📖 Reading time: approx. 21 minutes · 4,097 words · 27,083 characters🔊Listen
−1.0×+
⏹ StopBrief content overviewKey Facts
Technical Specifications
Measurements and Observations
Test Conditions and Limitations
The Berlin data volume of 5.7 to 5.8 terabytes and approximately 1.44 million files is currently an estimate provided by Rhysida and must not be treated as an officially verified figure.
Berlin confirmed the publication of stolen data and the ongoing forensic investigation. However, the complete composition of the material, the precise attack vector and the extent of internal movement have not yet been conclusively determined.
The DLSS-5 result of approximately 28 to 30 FPS at 1080p originates from an early, unofficial Radeon experiment. The code is not fully documented publicly and does not constitute a general performance guarantee for Radeon hardware.
On compatible platforms, actual support depends not only on the socket and mechanical compatibility, but also on BIOS capacity, power delivery, signal integrity, firmware, Management Engine and manufacturer support.
Classification
The Berlin incident is qualitatively far more serious than a conventional hardware or software leak. Published administrative archives cannot be reset like a compromised password. Even seemingly unspectacular files can become valuable for phishing, Business Email Compromise and social engineering through the combination of names, telephone numbers, addresses, roles, projects and communication data. Information about buildings, traffic planning, technical infrastructure and administrative procedures may also remain relevant for longer than access credentials.
The remaining security reports follow a common pattern: systems that other systems trust are being attacked. At Coder, manipulated modules were delivered through a compromised Cloudflare API key and were intended to harvest credentials for AWS, GCP and Azure. In JFrog Artifactory, an unauthenticated person can obtain administrative privileges with network access. PaperCut NG and MF were abused through combinable vulnerabilities for authentication bypass and code execution. SonicWall SMA-1000 devices and Elementor Pro installations are being actively attacked.
Strengths
The classification distinguishes confirmed events, statements by the attackers, manufacturer information and unconfirmed rumors.
The Berlin case is not reduced to the number of files, but also considers possible follow-up attacks through data correlation and identity misuse.
The DLSS-5 analysis demonstrates the technical and organizational implications of the leak based on the available implementations on RTX and Radeon hardware.
Limitations
The forensic investigation of the Berlin state network is still ongoing; the full extent of the data exfiltration and the original attack vector are not yet conclusively known.
DLSS 5 performance on Radeon cannot be equated with an official implementation because of the early, unofficial code.
The possible Intel and AMD product characteristics have not been finally confirmed and do not yet permit reliable statements about market position or performance.Generated as an editorial, reader-visible overview from the article content.
The current calendar week 36, from August 31 to September 6, 2026, offers a remarkably broad mix this time. There are classic hardware leaks in which roadmaps, clock speeds and platform details appear ahead of schedule. There is a software leak in which NVIDIA is involuntarily shown how quickly a technology that was supposed to be rolled out in a controlled manner can take on a life of its own after release. And there are several security incidents in which the term “leak” takes on its considerably more unpleasant meaning. By far the most serious case is not taking place in some hypothetical data sheet for an upcoming processor, but in Berlin’s state network. What initially appeared to be a partially unclear cyberattack has now turned into a full-scale data breach followed by extortion and the publication of stolen administrative data. This is qualitatively in a different league from the usual LeakWatch material and, at the same time, a fairly vivid example of why information security at public authorities must not end at the firewall.
Alongside this, NVIDIA’s DLSS 5 provides an almost textbook case for the “once it is out, it is always out” category. The neural rendering component appeared in NBA 2K27 before the actual official launch, was made usable in other games within a very short time and was subsequently brought by modders to hardware for which NVIDIA had not officially intended the technology at all. The experiment has now even extended to Radeon GPUs. Intel, meanwhile, is receiving fresh support for the hope that LGA1954 will actually remain relevant for longer than a single generation, courtesy of a leaked partner slide. AMD is contributing new rumors about the targeted clock speeds of RDNA 5. At the same time, attacks on Coder, JFrog, SonicWall, PaperCut and WordPress installations show that the more interesting leaks this week do not necessarily originate in development departments.
Berlin: The intrusion becomes an actual data leak
The attack on Berlin’s state network entered its most unpleasant phase to date this week. The perpetrators made good on their threat and published stolen data. The Berlin Senate Chancellery explicitly confirmed on September 4 that the stolen data had been published and that security authorities and commissioned IT forensic specialists were examining the material. Individuals identified as specifically affected during this analysis are to be informed depending on the respective risk. This means that an important boundary has been crossed. Previously, there had only been the alleged perpetrators’ claim that they had obtained large quantities of administrative data. It is now at least established that genuinely stolen data has been made publicly accessible. However, not every figure and every description of the contents published by Rhysida has been confirmed with equal certainty.
The ransomware group claims to have stolen approximately 5.7 to 5.8 terabytes, or around 1.44 million files. The state of Berlin has not independently confirmed this volume of data so far. It should therefore not be treated as an officially verified figure. Reuters and other media are also reporting this order of magnitude, citing the perpetrators’ site and the ongoing investigations. According to current knowledge, the essential data exfiltration took place between August 7 and 12. On August 14, affected areas were disconnected from the network. It is particularly relevant that the attack did not affect individual systems only for a short period. The perpetrators apparently had sufficient time to compile and transfer larger quantities of data. The Berlin administration later determined that additional data had been exfiltrated, particularly in the area of responsibility of the Senate Department for Mobility, Transport, Climate Protection and the Environment. Rhysida subsequently attempted to monetize the data. The minimum bid for the stolen material was stated as 30 Bitcoin, equivalent to around two million euros at the time. Berlin explicitly stated that it did not intend to pay. The auction period ended on September 4. Publication followed.
The political decision not to pay a ransom is understandable. However, it does not eliminate the actual problem. In the case of classic ransomware, the focus was often primarily on encrypted systems and the question of whether data could be restored from backups. Modern extortionists, by contrast, are increasingly combining encryption and data exfiltration with double extortion. Even if a company or public authority can restore all systems from backups, the leverage provided by the stolen data remains. And that is precisely why this Berlin case is so serious. A server can be reinstalled. A password can be changed. A published personnel file, a confidential contract document, an internal telephone number, infrastructure information or a combination of names, addresses, roles and contact details, on the other hand, cannot be retrieved.
However, restraint is also necessary in an incident of this kind. On its leak site, Rhysida listed contracts, emails, telephone numbers, passwords, personal data and allegedly confidential or classified documents, among other things. As long as the authorities are still evaluating the published material, such statements by the perpetrators should not be turned into a complete inventory. The danger does not lie solely in individual spectacular documents anyway. An extensive administrative archive can also be problematic when many files appear banal at first glance. Attackers can link different data sets with one another. An internal name gains a telephone number from one file, an organizational role from another document, possibly an address from an invoice and information about communication partners from email archives. Many inconspicuous fragments of information thereby form a substantially more valuable overall picture.
This is precisely what makes large-scale data exfiltration so interesting for phishing, Business Email Compromise and social engineering. An attacker no longer has to approach the victim with an obviously generic message. They can reference specific projects, contacts, organizational structures or actual business processes. There is also a second problem. Information about buildings, transport planning, technical infrastructure or administrative procedures may have a significantly longer half-life than a compromised password. Even if access credentials are changed immediately, plans and internal structures do not disappear automatically.
The Berlin authorities have stated that there is currently no indication of an ongoing infiltration of the state network. However, the forensic investigation is still in progress. This is not a contradiction. “No current indication of an infiltration” does not mean that it has already been fully clarified which attack path was used, how far the perpetrators were able to move and which data sets they accessed. From a technical perspective, it is therefore not enough to investigate only the original entry point. The entire attack chain is decisive. Which identities were compromised? What rights did these accounts possess? Were the perpetrators able to move laterally through the network? Which file servers and specialist applications were accessible? Which data was merely read, and which was actually exfiltrated? Are there indications of persistent access? Which logs are still available for the relevant period at all?
The question becomes particularly unpleasant if logging and network segmentation were not prepared for such a case. Good backups protect against data loss. However, they do not document who copied which data. An antivirus scanner may detect malware. It does not necessarily reveal which legitimate credentials an attacker subsequently used. Ransomware defense has therefore long since become a combination of identity security, network architecture, privileged access management, telemetry, egress monitoring and incident response. The Berlin incident should consequently not be reduced to the question of whether someone had poorly secured an individual server. The actual issue is how far a compromised actor can penetrate within a complex administration and how quickly unusual data exfiltration is detected.
DLSS 5: NVIDIA loses control of the controlled launch
Much more entertaining, although technically interesting as well, is the story surrounding DLSS 5. NVIDIA officially introduced DLSS 5 for NBA 2K27 this week. The focus is no longer limited to conventional reconstruction or frame generation. NVIDIA describes the new technology as 3D-Guided Neural Rendering. A neural model is intended to generate additional visual details using the geometry, material, lighting and motion information provided by the game. However, the event that qualifies for LeakWatch had already occurred immediately before the official launch. The library nvngx_dlssnr.dll appeared in an early version of NBA 2K27. The file was therefore available before NVIDIA had completed the planned rollout.
And what happened next among PC gamers was about as predictable as water following a gradient. The file was examined, extracted and made usable for other games within a very short time. Initial experimental implementations were created using ReShade and other intermediary layers; DLSS 5 was later integrated into OptiScaler, among other projects. Tom’s Hardware was already able to conduct tests with community mods before the official release. What is interesting is not only that DLSS 5 ran in games for which NVIDIA had never intended it. The hardware made the story even more interesting.
NVIDIA initially launched DLSS 5 officially on the GeForce RTX 50 series. However, the early modding attempts already showed that at least parts of the stack are not fundamentally tied to Blackwell. Modders adapted incompatible CUDA components and brought Neural Rendering to run on RTX 40 hardware. Further experiments reached older RTX generations, in some cases with drastically reduced performance. This explicitly does not mean that NVIDIA can simply flip a switch at will and make identical performance possible on every older RTX card. Different data types, Tensor capabilities, throughput and architectural details continue to play a role. Nevertheless, the existence of a fundamentally functional implementation is remarkable. The story becomes even more suitable for a LeakWatch edition because the journey no longer ends with NVIDIA.
On September 5, functioning experiments on AMD Radeon became known. An unofficial implementation can run DLSS 5 Neural Rendering on Radeon RX 9000, and initial tests also exist for RDNA 3 hardware such as the Radeon RX 7900 XTX. The approach apparently uses AMD-native HIP compute kernels to execute parts of the neural workload. The current performance is far from making this a practical alternative. A published test cites approximately 28 to 30 FPS at 1080p on a Radeon RX 9070 XT. The code is also in an early state and is currently not even fully documented publicly. The only recommendation can therefore be not to run such binaries carelessly on a production system. The experiment is nevertheless technically interesting. It shows that the boundary between a proprietary feature and the underlying computational operations is considerably more complicated than a marketing logo on a package might suggest.
The leak also provides a rare glimpse into the actual architecture of such a technology. DLSS 5 is not simply a filter that makes a finished image look better at the end. NVIDIA describes the frame as an immutable geometric foundation that is supplemented by additional engine data. The neural model is intended to modify or supplement material responses, light transport, skin, hair and similar aspects without reinventing the scene geometry specified by the developer. This is precisely why universal mods require additional information. Without motion vectors and other auxiliary data, a model of this kind cannot simply be applied reliably to any arbitrary image. The modding scene is therefore attempting to provide missing information through additional methods or to tap into existing rendering paths. This turns the original leak into almost an independent research platform. NVIDIA is unlikely to be entirely pleased about this. For those interested in the technology, however, it is exceptionally revealing.
Intel LGA1954: Perhaps this time it really is more than a brief affair
Intel is adding a more conventional leak this week. A partner slide from China is said to indicate that the upcoming LGA1954 socket is not only intended to accommodate Nova Lake-S, but is designed for multiple CPU generations. According to VideoCardz, the slide names or implies further generations such as Razor Lake and Hammer Lake after Nova Lake. It does not originate directly from Intel, which is why long-term compatibility cannot yet be considered confirmed. However, what is interesting is that the central premise is no longer a rumor. Intel itself has already mentioned LGA1954 together with NVL-S in a design-in tool entry. The fact that Nova Lake-S uses this socket can therefore be considered practically officially established.
The new slide now adds a possible schedule. According to it, mass production of Nova Lake-S is scheduled to begin in the fourth quarter of 2026. Initial 28-core versions could appear in the first quarter of 2027. Larger 52-core models would follow later. A large bLLC cache of up to 288 MB is also mentioned again. This fits with earlier information about the large dual-compute-tile configurations. Nevertheless, skepticism is warranted regarding socket longevity in particular. A platform can be electrically and mechanically compatible without this automatically meaning that every future processor will be supported on every motherboard. BIOS capacity, power delivery, signal integrity, firmware, Management Engine and manufacturer support can determine which combination actually works. Even so, a multi-generation LGA1954 platform would be a significant improvement over the perception of many Intel desktop platforms in recent years. Whether Intel will actually carry this promise through to Hammer Lake remains one of the more interesting points for the coming months.
AMD RDNA 5: 3.1 to 3.4 GHz are allegedly in the specifications
AMD is also providing fresh material. Kepler_L2 reports, citing internal information, targeted clock speeds between 3.1 and 3.4 GHz for RDNA 5. VideoCardz explicitly classifies the information as a rumor. AMD has confirmed neither these frequencies nor final RDNA 5 products. The range would be at least noteworthy compared with current RDNA 4 products, but not absurd. A Radeon RX 9070 XT officially has a maximum boost of up to around 2.97 GHz. 3.4 GHz would therefore not represent an entirely new frequency range, but roughly 14 percent more. At present, however, not much more can be reliably inferred from the figure. A target clock says nothing about the number of shaders, actual IPC, front-end width, cache hierarchy, memory bandwidth, ray-tracing performance or power consumption. Above all, it is unclear whether the stated range refers to discrete high-end GPUs, APUs or multiple product classes. The report is therefore exactly what a good hardware leak should be: interesting enough to monitor, but far too early for drawing benchmark bars from it.
Coder: The package server was correct; the path to it was not
A further incident this week is considerably less harmless. Coder confirmed an attack on its own Module Registry. Between 07:35 and 21:45 UTC on August 31, an attacker gained access to a Cloudflare API key and manipulated the infrastructure in front of registry.coder.com. As a result, some registry requests were redirected to a server controlled by the attacker. This server delivered manipulated Coder or Terraform modules. The modules were designed to harvest credentials. Coder names cloud credentials for AWS, GCP and Azure, among others, as relevant target information. What is remarkable is the attack path. The attacker did not need to manipulate the actual Coder source code or take over the official build process. The infrastructure between the user and the registry was compromised.
This is an important reminder that software supply chain security does not end at the Git repository. A perfectly signed and verified source code base is of limited help if an attacker gains control over which server delivers the supposedly associated artifacts to a client. Coder stated that it had resolved the incident on the same day. Affected users should in particular check whether modules were loaded during the relevant window and potentially rotate exposed credentials.
SonicWall: Two SMA1000 vulnerabilities are already being actively exploited
Classic perimeter devices are once again providing reasons this week not to postpone updates until the next maintenance month. On September 1, SonicWall published a warning about two vulnerabilities in the SMA-1000 series. CVE-2026-83548 has a CVSS rating of 10.0 and affects an SSRF path accessible before authentication. Under certain conditions, CVE-2026-83549 allows code execution after successful authentication. SonicWall explicitly confirms that the vulnerabilities are already being actively exploited. Remote-access appliances in particular are attractive targets because they are, by definition, intended to be accessible from outside while also providing extensive access to internal networks. An unpatched gateway is therefore not simply another vulnerable device. It can be the entry point into precisely the infrastructure the device is supposed to protect.
PaperCut: Once again, a Zero-Day vulnerability leads to data theft
At the end of August, PaperCut reported two vulnerabilities in PaperCut NG and MF, CVE-2026-82078 and CVE-2026-81578. The two flaws can be chained to bypass authentication and execute code remotely on vulnerable systems. PaperCut responded with several short-term security updates. This week, it became known that the vulnerabilities, which were already being exploited as Zero Days, were also being used for data theft. This is particularly relevant because print management systems often play an unglamorous but extensively integrated role in companies, public authorities, and educational institutions. They have access to directory services, user data, print jobs, and, in some cases, additional infrastructure. The print server may look inconspicuous in the organizational chart. From an attacker’s perspective, it can nevertheless be a highly useful stepping stone.
Elementor Pro: A single file upload can lead to a webshell
WordPress also remains reliable in creating work for administrators. CVE-2026-32475 in Elementor Pro is now being actively exploited. The vulnerability affects the processing of file uploads in forms. Due to incorrect validation of multiple files, an attacker can inject a specially crafted PHP file and subsequently execute code on the server. The affected versions extend up to and including Elementor Pro 4.2.1. On August 19, Elementor had already released security changes for the Form widget in version 4.2.2. Wordfence subsequently reported a very high number of observed exploit attempts. This once again demonstrates the typical time frame of modern WordPress attacks. As soon as a vulnerability is disclosed and a patch becomes available, there is not a leisurely, lengthy analysis phase. Automated scanners begin searching for unpatched installations almost immediately. Those operating a large WordPress installation should therefore not evaluate plugin updates solely on the basis of new features. A changelog entry such as “Improved code security enforcement” can be significantly more important than ten new editor features.
JFrog Artifactory: Admin privileges without logging in
JFrog Artifactory is also affected. CVE-2026-82329 describes a critical authentication vulnerability through which an unauthenticated attacker with network access can obtain administrative privileges. JFrog confirms that the vulnerability is present in the default configuration of various self-hosted Artifactory versions and specifies concrete patched versions. This week, reports emerged that attackers were already using the vulnerability to issue administrator tokens for themselves. Here too, the product’s position is decisive. Artifactory is not just another web service. Repository managers sit directly within software supply chains. Depending on the environment, anyone who gains administrative control there can modify artifacts, manipulate access, and influence downstream build and deployment processes. The boundary between “server compromised” and “software supply chain compromised” is consequently extremely thin.
The actual trend this week: Trust is becoming an attack vector
At first glance, there is little in common between Berlin, Coder, Artifactory, PaperCut, Elementor, and SonicWall. On closer examination, however, a fairly clear common thread runs through the week. Systems that other systems trust are being targeted preferentially. A remote-access gateway is trusted because it brings users into the internal network. A repository is trusted because it delivers software packages. A Terraform Registry is trusted because infrastructure is automatically built from it. A WordPress plugin is trusted because it is permitted to execute PHP and process files server-side. An administrative network contains trust because employees and specialized applications need to access shared data. The more central a service is, the more interesting a successful attack becomes. This also explains why traditional malware is increasingly only one part of the attack chain. The more important question is not necessarily which Trojan was used. It is often more interesting to determine which legitimate trust relationship could subsequently be abused.
The most interesting hardware report of the week is probably Intel’s possible attempt to keep LGA1954 alive for several generations in practice. AMD’s alleged RDNA-5 clock targets are interesting, but still exceedingly thin. The most technically interesting software leak is DLSS 5, because the modding scene impressively demonstrated within just a few days how little control a manufacturer has over distributed binaries once they reach millions of freely programmable PCs. Nevertheless, Berlin is still the most important leak of the week. This is not about a benchmark several months before launch, nor about a DLL that someone found too early. It concerns data belonging to public authorities, employees, citizens, and companies that a criminal group obtained and has now published. The figure of 5.7 or 5.8 terabytes should continue to be treated as an allegation by the perpetrators as long as Berlin has not conclusively confirmed the actual amount of data. The fact that extensive data was stolen and published, however, is no longer speculation.
A rumor can be false. A roadmap leak can be outdated. An engineering sample may never reach the market. A published dataset, by contrast, cannot be pushed back into the server. The internet does not forget particularly well. Criminal archives, unfortunately, forget even less.
What is LeakWatch?
As part of this editorial project, a specially programmed and trained bot is used for the author’s dedicated internet research. It performs the automated analysis of relevant data sources while also creating translations. The aim is to use primary sources that are as unaltered as possible, which is why all links are recorded in a table to enable optional in-depth research by interested readers. Without AI support, the automated search and extraction would only be feasible with disproportionate effort. Nevertheless, every evaluation and the actual text creation are carried out editorially, and all content is reviewed once again because AI cannot always interpret or formulate all content with complete reliability. LeakWatch is designed as a periodically published security and leak analysis format, created in the style of igor’sLAB and according to specific requirements. The focus is on verifiable events from primary sources, technical classification, and a completely neutral assessment without the influence of already filtered secondary information from third parties.
Noch keine sichtbaren Antworten im Forum gefunden. Der Thread ist bereits angelegt und kann direkt im Forum geöffnet werden.
