Flash Briefings
Short, sector-focused intelligence on active and emerging threats. Written for security and business leaders who need the picture fast.
Critical Gitea RCE Added to CISA KEV After Active Exploitation Deploys Miner Payloads
CISA added CVE-2026-60004, a critical unauthenticated-to-authenticated remote code execution flaw in self-hosted Gitea instances, to its Known Exploited Vulnerabilities catalog on August 25 after attackers were observed using it to drop cryptomining-style payloads.
CVE-2026-21962: Max-Severity Oracle WebLogic Proxy Flaw Under Active Exploitation — CISA Sets 3-Day Deadline
CISA added CVE-2026-21962, a CVSS 10.0 unauthenticated bypass in the Oracle WebLogic Server Proxy Plug-in and Oracle HTTP Server, to its Known Exploited Vulnerabilities catalog on August 24, 2026 — issuing its tightest-ever three-day federal patching deadline. Attackers are chaining path traversal and header manipulation to reach backend WebLogic instances directly.
The Gentlemen Ransomware Hijacks Hospital's Facebook Page to Pressure AnMed Health
The Gentlemen ransomware group escalated its extortion of nonprofit health system AnMed by seizing control of the hospital's Facebook page to publicize ransom demands, two weeks after an initial breach claiming 6TB of patient data.
Emperador Extortion Group Claims Breach of Vietnam's Largest Power Utility
A newly surfaced extortion group calling itself Emperador claims to have breached EVNHANOI, part of Vietnam Electricity, exposing over 300GB of customer and account data. The claim is unconfirmed by EVN or Vietnamese authorities.
Critical GitLab Flaw Under Active Exploitation Two Days After Disclosure
An unauthenticated, CVSS 9.4 GraphQL code-injection vulnerability in self-managed GitLab (CVE-2026-19478) is being actively exploited to delete or rewrite public repositories, with watchTowr confirming attacks within days of the emergency patch.
Microsoft Discloses Maximum-Severity CVSS 10.0 Entra ID Remote Code Execution Flaw
CVE-2026-69836, a deserialization bug in Microsoft's cloud identity platform, carried a perfect CVSS score — but Microsoft says it was never exploited and has already been fixed on its side, with no customer action required.
NSA, CISA, FBI Warn of AI-Generated Exploit Scripts Targeting Siemens S7 PLCs
A joint advisory from NSA, CISA, FBI, DOE and EPA warns that threat actors are using AI to generate exploitation scripts against internet-exposed Siemens S7 Series PLCs across water, energy, manufacturing and food and agriculture sectors.
Heights Finance Discloses Breach Exposing 1.2 Million Customers' SSNs and Bank Details
A US consumer lender has disclosed that hackers accessed a third-party cloud platform storing customer records, exposing Social Security numbers, bank account details, and government ID data for more than 1.2 million people.
CISA Adds SharePoint JWT Auth Bypass CVE-2026-55040 to KEV Catalog Amid Active Exploitation
A critical authentication bypass in on-premises SharePoint Server is being actively exploited days after a public proof-of-concept, letting unauthenticated attackers impersonate any user, including administrators.
Cavern C2 Evolves: Iranian MOIS Group Adds Google Apps Script and M365 Calendar Channels
Kaspersky and Group-IB analysis reveals Iranian MOIS-linked Cavern Manticore has extended its C2 framework with DNS-directed Google Apps Script relays and a new HOLLOWGRAPH module abusing Microsoft 365 calendar events — while APT42 separately targets the nuclear energy sector with AI-accelerated TAMECAT implants.
APT36 Campaign Deploys Three-Malware Cluster Against Afghan Telecom and South Asian Infrastructure
Acronis TRU has documented three previously undisclosed malware families — PATCHCORD, SHEETCORD, and a GitHub-based C2 agent — targeting Afghan telecom providers and Indian critical infrastructure in an espionage campaign active since March 2026.
Gunra Ransomware Actors Hit Healthcare, Finance, and Critical Infrastructure Across Five Continents
CISA, the FBI, NSA, and South Korean authorities have issued a joint advisory on Gunra, a Conti-derived ransomware-as-a-service operation that has compromised organisations across healthcare, financial services, manufacturing, transportation, and government sectors globally.
Clop Claims Shell Data Exfiltration: 89GB of Energy Sector Data at Risk
Clop has claimed responsibility for stealing 89GB of data from Shell, with the energy major now investigating a 'potential incident'. The claim follows Clop's established pattern of mass data theft through file transfer platform vulnerabilities, with the group's latest campaign affecting multiple sectors simultaneously.
CVE-2026-59310: VMware vCenter Exploited Globally Five Days After Disclosure
A critical directory-traversal vulnerability in VMware vCenter was patched July 29 and exploited within five days -- an APT actor has compromised 361 servers across 47 countries, deploying reverse shell infrastructure via a malicious cron job.
Lazarus Burned a Windows Kernel Zero-Day for Six Weeks Targeting Defence and Aerospace
CVE-2026-68820, a use-after-free in Windows AFD.sys patched on August 11 Patch Tuesday, was actively exploited by North Korea's Lazarus Group since early July in a fresh Operation Dream Job wave targeting defence, aerospace, aviation, and UAV firms across Europe and India. The attack chain drops the FudModule rootkit and a newly identified modular backdoor named Troy.
Gunra Ransomware: Five-Agency Advisory Flags Fortinet-Backed RaaS Targeting Healthcare and Critical Infrastructure
A joint advisory from CISA, FBI, NSA, US Secret Service, and South Korea's NPA attributes 51+ attacks to Gunra, a Conti-derived ransomware-as-a-service operation exploiting two Fortinet authentication bypass vulnerabilities for initial access.
LoadMaster Under Active Exploitation: CISA Adds CVE-2026-8037 to KEV
A critical unauthenticated command injection flaw in Progress Kemp LoadMaster has been added to CISA's Known Exploited Vulnerabilities catalog after 792 confirmed exploit attempts across 41 days. With over 100,000 deployments — including at the U.S. Air Force and 80% of Fortune 500 companies — unpatched appliances represent significant exposure across finance, healthcare, and communications infrastructure.
N-able N-central Zero-Day: Unauthenticated RMM Takeover Now on CISA KEV
CVE-2026-18577 in N-able N-central gives unauthenticated attackers full administrative access to RMM consoles and every endpoint they manage. CISA has confirmed active exploitation with over half of cloud instances still unpatched.
CrowdStrike Threat Hunting 2026: AI Embedded in Adversary Operations as Exploitation Window Narrows
CrowdStrike's 2026 Threat Hunting Report, published August 3, documents a structural shift in adversarial tradecraft: AI is now a core operational capability for threat actors, China-nexus groups are exploiting critical CVEs within 24 hours of disclosure, and North Korean actors have poisoned 131 AI framework packages in the npm ecosystem.
CaptiveCrunch: Midnight Blizzard Targets Corporate Travellers via Hotel Wi-Fi
Russian threat actor Storm-2945, linked to Midnight Blizzard, has been compromising hotel and conference Wi-Fi captive portals since May 2026 to harvest Microsoft 365 credentials from corporate travellers using custom malware families CornFlake and ChocoShell.
Ransom Cartel Mastermind Sentenced to 16 Years as DOJ Concludes Multi-Year Prosecution
Maksim Silnikau, the Belarusian architect of Ransom Cartel ransomware-as-a-service, received a 16-year federal sentence on August 5 following a campaign that compromised at least 18 organisations across multiple sectors between 2021 and 2023.
Coordinated OT Attack Disrupts 30+ Minnesota Water Utilities in Suspected Iranian PLC Campaign
A coordinated cyberattack on July 26-27 targeted operational technology at more than 30 Minnesota municipal water systems, exploiting internet-facing PLCs to lock out operators and disrupt service. Iranian-linked threat activity is suspected, mirroring CyberAv3ngers tactics.
N-able N-central Authentication Bypass: MSP Infrastructure Under Active Attack
Threat actors are actively exploiting authentication bypass vulnerabilities in N-able N-central, a remote monitoring and management platform used by managed service providers. Post-exploitation involves Cloudflare Tunnel implants for persistent access to downstream client environments.
Threat Actors Exploit N-able N-central to Mass-Pivot Across Managed Endpoints
Unknown threat actors have been exploiting an authentication bypass in N-able N-central since July 31, using the platform's own Take Control feature to deploy persistent Cloudflare tunnels across every endpoint under management.
CyberAv3ngers Attacks 30+ Minnesota Water Systems in Coordinated OT Campaign
Iran-linked CyberAv3ngers hit more than 30 Minnesota municipal water systems on July 26-27, targeting PLCs to lock operators out of treatment controls. One plant went offline. CISA has updated advisory AA26-097A. Intelligence agencies assess Iran as the likely actor, with Handala separately declaring US water infrastructure a priority target.
Dysphoria IoT Botnet Adopts Blockchain C2 After Law Enforcement Disruption
The Dysphoria IoT botnet has re-architected its command-and-control infrastructure using Ethereum and Solana blockchain name services and victim-relay mesh networks, directly responding to the March 2026 JackSkid disruption. Researchers report over 200,000 active bots sustaining near-daily DDoS campaigns against ISPs and communications infrastructure.
Qilin Ransomware Actively Exploiting Palo Alto PAN-OS Authentication Bypass
Qilin affiliates are exploiting CVE-2026-0257, an authentication bypass in Palo Alto GlobalProtect, enabling rapid domain-wide ransomware encryption. Arctic Wolf confirmed multiple intrusions across enterprise sectors in June and July 2026.
PolinRider: North Korea Floods npm, Go and Chrome With 108 Malicious Packages
A North Korean supply chain campaign tracked as PolinRider has distributed 162 malicious release artifacts across 108 packages in npm, Packagist, Go modules, and Chrome extensions, using VS Code auto-run tasks and blockchain-based command-and-control to deliver credential-stealing malware.
CISA Updates Iranian PLC Advisory: Scope Expands to Schneider and Siemens
CISA advisory AA26-097a, updated July 22, now confirms Iranian-affiliated actors are targeting PLCs from Schneider Electric and Siemens alongside Rockwell Automation across US water, energy, and government sectors.
Craneware Breach: Hackers Steal Data from UK Billing Software Firm Serving Thousands of US Hospitals
UK healthcare billing software company Craneware has confirmed attackers exfiltrated a 'significant volume' of data including employee records, customer data, and partner information. Craneware's software is used by thousands of clinics, hospitals, and pharmacies across the United States.
LAUNDRY BEAR: Russia-Linked APT Exploits Zimbra for Zero-Click Email Collection
A joint NCSC and Five Eyes advisory has exposed LAUNDRY BEAR, a Russian state-supported threat actor exploiting a Zimbra Collaboration Suite XSS vulnerability to silently harvest 90 days of email from targeted accounts without any victim interaction.
CISA Expands Iranian PLC Attack Advisory to Schneider Electric and Siemens
CISA updated advisory AA26-097A on July 22 to expand the scope of confirmed Iranian-affiliated OT intrusions beyond Rockwell Automation PLCs to include Schneider Electric and Siemens devices across US critical infrastructure.
JADEPUFFER Returns: Agentic Ransomware Deploys ENCFORGE Against AI Infrastructure
The threat actor behind the first confirmed LLM-driven ransomware campaign has returned with ENCFORGE, a Go-compiled payload built specifically to encrypt AI model weights, vector databases, and training datasets.
CVE-2026-46817: Oracle EBS Payments RCE Under Active Exploitation — CISA KEV
CISA added CVE-2026-46817, a CVSS 9.8 unauthenticated RCE in Oracle E-Business Suite's Payments module, to the Known Exploited Vulnerabilities catalog on July 15, 2026. Exploitation began six weeks after the May patch, and approximately 950 instances remain exposed. Finance and government organisations running Oracle EBS are at immediate risk.
SharePoint Zero-Day CVE-2026-58644 Exploited in Multi-CVE RCE Chain
A critical SharePoint deserialization zero-day (CVSS 9.8) was exploited in the wild before Microsoft's July 14 Patch Tuesday fixed it. CISA added it to the KEV catalog on July 16 alongside three companion CVEs forming an active RCE and persistence chain.
CISA AA26-194A: FSB Center 16 Exploiting Default SNMP Credentials to Exfiltrate Router Configs from Critical Infrastructure
A 19-agency joint advisory from 13 countries details how FSB Center 16 has been harvesting router configurations and credentials from critical infrastructure networks globally by exploiting default SNMP community strings and unpatched Cisco Smart Install deployments.
Fortinet FortiSandbox: Three OS Injection Flaws Under Active Exploitation, CISA Orders Patch by July 19
CISA added three critical OS command injection vulnerabilities in Fortinet FortiSandbox to the KEV catalog on July 16, 2026, citing active exploitation. Federal agencies face a July 19 patch deadline; enterprise defenders running FortiSandbox on-premises, cloud, or PaaS must act immediately.
Five Eyes Alert: Russian FSB Router Campaign Targets Critical Sectors Globally
CISA, NSA, FBI, and 15 international partners have issued a joint advisory warning that Russian FSB Center 16 actors are systematically exploiting poorly configured networking devices across energy, communications, healthcare, and financial services.
Oracle EBS Payments Component Hit with CVSS 9.8 Unauthenticated RCE — CISA Sets 72-Hour Federal Deadline
CVE-2026-46817 is a CVSS 9.8 unauthenticated remote code execution flaw in Oracle E-Business Suite's Payments File Transmission component. CISA added it to the Known Exploited Vulnerabilities catalogue on July 15 with a federal patch deadline of July 18 — 72 hours from disclosure to mandatory remediation.
SonicWall SMA1000 Zero-Days Exploited in Tandem: CISA Sets July 17 Federal Deadline as Four Flaws Hit KEV
Two SonicWall SMA1000 zero-days — an unauthenticated SSRF (CVE-2026-15409, CVSS 10.0) chained with post-auth code injection (CVE-2026-15410, CVSS 7.2) — are confirmed exploited in the wild. CISA added both plus two Microsoft zero-days to the KEV catalogue on July 14 with a July 17 federal patch deadline.
FSB Center 16 Named in Poland Grid Attack as UK and EU Issue First Joint Cyber Sanctions
The UK and EU have formally attributed a December 2025 cyberattack on Poland's energy grid — which came close to causing a blackout for half a million people — to Russia's FSB Center 16, imposing a landmark coordinated sanctions package targeting Moscow's broader cyber ecosystem.
GigaWiper: Iran-Nexus Destructive Backdoor Combines Wiper, Fake Ransomware, and Spyware
Microsoft and Binary Defense have separately documented GigaWiper, a modular Go-based Windows backdoor attributed to an Iran-nexus group that has been targeting Israeli organisations since October 2025. The implant combines irreversible disk wiping, fake ransomware with no recoverable key, and live spyware capabilities in a single deployable payload.
SharePoint RCE CVE-2026-45659 Exploited Despite Microsoft's 'Less Likely' Rating
CISA added CVE-2026-45659 to its KEV catalog on July 1, overriding Microsoft's own 'Exploitation Less Likely' assessment. Any authenticated SharePoint user with Site Member permissions can achieve remote code execution across SharePoint Server 2016, 2019, and Subscription Edition.
Progress Orders ShareFile Storage Zone Controllers Offline Over Active Security Threat
Progress Software has directed all ShareFile Storage Zone Controller customers to take their on-premises file-transfer infrastructure offline following a credible external security threat. No patch exists; shutdown is the only available mitigation.
Three CVSS 10.0 Flaws Hit CISA KEV in 48 Hours: ColdFusion and Joomla Actively Exploited
Adobe ColdFusion and two Joomla-ecosystem components with CVSS 10.0 ratings were added to the CISA Known Exploited Vulnerabilities catalog between July 7 and 9, with a federal patch deadline of July 10. Langflow also added as the first AI agent platform in the catalog.
GhostLock: 15-Year Linux Kernel Flaw Opens Root and Container Escape
A 15-year-old Linux kernel use-after-free vulnerability tracked as CVE-2026-43499 allows any logged-in user to gain root access on unpatched systems. Public exploit code is available and the flaw enables container escape, making patching of cloud, server, and multi-tenant Linux infrastructure an immediate priority.
Januscape (CVE-2026-53359): 16-Year-Old KVM Flaw Allows VM Escape to Host
A critical use-after-free in the Linux KVM shadow MMU lets a guest VM with root privileges escape to the host, threatening multi-tenant cloud and virtualised enterprise environments. A public PoC has been released.
CVE-2026-46242 'Bad Epoll': Linux Kernel LPE Demands Patch Urgency Across Server Fleets
A race-condition use-after-free in the Linux kernel's epoll subsystem gives any unprivileged local user a reliable path to root. A working exploit exists, kernel versions 6.4 and later are affected, and many distributions have not yet shipped the backport.
Armored Likho Deploys BusySnake Stealer Against Government and Power Sector
Russia-linked threat actor Armored Likho has launched a credential theft campaign targeting government agencies and electric power infrastructure across Russia, Kazakhstan, and Brazil. The Python-based BusySnake infostealer extracts browser credentials, Telegram sessions, and crypto wallet keys while operating in-memory to evade disk-based detection.
MuddyWater Deploys Four New Malware Families in Operation Olalampo Targeting MENA Government and Energy
Group-IB tracked MuddyWater's Operation Olalampo campaign from January 2026, uncovering four previously undocumented malware families including CHAR — a Rust backdoor using Telegram for C2 with evidence of AI-assisted development. Targets span government, energy, and telecoms across the MENA region.
FBI and Google Dismantle NetNut: 2 Million-Device Botnet Used by Spy Groups and Ransomware Gangs
A coordinated FBI and Google-led operation has seized hundreds of domains tied to NetNut, a residential proxy network secretly built on 2 million compromised home devices. GTIG observed 316 distinct threat actor clusters using the network in a single June week — spanning state-sponsored espionage groups and ransomware operators.
SharePoint Server RCE Under Active Ransomware Exploitation: CISA Sets July 4 Federal Deadline
CVE-2026-45659, a CVSS 8.8 deserialization remote code execution flaw in on-premises SharePoint Server, is being actively exploited by Storm-2603 ransomware operators. CISA added it to the Known Exploited Vulnerabilities catalogue on July 1 with a federal patch deadline of July 4.
CISA Flags Critical Unauthenticated RCE in StoneFly Storage Appliances
CISA's June 30 ICS advisory batch reveals CVSS 9.8 flaws in StoneFly Storage Concentrator including unauthenticated command injection granting remote root access via TCP port 9000, alongside hardcoded credentials and SQL injection.
SimpleHelp CVSS 10.0 Auth Bypass Exploited: Djinn Stealer Targets Cloud, AI, and Dev Credentials
Attackers are actively exploiting CVE-2026-48558, a perfect-CVSS authentication bypass in SimpleHelp RMM, to deploy a new cross-platform infostealer harvesting cloud platform credentials, AI API keys, developer tokens, and cryptocurrency wallets across Windows, macOS, and Linux.
CVE-2026-55200: Public PoC for Critical libssh2 Flaw Exposes Enterprise Infrastructure
A public proof-of-concept has been released for a CVSS 9.2 client-side flaw in libssh2 that enables zero-authentication remote code execution when connecting to a malicious or compromised SSH server. No official patched release exists yet.
PTC Windchill RCE Exploited: JSP Web Shells Hit Manufacturing PLM
Attackers are deploying persistent JSP web shells via CVE-2026-12569, a critical unauthenticated RCE flaw in PTC Windchill and FlexPLM affecting 1.5 million users across defence, aerospace, and automotive manufacturing.
Handala Breaches California Water Service via Third-Party Pivot, Mandiant Finds No OT Compromise
MOIS-affiliated Handala group accessed Cal Water billing systems via RTKBase pivot, exfiltrating 5GB of customer PII. Mandiant investigation found no OT access — but the claimed capability to disrupt water supply remains unverified propaganda.
CISA KEV: Lantronix EDS5000 and Ubiquiti UniFi Under Active Attack
CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog on June 23, 2026, including a CVSS 9.8 code injection flaw in Lantronix EDS5000 serial device servers widely used in OT environments, and three maximum-severity flaws in Ubiquiti UniFi OS.
Mistic Backdoor: Memory-Resident IAB Tooling Supplies Six Ransomware Groups
A fileless, memory-resident backdoor named Mistic has been identified as the primary initial-access tool for KongTuke — an access broker selling corporate footholds to at least six active ransomware operations including Qilin, Akira, Rhysida, and Black Basta. Active since April 2026, delivered via ClickFix and FileFix social engineering lures.
World Leaks Publishes 630GB of Apple and Tesla Data From Tata Electronics Breach
Data extortion group World Leaks has published more than 630 gigabytes of files allegedly stolen from Tata Electronics, one of the largest manufacturers of iPhone components and assemblies, exposing apparent Apple product schematics, Tesla manufacturing documents, and tens of thousands of employee passport scans.
Squidbleed: 29-Year-Old Squid Proxy Bug Exposes Enterprise Credentials
Researchers disclosed a heap over-read in Squid proxy's FTP parser on June 23, 2026 that can silently leak cleartext HTTP requests, credentials, and session tokens from other users on the same proxy instance. The bug has existed since 1997.
Sapphire Sleet Compromises 144 Mastra AI npm Packages in 88-Minute Operation
North Korean state actor Sapphire Sleet hijacked a contributor account to the Mastra AI framework and injected credential-stealing malware into 144 npm packages in under 90 minutes, targeting LLM API keys, cryptocurrency wallets, and cloud credentials across the AI developer ecosystem.
DragonForce Hides C2 in Microsoft Teams: Backdoor.Turn Evades Detection for Two Months
DragonForce ransomware operators deployed a custom Go-based backdoor that tunnels command-and-control traffic through legitimate Microsoft Teams relay infrastructure, rendering traditional network monitoring ineffective.
Icarus Compromises Klue to Steal CRM Data from Salesforce Customers
A new extortion group called Icarus abused a legacy integration credential to steal OAuth tokens from Klue's integration infrastructure, enabling automated bulk extraction of Salesforce CRM data from dozens of enterprise customers — with Huntress among those confirming impact as of June 19, 2026.
FortiBleed: 73,932 FortiGate Credentials from CVE-2022-40684 Surface Four Years After Exploitation
A dataset of valid VPN credentials harvested from 73,932 FortiGate devices during CVE-2022-40684 exploitation was published on 17 June 2026. The four-year gap between collection and release illustrates a documented threat actor pattern — credential harvesting during a mass exploitation window, then monetising the dataset years later when many organisations have forgotten to rotate.
CVE-2026-20253: Splunk Enterprise RCE Added to CISA KEV — SOCs at Risk
CISA added CVE-2026-20253, an unauthenticated RCE in Splunk Enterprise's PostgreSQL sidecar service, to the Known Exploited Vulnerabilities catalog on June 18, 2026. Federal remediation deadline is June 21. Splunk deployments at SOCs, financial institutions, healthcare, and government are at elevated risk.
UNC6508: China-Linked Group Mined Medical and Military Research for Two Years
Google Threat Intelligence has disclosed a PRC-nexus espionage campaign that breached North American clinical, academic, and military health institutions via REDCap research servers, remaining undetected from September 2023 through November 2025.
Handala Claims Breach of California Water Service, Exposing Customer Data and GNSS Credentials
Iran-linked Handala group claims 5GB exfiltration from California Water Service including customer records and RTKBase GNSS platform credentials across seven districts. Investigation ongoing; no OT disruption confirmed but destructive escalation risk is real.
NCSC Warning: Citrix NetScaler ADC and Gateway Critical Vulnerabilities Under Active Exploitation
NCSC has issued an urgent advisory on two vulnerabilities in Citrix NetScaler ADC and Gateway — CVE-2026-3055 (CVSS 9.3, unauthenticated memory exfiltration) and CVE-2026-4368 — urging UK organisations to patch immediately. Both flaws affect versions widely deployed across enterprise, healthcare, and finance environments.
Velvet Ant's Operation Highland: China-Nexus APT Backdoored Linux Auth Stack for Nearly a Decade
Sygnia's disclosure of Operation Highland reveals a China-linked threat actor that modified PAM and OpenSSH components to maintain persistent, credential-harvesting access inside isolated networks from 2016 to at least 2026.
ShinyHunters Weaponised Oracle PeopleSoft Zero-Day Against 100+ Universities and Enterprises: CVE-2026-35273
ShinyHunters (UNC6240) exploited a CVSS 9.8 unauthenticated RCE in Oracle PeopleSoft as a zero-day for two weeks before any patch existed, breaching more than 100 organisations — 68% of them universities. CISA added CVE-2026-35273 to its KEV catalog on 12 June 2026.
Europol and FBI Dismantle AudiA6: The €336 Million Ransomware Laundering Pipeline
International law enforcement dismantled AudiA6, a cryptocurrency laundering service that processed €336 million in ransomware proceeds since 2021, arresting two administrators and seizing 25 domains and 30 servers in a coordinated operation on 10 June 2026.
Ivanti Sentry MDM Gateways Backdoored Within 48 Hours of Patch: CVSS 10.0 Pre-Auth RCE
A CVSS 10.0 pre-authentication OS command injection in Ivanti Sentry allows unauthenticated root-level code execution on MDM gateway appliances. Production instances were backdoored within 48 hours of the advisory. CISA has set a 14 June 2026 remediation deadline.
RoguePlanet: Seventh Zero-Day Dropped Hours After Patch Tuesday, Targets Microsoft Defender on Fully Patched Windows
The researcher behind the Nightmare-Eclipse exploit series has released a seventh zero-day — RoguePlanet — exploiting a race condition in Microsoft Defender to deliver SYSTEM privileges on fully patched Windows 10 and 11, hours after June Patch Tuesday closed the previous six.
CVE-2026-44963: Critical Veeam Backup RCE Gives Any Domain User a Path to Ransomware's Favourite Target
A CVSS 9.4 remote code execution flaw in Veeam Backup & Replication v12 lets any authenticated domain user execute arbitrary code on backup servers — recreating the low-barrier attack surface that ransomware groups have repeatedly weaponised in prior Veeam vulnerabilities.
Qilin Ransomware Affiliate Exploiting Authentication Bypasses Across Four VPN Platforms in Coordinated Campaign
A Qilin ransomware affiliate is systematically exploiting authentication bypass vulnerabilities across Check Point, Palo Alto Networks, Fortinet, and F5 VPN infrastructure simultaneously — with a month-long zero-day window on the Check Point flaw before any patch existed.
ShinyHunters Publishes 234 GB of DentaQuest Healthcare Data After Ransom Talks Fail
The ShinyHunters extortion group has published 234 GB of data stolen from DentaQuest, a dental benefits administrator serving 32 million Americans. The leaked dataset includes healthcare enrollment records, Medicaid IDs, and personal information for an estimated 2.6 million individuals.
Miasma Worm Hits 73 Microsoft GitHub Repositories, Including Core Azure SDKs
The Miasma supply chain worm -- a variant of the Mini Shai-Hulud campaign -- has compromised 73 repositories across Microsoft's GitHub organisations today, including Azure Functions, Durable Task, and several developer tooling packages. GitHub has disabled access to affected repos; credentials from the May compromise appear not to have been fully rotated.
CVE-2026-41089: Critical Windows Netlogon RCE Now Actively Exploited — Every Unpatched Domain Controller at Risk
Active exploitation of CVE-2026-41089, a pre-authentication zero-click RCE in Windows Netlogon, was confirmed by Belgium's Centre for Cybersecurity on 29 May. Successful exploitation gives an attacker SYSTEM-level control of the domain controller and full ownership of the Active Directory domain.
TA4922 Extends High-Tempo Campaign Operations to UK and Europe With Atlas RAT and Credential Stealer
Proofpoint has published intelligence on TA4922's geographic expansion into the UK, Germany, Italy, and South Africa — deploying two new malware families via tax-themed and HR-themed phishing. The group holds the highest campaign pace of any Proofpoint-tracked threat actor.
Screening Serpens Expands Arsenal With Six New RAT Variants in Aerospace, Defence, and Telecom Espionage Campaign
Palo Alto Networks Unit 42 has published new research detailing how Iran-nexus APT Screening Serpens deployed six previously undocumented RAT variants against US, Israeli, and UAE targets in aerospace, defence manufacturing, and telecommunications between February and April 2026.
Android Zero-Day Exploitation Confirmed: June 2026 Bulletin Signals Commercial Spyware Activity
Google's June 2026 Android Security Bulletin confirms active exploitation of CVE-2025-48595, a local privilege escalation requiring no user interaction. CISA's simultaneous KEV addition with a three-day federal deadline points to targeted commercial surveillance tool deployment against high-value individuals.
Operation Dragon Weave: China-Linked APT Abuses Azure Blob Storage as C2 to Target European Governments and Finance
Seqrite researchers have attributed a targeted espionage campaign against government, financial, and research organisations in the Czech Republic and Taiwan to a China-aligned threat actor using Azure Blob Storage as a covert C2 channel.
CVE-2026-0257: PAN-OS GlobalProtect Authentication Bypass Under Active Exploitation — CISA Deadline Today
A medium-severity authentication bypass in Palo Alto Networks PAN-OS GlobalProtect is being actively exploited across enterprise networks, with CISA's KEV remediation deadline falling on 1 June 2026.
FortiClient EMS Active Exploitation: Threat Actors Deploying EKZ Infostealer Via Fake Fortinet Patch
Fresh exploitation of CVE-2026-35616, a critical pre-authentication bypass in Fortinet's FortiClient Endpoint Management Server, is ongoing in May 2026. Threat actors are delivering the EKZ credential-stealing malware disguised as a legitimate Fortinet software update, prompting an NHS England Digital alert.
ShinyHunters Publishes Charter Communications Customer Data After Vishing Compromise
ShinyHunters extortion group has published data from Charter Communications after a vishing attack compromised a Microsoft Entra account and enabled access to Charter's Salesforce environment. At least 4.9 million customer records confirmed; the group claims 42 million.
Silent Ransom Group Goes Physical: FBI Flash Alert as Gang Walks Operatives Into Law Firm Offices
A Russia-linked extortion group has escalated from phishing and vishing to physically dispatching operatives into victim premises -- the FBI issued a FLASH alert on 26 May after confirming the tactic across more than 38 law firm victims.
TeamPCP's Mini Shai-Hulud: The Developer Supply Chain Worm That Hit GitHub, OpenAI, and Mistral -- Then Went Public
The Mini Shai-Hulud npm worm has expanded well beyond the initial TanStack compromise to breach GitHub's internal infrastructure, compromise devices at OpenAI and Mistral AI, and poison 600+ packages across 16 million weekly downloads -- before its authors open-sourced it on BreachForums.
Dutch Authorities Seize 800 Servers Tied to Russian Cyber-Attack Infrastructure
Dutch financial crime investigators arrested two suspects and seized 800 servers connected to Stark Industries, a hosting network linked to NoName057(16) DDoS campaigns against European governments and critical infrastructure.
Nightmare-Eclipse: Six Windows Zero-Days Released in Six Weeks, Three Now Weaponised in Live Attacks
A rogue researcher has published six working Windows exploit drops since April 2026. Three are confirmed active in attacks linked to Russian infrastructure, with more exploits -- including RCE -- threatened for June Patch Tuesday.
Nimbus Manticore Resurfaces with New Backdoor and Expanded European Targeting After Operation Epic Fury
Iranian IRGC-affiliated APT Nimbus Manticore has resumed aggressive campaigns against aviation, telecommunications, and critical infrastructure in Europe and the US, deploying an undocumented AI-assisted backdoor and adopting new delivery techniques since the outbreak of the US-Iran conflict.
CISA Confirms Active Exploitation: Apex One Endpoint Platform Turned Against Defenders, Langflow Linked to Iranian APT
CISA's May 21 KEV additions confirm active exploitation of Trend Micro Apex One's directory traversal flaw -- which allows attackers to push malicious code through the defender's own endpoint management -- alongside a Langflow AI workflow vulnerability tied to MuddyWater intrusions.
PHP Supply Chain Compromise: Laravel-Lang Packages Weaponised to Harvest Cloud Credentials Across Enterprise CI/CD Pipelines
An attacker who obtained push access to the Laravel-Lang GitHub organisation rewrote over 230 package versions in under 90 minutes on 22–23 May, injecting a sophisticated cloud credential stealer into one of PHP's most widely used localisation library sets.
Iranian APT MuddyWater Deploys Chaos Ransomware as False Flag to Mask Espionage
Rapid7 researchers have attributed a series of intrusions using Chaos ransomware branding to MuddyWater -- an Iranian state-sponsored group -- in a deliberate false flag operation designed to obscure intelligence collection behind the appearance of criminal extortion.
APT10 Renews MSP Targeting in UK and Europe -- Cloud Hopper Techniques Persist
China's APT10 has resumed systematic targeting of UK managed service providers and professional services firms, using the same supply chain pivot techniques that characterised the Cloud Hopper campaign -- now adapted for cloud-managed tenants.
APT28 Intensifies Targeting of European Government Networks Ahead of 2026 Election Cycle
Russia's GRU-linked APT28 has escalated spear-phishing and credential-harvesting operations against European government ministries, NATO-adjacent bodies, and political parties in the run-up to elections across the continent.
APT29 Exploiting Trusted Vendor Relationships to Reach UK and European Government Networks
Russia's SVR-linked APT29 is using compromised software vendor and IT service provider accounts to pivot into government targets -- a continuation of the SolarWinds playbook applied to UK and European supply chains.
Critical Unpatched RCE in Siemens RUGGEDCOM and ScadaBR -- No Fix Available for Either
CISA's May 19 ICS advisories flag unauthenticated root-level code execution in Siemens RUGGEDCOM APE1808 and ScadaBR SCADA software. Neither has a patch. The ScadaBR vendor has not responded to CISA.
Lazarus Group Extends Cryptocurrency Targeting to UK Exchanges and Law Firm Custodians
North Korea's Lazarus Group has extended its cryptocurrency theft operations to UK-regulated digital asset exchanges and the law firms that provide custody and compliance services to crypto clients -- combining financial theft with intelligence collection.
LockBit Resurgence: Affiliate Network Active Across UK Healthcare and Professional Services
Despite Operation Cronos and the February 2024 infrastructure seizure, LockBit-affiliated actors continue to operate under the LockBit 3.0 and successor infrastructure. UK healthcare and professional services organisations have been among the most recent confirmed victims.
NCSC Warns: Volt Typhoon Reconnaissance Extends to Tier 2 UK Government Suppliers
Intelligence confirms Volt Typhoon pre-positioning activity has moved beyond primary CNI operators into the Tier 2 supplier networks that service UK central government and defence. Smaller suppliers with privileged access to government systems are now directly in scope.
RansomHub Affiliates Targeting UK Law Firms During Active M&A Mandates
Multiple UK and European law firms have been hit by RansomHub-affiliated actors during live M&A transactions. The timing is deliberate: attackers maximise leverage by striking when client pressure to resolve the incident is highest.
Volt Typhoon Activity Confirmed Across UK Water and Energy OT Networks
NCSC and Five Eyes partners have confirmed Volt Typhoon intrusions at operational technology networks in UK water treatment and regional energy distribution. The group is not causing disruption -- it is waiting.
NHS Trusts Targeted in Coordinated Ransomware Wave as RaaS Affiliates Shift Focus
A cluster of ransomware affiliates, several previously linked to ALPHV/BlackCat, has targeted three NHS trusts in the past six weeks. Attackers are exploiting legacy VPN appliances and unpatched remote access infrastructure.
First Confirmed AI-Built Zero-Day: Google Thwarts Mass Exploitation Campaign
A threat actor used a large language model to write a working 2FA bypass exploit for a widely deployed open-source admin tool. Google's threat intelligence team detected the planned mass exploitation campaign before it launched. The code left distinctive LLM fingerprints.
FIN7 Pivots to Financial Services with New Phishing Infrastructure and Loader Malware
The FIN7 group has refreshed its phishing infrastructure and is deploying a new loader variant against mid-tier UK and European financial institutions. Targets include wealth managers, brokers, and payment processors.
Salt Typhoon Access Persists in European Telecoms More Than a Year After Initial Disclosure
Fourteen months after the US disclosed Salt Typhoon's compromise of major American carriers, intelligence assessments confirm the same group retains access inside at least two major European telecommunications networks.
Cl0p Exploiting File Transfer Vulnerabilities Across Transport and Logistics Sector
The Cl0p ransomware group is mass-exploiting a newly disclosed vulnerability in a widely used managed file transfer platform. Several European freight and logistics operators have been impacted, with customs and supply chain data exfiltrated.
No briefings match this sector filter.