeaway: AI security strategies must rely on layered defense and rapid response, not on the illusion of absolute protection.
Ströer and domestic intelligence service: IT security warnings on digital billboards
The Bremen State Office for the Protection of the Constitution and media company Ströer are using digital out-of-home advertising to broadcast IT security warnings — a partnership that is unique in Germany to date. The first campaign warned against a phishing scheme in which attackers impersonated Signal support staff. Further campaigns covering hybrid threats and disinformation are planned.
Operation Endgame: international authorities dismantle three global malware networks
Germany’s BKA, Europol, and partners from six countries dismantled the infrastructure behind the malware strains “SocGholish,” “StealC,” and “Amadey.” More than 320 servers, 15,000 websites, and 140 domains were taken offline; 27 million victim records were secured. For the first time, AI tools were used in the analysis phase, processing complex malicious code in minutes rather than days.
Things to know
Annual DDoS simulations are no longer enough: continuous testing is essential
Annual DDoS simulations rarely reflect real operating environments: infrastructure changes continuously as new services, configurations, and providers are introduced. More frequent, architecture-specific load tests provide a more accurate picture of an organization’s resilience. Given the dramatic rise in DDoS attacks, adjusting testing frequency has become a strategic imperative.
Federal government spends nearly €500 million on Microsoft licenses
In 2025, Germany’s federal administration spent approximately €481 million on Microsoft products — 38 percent more than the previous year and double the 2023 figure. The open-source alternative OpenDesk has not moved beyond a few thousand licenses. Critics warn of growing vendor dependency and steadily rising costs. Further price increases are already announced for 2026.
Stefan Bordel
Senior Editor
Stefan Bordel has been working as Editor and Technical Writer at Myra Security since 2020. He is responsible for the strategic development and editorial management of all content formats – from website content and specialist publications to whitepapers, social media communication, and technical documentation. In this role, he combines solid expertise from IT journalism with in-depth technical understanding in the field of cybersecurity. As a long-time Linux enthusiast, he closely follows developments in the IT industry both professionally and personally.