Skip to content

Flash Briefings

critical

Critical Gitea RCE Added to CISA KEV After Active Exploitation Deploys Miner Payloads

CISA added CVE-2026-60004, a critical unauthenticated-to-authenticated remote code execution flaw in self-hosted Gitea instances, to its Known Exploited Vulnerabilities catalog on August 25 after attackers were observed using it to drop cryptomining-style payloads.

critical

CVE-2026-21962: Max-Severity Oracle WebLogic Proxy Flaw Under Active Exploitation — CISA Sets 3-Day Deadline

CISA added CVE-2026-21962, a CVSS 10.0 unauthenticated bypass in the Oracle WebLogic Server Proxy Plug-in and Oracle HTTP Server, to its Known Exploited Vulnerabilities catalog on August 24, 2026 — issuing its tightest-ever three-day federal patching deadline. Attackers are chaining path traversal and header manipulation to reach backend WebLogic instances directly.

critical

Critical GitLab Flaw Under Active Exploitation Two Days After Disclosure

An unauthenticated, CVSS 9.4 GraphQL code-injection vulnerability in self-managed GitLab (CVE-2026-19478) is being actively exploited to delete or rewrite public repositories, with watchTowr confirming attacks within days of the emergency patch.

critical

Microsoft Discloses Maximum-Severity CVSS 10.0 Entra ID Remote Code Execution Flaw

CVE-2026-69836, a deserialization bug in Microsoft's cloud identity platform, carried a perfect CVSS score — but Microsoft says it was never exploited and has already been fixed on its side, with no customer action required.

high

Heights Finance Discloses Breach Exposing 1.2 Million Customers' SSNs and Bank Details

A US consumer lender has disclosed that hackers accessed a third-party cloud platform storing customer records, exposing Social Security numbers, bank account details, and government ID data for more than 1.2 million people.

critical

CISA Adds SharePoint JWT Auth Bypass CVE-2026-55040 to KEV Catalog Amid Active Exploitation

A critical authentication bypass in on-premises SharePoint Server is being actively exploited days after a public proof-of-concept, letting unauthenticated attackers impersonate any user, including administrators.

high Cavern Manticore / APT42

Cavern C2 Evolves: Iranian MOIS Group Adds Google Apps Script and M365 Calendar Channels

Kaspersky and Group-IB analysis reveals Iranian MOIS-linked Cavern Manticore has extended its C2 framework with DNS-directed Google Apps Script relays and a new HOLLOWGRAPH module abusing Microsoft 365 calendar events — while APT42 separately targets the nuclear energy sector with AI-accelerated TAMECAT implants.

high Gunra

Gunra Ransomware Actors Hit Healthcare, Finance, and Critical Infrastructure Across Five Continents

CISA, the FBI, NSA, and South Korean authorities have issued a joint advisory on Gunra, a Conti-derived ransomware-as-a-service operation that has compromised organisations across healthcare, financial services, manufacturing, transportation, and government sectors globally.

high Clop

Clop Claims Shell Data Exfiltration: 89GB of Energy Sector Data at Risk

Clop has claimed responsibility for stealing 89GB of data from Shell, with the energy major now investigating a 'potential incident'. The claim follows Clop's established pattern of mass data theft through file transfer platform vulnerabilities, with the group's latest campaign affecting multiple sectors simultaneously.

critical

CVE-2026-59310: VMware vCenter Exploited Globally Five Days After Disclosure

A critical directory-traversal vulnerability in VMware vCenter was patched July 29 and exploited within five days -- an APT actor has compromised 361 servers across 47 countries, deploying reverse shell infrastructure via a malicious cron job.

critical Gunra

Gunra Ransomware: Five-Agency Advisory Flags Fortinet-Backed RaaS Targeting Healthcare and Critical Infrastructure

A joint advisory from CISA, FBI, NSA, US Secret Service, and South Korea's NPA attributes 51+ attacks to Gunra, a Conti-derived ransomware-as-a-service operation exploiting two Fortinet authentication bypass vulnerabilities for initial access.

critical

LoadMaster Under Active Exploitation: CISA Adds CVE-2026-8037 to KEV

A critical unauthenticated command injection flaw in Progress Kemp LoadMaster has been added to CISA's Known Exploited Vulnerabilities catalog after 792 confirmed exploit attempts across 41 days. With over 100,000 deployments — including at the U.S. Air Force and 80% of Fortune 500 companies — unpatched appliances represent significant exposure across finance, healthcare, and communications infrastructure.

critical

N-able N-central Zero-Day: Unauthenticated RMM Takeover Now on CISA KEV

CVE-2026-18577 in N-able N-central gives unauthenticated attackers full administrative access to RMM consoles and every endpoint they manage. CISA has confirmed active exploitation with over half of cloud instances still unpatched.

high

CrowdStrike Threat Hunting 2026: AI Embedded in Adversary Operations as Exploitation Window Narrows

CrowdStrike's 2026 Threat Hunting Report, published August 3, documents a structural shift in adversarial tradecraft: AI is now a core operational capability for threat actors, China-nexus groups are exploiting critical CVEs within 24 hours of disclosure, and North Korean actors have poisoned 131 AI framework packages in the npm ecosystem.

high Midnight Blizzard (Storm-2945)

CaptiveCrunch: Midnight Blizzard Targets Corporate Travellers via Hotel Wi-Fi

Russian threat actor Storm-2945, linked to Midnight Blizzard, has been compromising hotel and conference Wi-Fi captive portals since May 2026 to harvest Microsoft 365 credentials from corporate travellers using custom malware families CornFlake and ChocoShell.

Ransom Cartel Mastermind Sentenced to 16 Years as DOJ Concludes Multi-Year Prosecution

Maksim Silnikau, the Belarusian architect of Ransom Cartel ransomware-as-a-service, received a 16-year federal sentence on August 5 following a campaign that compromised at least 18 organisations across multiple sectors between 2021 and 2023.

high

N-able N-central Authentication Bypass: MSP Infrastructure Under Active Attack

Threat actors are actively exploiting authentication bypass vulnerabilities in N-able N-central, a remote monitoring and management platform used by managed service providers. Post-exploitation involves Cloudflare Tunnel implants for persistent access to downstream client environments.

high

Threat Actors Exploit N-able N-central to Mass-Pivot Across Managed Endpoints

Unknown threat actors have been exploiting an authentication bypass in N-able N-central since July 31, using the platform's own Take Control feature to deploy persistent Cloudflare tunnels across every endpoint under management.

critical Qilin

Qilin Ransomware Actively Exploiting Palo Alto PAN-OS Authentication Bypass

Qilin affiliates are exploiting CVE-2026-0257, an authentication bypass in Palo Alto GlobalProtect, enabling rapid domain-wide ransomware encryption. Arctic Wolf confirmed multiple intrusions across enterprise sectors in June and July 2026.

high Contagious Interview / Famous Chollima (North Korea)

PolinRider: North Korea Floods npm, Go and Chrome With 108 Malicious Packages

A North Korean supply chain campaign tracked as PolinRider has distributed 162 malicious release artifacts across 108 packages in npm, Packagist, Go modules, and Chrome extensions, using VS Code auto-run tasks and blockchain-based command-and-control to deliver credential-stealing malware.

critical JADEPUFFER

JADEPUFFER Returns: Agentic Ransomware Deploys ENCFORGE Against AI Infrastructure

The threat actor behind the first confirmed LLM-driven ransomware campaign has returned with ENCFORGE, a Go-compiled payload built specifically to encrypt AI model weights, vector databases, and training datasets.

critical DriveSurge

CVE-2026-46817: Oracle EBS Payments RCE Under Active Exploitation — CISA KEV

CISA added CVE-2026-46817, a CVSS 9.8 unauthenticated RCE in Oracle E-Business Suite's Payments module, to the Known Exploited Vulnerabilities catalog on July 15, 2026. Exploitation began six weeks after the May patch, and approximately 950 instances remain exposed. Finance and government organisations running Oracle EBS are at immediate risk.

critical

SharePoint Zero-Day CVE-2026-58644 Exploited in Multi-CVE RCE Chain

A critical SharePoint deserialization zero-day (CVSS 9.8) was exploited in the wild before Microsoft's July 14 Patch Tuesday fixed it. CISA added it to the KEV catalog on July 16 alongside three companion CVEs forming an active RCE and persistence chain.

high FSB Center 16

CISA AA26-194A: FSB Center 16 Exploiting Default SNMP Credentials to Exfiltrate Router Configs from Critical Infrastructure

A 19-agency joint advisory from 13 countries details how FSB Center 16 has been harvesting router configurations and credentials from critical infrastructure networks globally by exploiting default SNMP community strings and unpatched Cisco Smart Install deployments.

critical

Fortinet FortiSandbox: Three OS Injection Flaws Under Active Exploitation, CISA Orders Patch by July 19

CISA added three critical OS command injection vulnerabilities in Fortinet FortiSandbox to the KEV catalog on July 16, 2026, citing active exploitation. Federal agencies face a July 19 patch deadline; enterprise defenders running FortiSandbox on-premises, cloud, or PaaS must act immediately.

high FSB Center 16

Five Eyes Alert: Russian FSB Router Campaign Targets Critical Sectors Globally

CISA, NSA, FBI, and 15 international partners have issued a joint advisory warning that Russian FSB Center 16 actors are systematically exploiting poorly configured networking devices across energy, communications, healthcare, and financial services.

critical

Oracle EBS Payments Component Hit with CVSS 9.8 Unauthenticated RCE — CISA Sets 72-Hour Federal Deadline

CVE-2026-46817 is a CVSS 9.8 unauthenticated remote code execution flaw in Oracle E-Business Suite's Payments File Transmission component. CISA added it to the Known Exploited Vulnerabilities catalogue on July 15 with a federal patch deadline of July 18 — 72 hours from disclosure to mandatory remediation.

critical

SonicWall SMA1000 Zero-Days Exploited in Tandem: CISA Sets July 17 Federal Deadline as Four Flaws Hit KEV

Two SonicWall SMA1000 zero-days — an unauthenticated SSRF (CVE-2026-15409, CVSS 10.0) chained with post-auth code injection (CVE-2026-15410, CVSS 7.2) — are confirmed exploited in the wild. CISA added both plus two Microsoft zero-days to the KEV catalogue on July 14 with a July 17 federal patch deadline.

high

SharePoint RCE CVE-2026-45659 Exploited Despite Microsoft's 'Less Likely' Rating

CISA added CVE-2026-45659 to its KEV catalog on July 1, overriding Microsoft's own 'Exploitation Less Likely' assessment. Any authenticated SharePoint user with Site Member permissions can achieve remote code execution across SharePoint Server 2016, 2019, and Subscription Edition.

high

Progress Orders ShareFile Storage Zone Controllers Offline Over Active Security Threat

Progress Software has directed all ShareFile Storage Zone Controller customers to take their on-premises file-transfer infrastructure offline following a credible external security threat. No patch exists; shutdown is the only available mitigation.

critical

Three CVSS 10.0 Flaws Hit CISA KEV in 48 Hours: ColdFusion and Joomla Actively Exploited

Adobe ColdFusion and two Joomla-ecosystem components with CVSS 10.0 ratings were added to the CISA Known Exploited Vulnerabilities catalog between July 7 and 9, with a federal patch deadline of July 10. Langflow also added as the first AI agent platform in the catalog.

high

GhostLock: 15-Year Linux Kernel Flaw Opens Root and Container Escape

A 15-year-old Linux kernel use-after-free vulnerability tracked as CVE-2026-43499 allows any logged-in user to gain root access on unpatched systems. Public exploit code is available and the flaw enables container escape, making patching of cloud, server, and multi-tenant Linux infrastructure an immediate priority.

critical

Januscape (CVE-2026-53359): 16-Year-Old KVM Flaw Allows VM Escape to Host

A critical use-after-free in the Linux KVM shadow MMU lets a guest VM with root privileges escape to the host, threatening multi-tenant cloud and virtualised enterprise environments. A public PoC has been released.

high

CVE-2026-46242 'Bad Epoll': Linux Kernel LPE Demands Patch Urgency Across Server Fleets

A race-condition use-after-free in the Linux kernel's epoll subsystem gives any unprivileged local user a reliable path to root. A working exploit exists, kernel versions 6.4 and later are affected, and many distributions have not yet shipped the backport.

high

FBI and Google Dismantle NetNut: 2 Million-Device Botnet Used by Spy Groups and Ransomware Gangs

A coordinated FBI and Google-led operation has seized hundreds of domains tied to NetNut, a residential proxy network secretly built on 2 million compromised home devices. GTIG observed 316 distinct threat actor clusters using the network in a single June week — spanning state-sponsored espionage groups and ransomware operators.

high Storm-2603

SharePoint Server RCE Under Active Ransomware Exploitation: CISA Sets July 4 Federal Deadline

CVE-2026-45659, a CVSS 8.8 deserialization remote code execution flaw in on-premises SharePoint Server, is being actively exploited by Storm-2603 ransomware operators. CISA added it to the Known Exploited Vulnerabilities catalogue on July 1 with a federal patch deadline of July 4.

critical

SimpleHelp CVSS 10.0 Auth Bypass Exploited: Djinn Stealer Targets Cloud, AI, and Dev Credentials

Attackers are actively exploiting CVE-2026-48558, a perfect-CVSS authentication bypass in SimpleHelp RMM, to deploy a new cross-platform infostealer harvesting cloud platform credentials, AI API keys, developer tokens, and cryptocurrency wallets across Windows, macOS, and Linux.

critical

CVE-2026-55200: Public PoC for Critical libssh2 Flaw Exposes Enterprise Infrastructure

A public proof-of-concept has been released for a CVSS 9.2 client-side flaw in libssh2 that enables zero-authentication remote code execution when connecting to a malicious or compromised SSH server. No official patched release exists yet.

high KongTuke

Mistic Backdoor: Memory-Resident IAB Tooling Supplies Six Ransomware Groups

A fileless, memory-resident backdoor named Mistic has been identified as the primary initial-access tool for KongTuke — an access broker selling corporate footholds to at least six active ransomware operations including Qilin, Akira, Rhysida, and Black Basta. Active since April 2026, delivered via ClickFix and FileFix social engineering lures.

high

Squidbleed: 29-Year-Old Squid Proxy Bug Exposes Enterprise Credentials

Researchers disclosed a heap over-read in Squid proxy's FTP parser on June 23, 2026 that can silently leak cleartext HTTP requests, credentials, and session tokens from other users on the same proxy instance. The bug has existed since 1997.

high Sapphire Sleet (BlueNoroff)

Sapphire Sleet Compromises 144 Mastra AI npm Packages in 88-Minute Operation

North Korean state actor Sapphire Sleet hijacked a contributor account to the Mastra AI framework and injected credential-stealing malware into 144 npm packages in under 90 minutes, targeting LLM API keys, cryptocurrency wallets, and cloud credentials across the AI developer ecosystem.

high DragonForce (Hackledorb)

DragonForce Hides C2 in Microsoft Teams: Backdoor.Turn Evades Detection for Two Months

DragonForce ransomware operators deployed a custom Go-based backdoor that tunnels command-and-control traffic through legitimate Microsoft Teams relay infrastructure, rendering traditional network monitoring ineffective.

high Icarus

Icarus Compromises Klue to Steal CRM Data from Salesforce Customers

A new extortion group called Icarus abused a legacy integration credential to steal OAuth tokens from Klue's integration infrastructure, enabling automated bulk extraction of Salesforce CRM data from dozens of enterprise customers — with Huntress among those confirming impact as of June 19, 2026.

high

FortiBleed: 73,932 FortiGate Credentials from CVE-2022-40684 Surface Four Years After Exploitation

A dataset of valid VPN credentials harvested from 73,932 FortiGate devices during CVE-2022-40684 exploitation was published on 17 June 2026. The four-year gap between collection and release illustrates a documented threat actor pattern — credential harvesting during a mass exploitation window, then monetising the dataset years later when many organisations have forgotten to rotate.

critical

CVE-2026-20253: Splunk Enterprise RCE Added to CISA KEV — SOCs at Risk

CISA added CVE-2026-20253, an unauthenticated RCE in Splunk Enterprise's PostgreSQL sidecar service, to the Known Exploited Vulnerabilities catalog on June 18, 2026. Federal remediation deadline is June 21. Splunk deployments at SOCs, financial institutions, healthcare, and government are at elevated risk.

critical

NCSC Warning: Citrix NetScaler ADC and Gateway Critical Vulnerabilities Under Active Exploitation

NCSC has issued an urgent advisory on two vulnerabilities in Citrix NetScaler ADC and Gateway — CVE-2026-3055 (CVSS 9.3, unauthenticated memory exfiltration) and CVE-2026-4368 — urging UK organisations to patch immediately. Both flaws affect versions widely deployed across enterprise, healthcare, and finance environments.

critical Velvet Ant

Velvet Ant's Operation Highland: China-Nexus APT Backdoored Linux Auth Stack for Nearly a Decade

Sygnia's disclosure of Operation Highland reveals a China-linked threat actor that modified PAM and OpenSSH components to maintain persistent, credential-harvesting access inside isolated networks from 2016 to at least 2026.

critical ShinyHunters

ShinyHunters Weaponised Oracle PeopleSoft Zero-Day Against 100+ Universities and Enterprises: CVE-2026-35273

ShinyHunters (UNC6240) exploited a CVSS 9.8 unauthenticated RCE in Oracle PeopleSoft as a zero-day for two weeks before any patch existed, breaching more than 100 organisations — 68% of them universities. CISA added CVE-2026-35273 to its KEV catalog on 12 June 2026.

medium

Europol and FBI Dismantle AudiA6: The €336 Million Ransomware Laundering Pipeline

International law enforcement dismantled AudiA6, a cryptocurrency laundering service that processed €336 million in ransomware proceeds since 2021, arresting two administrators and seizing 25 domains and 30 servers in a coordinated operation on 10 June 2026.

critical

Ivanti Sentry MDM Gateways Backdoored Within 48 Hours of Patch: CVSS 10.0 Pre-Auth RCE

A CVSS 10.0 pre-authentication OS command injection in Ivanti Sentry allows unauthenticated root-level code execution on MDM gateway appliances. Production instances were backdoored within 48 hours of the advisory. CISA has set a 14 June 2026 remediation deadline.

critical

RoguePlanet: Seventh Zero-Day Dropped Hours After Patch Tuesday, Targets Microsoft Defender on Fully Patched Windows

The researcher behind the Nightmare-Eclipse exploit series has released a seventh zero-day — RoguePlanet — exploiting a race condition in Microsoft Defender to deliver SYSTEM privileges on fully patched Windows 10 and 11, hours after June Patch Tuesday closed the previous six.

critical

CVE-2026-44963: Critical Veeam Backup RCE Gives Any Domain User a Path to Ransomware's Favourite Target

A CVSS 9.4 remote code execution flaw in Veeam Backup & Replication v12 lets any authenticated domain user execute arbitrary code on backup servers — recreating the low-barrier attack surface that ransomware groups have repeatedly weaponised in prior Veeam vulnerabilities.

critical Qilin

Qilin Ransomware Affiliate Exploiting Authentication Bypasses Across Four VPN Platforms in Coordinated Campaign

A Qilin ransomware affiliate is systematically exploiting authentication bypass vulnerabilities across Check Point, Palo Alto Networks, Fortinet, and F5 VPN infrastructure simultaneously — with a month-long zero-day window on the Check Point flaw before any patch existed.

critical TeamPCP (Miasma variant)

Miasma Worm Hits 73 Microsoft GitHub Repositories, Including Core Azure SDKs

The Miasma supply chain worm -- a variant of the Mini Shai-Hulud campaign -- has compromised 73 repositories across Microsoft's GitHub organisations today, including Azure Functions, Durable Task, and several developer tooling packages. GitHub has disabled access to affected repos; credentials from the May compromise appear not to have been fully rotated.

critical

CVE-2026-41089: Critical Windows Netlogon RCE Now Actively Exploited — Every Unpatched Domain Controller at Risk

Active exploitation of CVE-2026-41089, a pre-authentication zero-click RCE in Windows Netlogon, was confirmed by Belgium's Centre for Cybersecurity on 29 May. Successful exploitation gives an attacker SYSTEM-level control of the domain controller and full ownership of the Active Directory domain.

high TA4922

TA4922 Extends High-Tempo Campaign Operations to UK and Europe With Atlas RAT and Credential Stealer

Proofpoint has published intelligence on TA4922's geographic expansion into the UK, Germany, Italy, and South Africa — deploying two new malware families via tax-themed and HR-themed phishing. The group holds the highest campaign pace of any Proofpoint-tracked threat actor.

high

Android Zero-Day Exploitation Confirmed: June 2026 Bulletin Signals Commercial Spyware Activity

Google's June 2026 Android Security Bulletin confirms active exploitation of CVE-2025-48595, a local privilege escalation requiring no user interaction. CISA's simultaneous KEV addition with a three-day federal deadline points to targeted commercial surveillance tool deployment against high-value individuals.

high China-aligned (unattributed)

Operation Dragon Weave: China-Linked APT Abuses Azure Blob Storage as C2 to Target European Governments and Finance

Seqrite researchers have attributed a targeted espionage campaign against government, financial, and research organisations in the Czech Republic and Taiwan to a China-aligned threat actor using Azure Blob Storage as a covert C2 channel.

high

CVE-2026-0257: PAN-OS GlobalProtect Authentication Bypass Under Active Exploitation — CISA Deadline Today

A medium-severity authentication bypass in Palo Alto Networks PAN-OS GlobalProtect is being actively exploited across enterprise networks, with CISA's KEV remediation deadline falling on 1 June 2026.

critical

FortiClient EMS Active Exploitation: Threat Actors Deploying EKZ Infostealer Via Fake Fortinet Patch

Fresh exploitation of CVE-2026-35616, a critical pre-authentication bypass in Fortinet's FortiClient Endpoint Management Server, is ongoing in May 2026. Threat actors are delivering the EKZ credential-stealing malware disguised as a legitimate Fortinet software update, prompting an NHS England Digital alert.

high Silent Ransom Group

Silent Ransom Group Goes Physical: FBI Flash Alert as Gang Walks Operatives Into Law Firm Offices

A Russia-linked extortion group has escalated from phishing and vishing to physically dispatching operatives into victim premises -- the FBI issued a FLASH alert on 26 May after confirming the tactic across more than 38 law firm victims.

critical TeamPCP (UNC6780)

TeamPCP's Mini Shai-Hulud: The Developer Supply Chain Worm That Hit GitHub, OpenAI, and Mistral -- Then Went Public

The Mini Shai-Hulud npm worm has expanded well beyond the initial TanStack compromise to breach GitHub's internal infrastructure, compromise devices at OpenAI and Mistral AI, and poison 600+ packages across 16 million weekly downloads -- before its authors open-sourced it on BreachForums.

critical

Nightmare-Eclipse: Six Windows Zero-Days Released in Six Weeks, Three Now Weaponised in Live Attacks

A rogue researcher has published six working Windows exploit drops since April 2026. Three are confirmed active in attacks linked to Russian infrastructure, with more exploits -- including RCE -- threatened for June Patch Tuesday.

high MuddyWater

CISA Confirms Active Exploitation: Apex One Endpoint Platform Turned Against Defenders, Langflow Linked to Iranian APT

CISA's May 21 KEV additions confirm active exploitation of Trend Micro Apex One's directory traversal flaw -- which allows attackers to push malicious code through the defender's own endpoint management -- alongside a Langflow AI workflow vulnerability tied to MuddyWater intrusions.

high

PHP Supply Chain Compromise: Laravel-Lang Packages Weaponised to Harvest Cloud Credentials Across Enterprise CI/CD Pipelines

An attacker who obtained push access to the Laravel-Lang GitHub organisation rewrote over 230 package versions in under 90 minutes on 22–23 May, injecting a sophisticated cloud credential stealer into one of PHP's most widely used localisation library sets.

high MuddyWater

Iranian APT MuddyWater Deploys Chaos Ransomware as False Flag to Mask Espionage

Rapid7 researchers have attributed a series of intrusions using Chaos ransomware branding to MuddyWater -- an Iranian state-sponsored group -- in a deliberate false flag operation designed to obscure intelligence collection behind the appearance of criminal extortion.

high Lazarus Group

Lazarus Group Extends Cryptocurrency Targeting to UK Exchanges and Law Firm Custodians

North Korea's Lazarus Group has extended its cryptocurrency theft operations to UK-regulated digital asset exchanges and the law firms that provide custody and compliance services to crypto clients -- combining financial theft with intelligence collection.

high RansomHub affiliates

RansomHub Affiliates Targeting UK Law Firms During Active M&A Mandates

Multiple UK and European law firms have been hit by RansomHub-affiliated actors during live M&A transactions. The timing is deliberate: attackers maximise leverage by striking when client pressure to resolve the incident is highest.

critical

First Confirmed AI-Built Zero-Day: Google Thwarts Mass Exploitation Campaign

A threat actor used a large language model to write a working 2FA bypass exploit for a widely deployed open-source admin tool. Google's threat intelligence team detected the planned mass exploitation campaign before it launched. The code left distinctive LLM fingerprints.

high FIN7

FIN7 Pivots to Financial Services with New Phishing Infrastructure and Loader Malware

The FIN7 group has refreshed its phishing infrastructure and is deploying a new loader variant against mid-tier UK and European financial institutions. Targets include wealth managers, brokers, and payment processors.

Deep Analysis

high UNC6671 13 min read

UNC6671: Inside the Vishing Crew Behind BlackFile, Redact, Pink, Helix, and Falcon

A single financially motivated intrusion group has spent 2026 impersonating IT helpdesks to bypass MFA at scale, quietly cycling through five extortion brands -- and this summer set its sights on Wall Street's largest hedge funds.

high 11 min read

The CareCloud Breach: 3.75 Million Patients Exposed in an Unattributed AWS Intrusion

New Jersey-based EHR vendor CareCloud disclosed that attackers spent six days inside an Amazon Web Services environment in March, exfiltrating Social Security numbers, government IDs, financial data, and medical records for 3.75 million patients — the fifth-largest US healthcare breach of 2026.

high Jewelbug (Earth Alux / Ink Dragon / REF7707 / CL-STA-0049) 11 min read

Jewelbug: The China-Linked Hack-for-Hire Crew Running Espionage and Crypto Fraud From One Panel

Broadcom researchers have exposed Jewelbug, a China-based threat actor that breached 15 government webmail tenants in a single Middle Eastern intrusion while operating a parallel million-dollar cryptocurrency fraud scheme from the same control infrastructure.

high Spearwing 13 min read

Medusa Ransomware: The 500-Victim Operation Using a CrowdStrike Lookalike to Kill EDR

Medusa is a ransomware-as-a-service operation with more than 500 confirmed victims across healthcare, education, manufacturing, and legal. Its ABYSSWORKER kernel driver — signed with stolen Chinese certificates and disguised to mimic a CrowdStrike component — disables endpoint defences before encryption. North Korea's Lazarus Group has now been confirmed deploying Medusa in targeted campaigns, blurring the line between criminal RaaS and nation-state operations.

critical DeadLock 14 min read

DeadLock Ransomware: Rust Encryptor, Polygon Blockchain C2, and Europe-Focused Campaigns

DeadLock is a technically distinctive ransomware operation that stores recovery infrastructure on the Polygon blockchain, uses Rust for cross-platform encryption, and coordinates via Session's decentralised messaging network — three design choices that collectively complicate takedown operations and make decryption impossible without payment.

high APT34 15 min read

APT34 / OilRig / Hazel Sandstorm: Inside Iran's Premier Cyber Espionage Group

APT34 has operated persistently since at least 2014, targeting energy, government, financial, and telecoms sectors across the Middle East and beyond. Known for DNS-based command-and-control, a continuously evolving malware arsenal, and deep operational persistence, the group represents Iran's most capable and consistently active espionage platform. This deep-dive covers APT34's organisational profile, TTPs, malware families, and 2025-2026 activity.

high Hyadina (GodDamn / Beast / Monster) 10 min read

GodDamn / Hyadina -- The Beast Rebrand That Ships With a Microsoft-Signed EDR Killer

The threat actor Symantec tracks as Hyadina has run three successive ransomware families since 2022. The latest, GodDamn, arrives paired with PoisonX -- a kernel driver that carries a valid Microsoft signature and kills endpoint defences before encryption starts. This is not a BYOVD attack. The driver was built for this purpose, and then it got a legitimate certificate.

high NadMesh 9 min read

NadMesh: The Go Botnet Built to Exploit the AI Service Sprawl

NadMesh is a Go-compiled mesh botnet with over 20 built-in RCE exploit chains targeting exposed AI services including Ollama, ComfyUI, n8n, Langflow, and Gradio. The operator claims 3,811 harvested AWS access keys. The botnet's Shodan-powered auto-discovery and automated exploitation pipeline represents the industrialisation of opportunistic AI infrastructure attacks.

high Nitrogen/Azote 10 min read

Nitrogen/Azote: From Poisoned Google Ads to the Foxconn North America Breach

Nitrogen, now operating as Azote, is a threat group running one of the most sustained malvertising-to-ransomware pipelines active today. By buying Google and Bing ads for popular software titles, the group delivers trojaned MSIX installers that establish Cobalt Strike footholds used for data theft and ALPHV/BlackCat ransomware deployment. The Foxconn North America breach — 8TB exfiltrated, 11 million files — is the group's most significant confirmed operation.

critical UTA0533 11 min read

UTA0533: Two SonicWall Zero-Days, Custom Implants, and the SMA 1000 Espionage Campaign

Volexity's July 2026 disclosure named UTA0533 as the operator behind simultaneous exploitation of two zero-day vulnerabilities in SonicWall SMA 1000 appliances. The group deployed KNUCKLEBALL, a passive credential-harvesting implant, and ROOTRUN, a persistent backdoor with tunneling capability, against targets in government and enterprise sectors.

high Akira 12 min read

Akira Ransomware: The VPN-First Playbook Behind a $244 Million Operation

Akira has become one of the most prolific ransomware operations of 2025-26 by sticking to a disciplined playbook: compromised VPN credentials, ESXi encryptors, and a short negotiation window. Here's how the group operates, who it targets, and what defenders can do about it.

high Lurking Lizard 12 min read

Lurking Lizard: How a China-Linked Cybercrime Group Built a Global Residential Proxy Network Through Fake Software

Infoblox and The Hacker News disclosed in July 2026 that Lurking Lizard, a China-based financially motivated threat group, operates an industrial-scale residential proxy business sustained by trojaned installers for legitimate software. The network has processed hundreds of millions of proxy requests and is actively rented to criminal and espionage-linked operators.

high Storm-2755 11 min read

Storm-2755: Inside the Malware-Free Payroll Fraud Group Redirecting Canadian Salaries to Attacker Accounts

Microsoft disclosed Storm-2755 in April 2026 — a financially motivated threat actor conducting adversary-in-the-middle phishing campaigns against Canadian employees to redirect payroll deposits to attacker-controlled bank accounts. The group operates without traditional malware, using stolen session tokens to bypass MFA and modify direct deposit settings in HR portals.

high DPRK IT Worker Networks (UNC5267 / Nickel Tapestry) 14 min read

DPRK IT Worker Networks: North Korea's Industrial-Scale Employment Fraud Operation

North Korea is running an industrial-scale programme in which thousands of operatives pose as freelance software developers and remote employees to generate revenue, conduct espionage, and extort companies they infiltrate. Tracked as UNC5267 and Nickel Tapestry, this threat has graduated from a revenue scheme to a direct enterprise security risk.

high UAT-7810 14 min read

UAT-7810 and LapDogs: Inside China's Malware Factory for Covert Relay Infrastructure

Cisco Talos has published detailed research on UAT-7810's LapDogs campaign: a China-nexus operation building Operational Relay Box networks through compromised SOHO routers. New malware families LONGLEASH, DOGLEASH, and JARLEASH reveal how far this infrastructure-as-a-service model has matured.

critical Anubis 13 min read

Anubis Ransomware: The RaaS Platform Weaponising Healthcare Regulators Against Its Own Victims

Anubis is a Go-based ransomware-as-a-service operation that emerged in late 2024 and has rapidly focused on healthcare organisations, deploying a novel pressure tactic: threatening to notify data protection regulators and HIPAA enforcement bodies unless victims pay. This deep dive covers Anubis's affiliate model, technical profile, targeting patterns, and the regulatory weaponisation that distinguishes its extortion approach.

critical Cicada3301 14 min read

Cicada3301: The Rust-Based RaaS That Emerged From the ALPHV Collapse

Cicada3301, tracked by Palo Alto Unit 42 as Repellent Scorpius, emerged in mid-2024 as a technically sophisticated ransomware-as-a-service operation bearing strong similarities to the ALPHV/BlackCat platform. This deep dive examines the evidence for an ALPHV connection, the technical profile of the Rust-based encryptor, targeting patterns, and what the group's structure tells us about resilience in the ransomware ecosystem.

critical Qilin 15 min read

Qilin: The Ransomware Group Behind the NHS Synnovis Attack and the Chrome Credential Theft Innovation

Qilin emerged in 2022 as Agenda ransomware and has evolved through a complete Rust rewrite, a defining attack on NHS blood supply services in 2024, a novel Chrome browser credential theft technique, and a 2026 VPN exploitation campaign hitting four major vendors simultaneously. This deep dive covers the full operational and technical profile.

critical RansomHub 14 min read

RansomHub: The RaaS Platform That Inherited the Ransomware Ecosystem

RansomHub launched in February 2024 as a direct beneficiary of two simultaneous law enforcement disruptions — the FBI's LockBit takedown and the ALPHV/BlackCat collapse — and in less than a year became the most prolific ransomware group by victim count. This deep dive covers how RansomHub built its dominance, the multi-platform technical architecture, the affiliate model that makes it resilient to law enforcement pressure, and what defenders should prioritise.

high Pioneer Kitten / Fox Kitten 12 min read

Pioneer Kitten: How Iran's IRGC Became an Access Broker for Ransomware Gangs

Pioneer Kitten — tracked as Fox Kitten, Lemon Sandstorm, and UNC757 — is an Iranian state-sponsored group that exploits network perimeter devices to establish persistent access, then sells that access to criminal ransomware affiliates. This deep dive examines the group's dual mandate, tradecraft, and what a compromise looks like in practice.

high INC Ransom 10 min read

INC Ransomware: Rust Encryptors, Veeam Credential Theft, and 830 Victims

INC Ransom has quietly become one of the most prolific ransomware operations of 2025-2026, combining purpose-rebuilt Rust encryptors, a modified Veeam DPAPI credential dumper, and deliberate use of living-off-the-land techniques to evade detection. With over 830 confirmed victims across healthcare, legal, and manufacturing, this group deserves closer examination than it typically receives.

critical APT41 10 min read

APT41 / Winnti / Double Dragon: China's Dual-Mandate Cyber Threat Group

APT41 operates simultaneously as a state-directed espionage actor targeting strategic industries for Beijing and a financially motivated cybercriminal enterprise — a combination unique among Chinese threat groups. A 2026 ELF cloud credential backdoor with zero VirusTotal detections is the latest evidence of the group's continued operational sophistication.

critical Cl0p 11 min read

Cl0p: The Group That Turned File Transfer Vulnerabilities Into a Mass Exploitation Business

Cl0p is a financially motivated cybercriminal group that has systematically identified and mass-exploited zero-day vulnerabilities in enterprise file transfer software, compromising thousands of organisations globally. Their MOVEit campaign in 2023 was the largest data theft operation in the history of ransomware. This deep dive covers their operational model, technical approach, and what comes next.

critical LockBit 12 min read

LockBit: The Ransomware Operation That Survived Its Own Takedown

LockBit is the world's most prolific ransomware-as-a-service operation, responsible for more confirmed attacks than any other RaaS group. Despite Operation Cronos seizing its infrastructure and unmasking its administrator in 2024, the affiliate network remains active. This deep dive covers LockBit's operational model, technical capabilities, and what the post-Cronos resurgence means for defenders.

critical APT29 15 min read

Midnight Blizzard: A Complete Profile of Russia's SVR Espionage Apparatus

APT29 — Cozy Bear, Midnight Blizzard — is Russia's SVR-aligned intelligence collection machine, responsible for SolarWinds, the 2024 Microsoft corporate email compromise, and ongoing targeting of European governments, diplomatic missions, and defence industrial base organisations. This deep dive covers their full operational history, tradecraft, tooling, and what defenders need to be doing now.

high Silk Typhoon 12 min read

Silk Typhoon: China's IT Supply Chain Pivot and the Downstream Threat to Every Sector

Silk Typhoon — the Chinese state actor behind the 2021 Exchange ProxyLogon campaign and the 2024 US Treasury breach — has fundamentally changed how it operates. A deep dive into the group's shift to IT supply chain targeting and what it means for every organisation that relies on a managed service provider.

critical Lazarus Group (TraderTraitor / APT38 / UNC4736) 12 min read

Lazarus Group / TraderTraitor: North Korea's Premier Financial Theft Operation

A comprehensive profile of Lazarus Group and its TraderTraitor subcluster -- the North Korean cyber apparatus responsible for over $6 billion in cryptocurrency theft, the largest single financial heist in history, and a growing campaign of developer-targeted supply chain intrusions.

high The Gentlemen 10 min read

The Gentlemen: From Zero to 340 Victims in Nine Months -- Inside the RaaS Group Rewriting the Ransomware Playbook

Launched in mid-2025 by a disgruntled Qilin affiliate, The Gentlemen ransomware-as-a-service operation reached third place globally in Q1 2026 through pre-stockpiled FortiGate access, a 90% affiliate commission, and a deliberate strategy to target non-US markets that most groups neglect.

high 18 min read

AI in the Attack Chain: How Threat Actors Are Using Language Models Operationally

AI-assisted exploitation is no longer theoretical. From automated vulnerability research to AI-generated spear-phishing, the adoption of LLMs across the offensive lifecycle is accelerating. This analysis examines what is confirmed, what is emerging, and what it means for defenders.

high Scattered Spider 15 min read

Scattered Spider: When Social Engineering Becomes a Professional Discipline

The group behind the MGM Resorts and Caesars Entertainment attacks isn't a nation-state operation or a seasoned criminal enterprise. They're young, English-speaking, and they're better at manipulating people than most security teams are at stopping them.

Commentary

7 min read

Twenty-Two Seconds: What M-Trends 2026 Says About Attacker Speed and Defender Reality

Mandiant's M-Trends 2026 report, grounded in over 500,000 hours of incident investigations, contains several findings that should recalibrate how security teams think about detection windows, initial access economics, and the real mechanics of ransomware recovery denial. The headline statistic — 22 seconds from initial access to secondary threat group handoff — isn't the most important one.

8 min read

The Agentic Attack Surface: Your AI Assistant Is the New Endpoint

Enterprise AI assistants now hold privileged access to code repositories, cloud credentials, internal APIs, and production systems. Security teams are not monitoring them. This is a structural blind spot with material consequences — and it's arriving faster than most organisations realise.

7 min read

The AI Patch Wave Is Already Here -- and Defenders Are Already Behind

The NCSC warned in May that AI-accelerated vulnerability discovery would create a forced correction of technical debt. One month later, Anthropic's Project Glasswing has already found over 10,000 critical vulnerabilities in open source. The bottleneck is no longer finding bugs. It's fixing them.

8 min read

The Data That Nation-States Actually Want Is Sitting in Your Document Management System

Law firms and professional services firms are among the most intelligence-rich targets in the UK economy. Understanding why clarifies the threat -- and why perimeter security alone is the wrong response.

7 min read

Why Ransomware Groups Don't Die When You Arrest Their Leaders

The ransomware-as-a-service model has created a resilient criminal infrastructure that survives law enforcement actions, FBI seizures, and individual prosecutions. Understanding why is the first step to defending against it.

7 min read

Nation-State Threats: What Business Leaders Get Wrong and Why It Matters

Most executives conflate nation-state cyber activity with the ransomware threat they're more familiar with. They are different in purpose, method, and the defences required. Getting this wrong shapes your entire risk posture.

Threat Actors

Qilin critical 3 reports Gunra critical 2 reports FSB Center 16 high 2 reports MuddyWater high 2 reports UNC6671 high 1 report Jewelbug (Earth Alux / Ink Dragon / REF7707 / CL-STA-0049) high 1 report Cavern Manticore / APT42 high 1 report Clop high 1 report Spearwing high 1 report DeadLock critical 1 report Midnight Blizzard (Storm-2945) high 1 report APT34 high 1 report Hyadina (GodDamn / Beast / Monster) high 1 report Contagious Interview / Famous Chollima (North Korea) high 1 report JADEPUFFER critical 1 report NadMesh high 1 report Nitrogen/Azote high 1 report UTA0533 critical 1 report DriveSurge critical 1 report Akira high 1 report Lurking Lizard high 1 report Storm-2755 high 1 report DPRK IT Worker Networks (UNC5267 / Nickel Tapestry) high 1 report UAT-7810 high 1 report Storm-2603 high 1 report Anubis critical 1 report Cicada3301 critical 1 report RansomHub critical 1 report Pioneer Kitten / Fox Kitten high 1 report KongTuke high 1 report Sapphire Sleet (BlueNoroff) high 1 report DragonForce (Hackledorb) high 1 report INC Ransom high 1 report Icarus high 1 report Velvet Ant critical 1 report ShinyHunters critical 1 report APT41 critical 1 report TeamPCP (Miasma variant) critical 1 report TA4922 high 1 report Cl0p critical 1 report LockBit critical 1 report APT29 critical 1 report China-aligned (unattributed) high 1 report Silk Typhoon high 1 report Silent Ransom Group high 1 report Lazarus Group (TraderTraitor / APT38 / UNC4736) critical 1 report TeamPCP (UNC6780) critical 1 report The Gentlemen high 1 report Lazarus Group high 1 report RansomHub affiliates high 1 report FIN7 high 1 report Scattered Spider high 1 report