Skip to content

Flash Briefings

high FSB Center 16

CISA AA26-194A: FSB Center 16 Exploiting Default SNMP Credentials to Exfiltrate Router Configs from Critical Infrastructure

A 19-agency joint advisory from 13 countries details how FSB Center 16 has been harvesting router configurations and credentials from critical infrastructure networks globally by exploiting default SNMP community strings and unpatched Cisco Smart Install deployments.

critical

Fortinet FortiSandbox: Three OS Injection Flaws Under Active Exploitation, CISA Orders Patch by July 19

CISA added three critical OS command injection vulnerabilities in Fortinet FortiSandbox to the KEV catalog on July 16, 2026, citing active exploitation. Federal agencies face a July 19 patch deadline; enterprise defenders running FortiSandbox on-premises, cloud, or PaaS must act immediately.

high FSB Center 16

Five Eyes Alert: Russian FSB Router Campaign Targets Critical Sectors Globally

CISA, NSA, FBI, and 15 international partners have issued a joint advisory warning that Russian FSB Center 16 actors are systematically exploiting poorly configured networking devices across energy, communications, healthcare, and financial services.

critical

Oracle EBS Payments Component Hit with CVSS 9.8 Unauthenticated RCE — CISA Sets 72-Hour Federal Deadline

CVE-2026-46817 is a CVSS 9.8 unauthenticated remote code execution flaw in Oracle E-Business Suite's Payments File Transmission component. CISA added it to the Known Exploited Vulnerabilities catalogue on July 15 with a federal patch deadline of July 18 — 72 hours from disclosure to mandatory remediation.

high Iran-nexus (GigaWiper/BLUERABBIT)

GigaWiper: Iran-Nexus Destructive Backdoor Combines Wiper, Fake Ransomware, and Spyware

Microsoft and Binary Defense have separately documented GigaWiper, a modular Go-based Windows backdoor attributed to an Iran-nexus group that has been targeting Israeli organisations since October 2025. The implant combines irreversible disk wiping, fake ransomware with no recoverable key, and live spyware capabilities in a single deployable payload.

high

SharePoint RCE CVE-2026-45659 Exploited Despite Microsoft's 'Less Likely' Rating

CISA added CVE-2026-45659 to its KEV catalog on July 1, overriding Microsoft's own 'Exploitation Less Likely' assessment. Any authenticated SharePoint user with Site Member permissions can achieve remote code execution across SharePoint Server 2016, 2019, and Subscription Edition.

high

Progress Orders ShareFile Storage Zone Controllers Offline Over Active Security Threat

Progress Software has directed all ShareFile Storage Zone Controller customers to take their on-premises file-transfer infrastructure offline following a credible external security threat. No patch exists; shutdown is the only available mitigation.

critical

Three CVSS 10.0 Flaws Hit CISA KEV in 48 Hours: ColdFusion and Joomla Actively Exploited

Adobe ColdFusion and two Joomla-ecosystem components with CVSS 10.0 ratings were added to the CISA Known Exploited Vulnerabilities catalog between July 7 and 9, with a federal patch deadline of July 10. Langflow also added as the first AI agent platform in the catalog.

high

GhostLock: 15-Year Linux Kernel Flaw Opens Root and Container Escape

A 15-year-old Linux kernel use-after-free vulnerability tracked as CVE-2026-43499 allows any logged-in user to gain root access on unpatched systems. Public exploit code is available and the flaw enables container escape, making patching of cloud, server, and multi-tenant Linux infrastructure an immediate priority.

high

CVE-2026-46242 'Bad Epoll': Linux Kernel LPE Demands Patch Urgency Across Server Fleets

A race-condition use-after-free in the Linux kernel's epoll subsystem gives any unprivileged local user a reliable path to root. A working exploit exists, kernel versions 6.4 and later are affected, and many distributions have not yet shipped the backport.

high Storm-2603

SharePoint Server RCE Under Active Ransomware Exploitation: CISA Sets July 4 Federal Deadline

CVE-2026-45659, a CVSS 8.8 deserialization remote code execution flaw in on-premises SharePoint Server, is being actively exploited by Storm-2603 ransomware operators. CISA added it to the Known Exploited Vulnerabilities catalogue on July 1 with a federal patch deadline of July 4.

critical

CVE-2026-55200: Public PoC for Critical libssh2 Flaw Exposes Enterprise Infrastructure

A public proof-of-concept has been released for a CVSS 9.2 client-side flaw in libssh2 that enables zero-authentication remote code execution when connecting to a malicious or compromised SSH server. No official patched release exists yet.

high

FortiBleed: 73,932 FortiGate Credentials from CVE-2022-40684 Surface Four Years After Exploitation

A dataset of valid VPN credentials harvested from 73,932 FortiGate devices during CVE-2022-40684 exploitation was published on 17 June 2026. The four-year gap between collection and release illustrates a documented threat actor pattern — credential harvesting during a mass exploitation window, then monetising the dataset years later when many organisations have forgotten to rotate.

critical

CVE-2026-20253: Splunk Enterprise RCE Added to CISA KEV — SOCs at Risk

CISA added CVE-2026-20253, an unauthenticated RCE in Splunk Enterprise's PostgreSQL sidecar service, to the Known Exploited Vulnerabilities catalog on June 18, 2026. Federal remediation deadline is June 21. Splunk deployments at SOCs, financial institutions, healthcare, and government are at elevated risk.

high UNC6508

UNC6508: China-Linked Group Mined Medical and Military Research for Two Years

Google Threat Intelligence has disclosed a PRC-nexus espionage campaign that breached North American clinical, academic, and military health institutions via REDCap research servers, remaining undetected from September 2023 through November 2025.

critical

NCSC Warning: Citrix NetScaler ADC and Gateway Critical Vulnerabilities Under Active Exploitation

NCSC has issued an urgent advisory on two vulnerabilities in Citrix NetScaler ADC and Gateway — CVE-2026-3055 (CVSS 9.3, unauthenticated memory exfiltration) and CVE-2026-4368 — urging UK organisations to patch immediately. Both flaws affect versions widely deployed across enterprise, healthcare, and finance environments.

critical ShinyHunters

ShinyHunters Weaponised Oracle PeopleSoft Zero-Day Against 100+ Universities and Enterprises: CVE-2026-35273

ShinyHunters (UNC6240) exploited a CVSS 9.8 unauthenticated RCE in Oracle PeopleSoft as a zero-day for two weeks before any patch existed, breaching more than 100 organisations — 68% of them universities. CISA added CVE-2026-35273 to its KEV catalog on 12 June 2026.

critical

Ivanti Sentry MDM Gateways Backdoored Within 48 Hours of Patch: CVSS 10.0 Pre-Auth RCE

A CVSS 10.0 pre-authentication OS command injection in Ivanti Sentry allows unauthenticated root-level code execution on MDM gateway appliances. Production instances were backdoored within 48 hours of the advisory. CISA has set a 14 June 2026 remediation deadline.

critical

RoguePlanet: Seventh Zero-Day Dropped Hours After Patch Tuesday, Targets Microsoft Defender on Fully Patched Windows

The researcher behind the Nightmare-Eclipse exploit series has released a seventh zero-day — RoguePlanet — exploiting a race condition in Microsoft Defender to deliver SYSTEM privileges on fully patched Windows 10 and 11, hours after June Patch Tuesday closed the previous six.

critical

CVE-2026-44963: Critical Veeam Backup RCE Gives Any Domain User a Path to Ransomware's Favourite Target

A CVSS 9.4 remote code execution flaw in Veeam Backup & Replication v12 lets any authenticated domain user execute arbitrary code on backup servers — recreating the low-barrier attack surface that ransomware groups have repeatedly weaponised in prior Veeam vulnerabilities.

critical Qilin

Qilin Ransomware Affiliate Exploiting Authentication Bypasses Across Four VPN Platforms in Coordinated Campaign

A Qilin ransomware affiliate is systematically exploiting authentication bypass vulnerabilities across Check Point, Palo Alto Networks, Fortinet, and F5 VPN infrastructure simultaneously — with a month-long zero-day window on the Check Point flaw before any patch existed.

high ShinyHunters

ShinyHunters Publishes 234 GB of DentaQuest Healthcare Data After Ransom Talks Fail

The ShinyHunters extortion group has published 234 GB of data stolen from DentaQuest, a dental benefits administrator serving 32 million Americans. The leaked dataset includes healthcare enrollment records, Medicaid IDs, and personal information for an estimated 2.6 million individuals.

critical

CVE-2026-41089: Critical Windows Netlogon RCE Now Actively Exploited — Every Unpatched Domain Controller at Risk

Active exploitation of CVE-2026-41089, a pre-authentication zero-click RCE in Windows Netlogon, was confirmed by Belgium's Centre for Cybersecurity on 29 May. Successful exploitation gives an attacker SYSTEM-level control of the domain controller and full ownership of the Active Directory domain.

high

CVE-2026-0257: PAN-OS GlobalProtect Authentication Bypass Under Active Exploitation — CISA Deadline Today

A medium-severity authentication bypass in Palo Alto Networks PAN-OS GlobalProtect is being actively exploited across enterprise networks, with CISA's KEV remediation deadline falling on 1 June 2026.

critical

FortiClient EMS Active Exploitation: Threat Actors Deploying EKZ Infostealer Via Fake Fortinet Patch

Fresh exploitation of CVE-2026-35616, a critical pre-authentication bypass in Fortinet's FortiClient Endpoint Management Server, is ongoing in May 2026. Threat actors are delivering the EKZ credential-stealing malware disguised as a legitimate Fortinet software update, prompting an NHS England Digital alert.

critical

Nightmare-Eclipse: Six Windows Zero-Days Released in Six Weeks, Three Now Weaponised in Live Attacks

A rogue researcher has published six working Windows exploit drops since April 2026. Three are confirmed active in attacks linked to Russian infrastructure, with more exploits -- including RCE -- threatened for June Patch Tuesday.

high MuddyWater

CISA Confirms Active Exploitation: Apex One Endpoint Platform Turned Against Defenders, Langflow Linked to Iranian APT

CISA's May 21 KEV additions confirm active exploitation of Trend Micro Apex One's directory traversal flaw -- which allows attackers to push malicious code through the defender's own endpoint management -- alongside a Langflow AI workflow vulnerability tied to MuddyWater intrusions.

high LockBit

LockBit Resurgence: Affiliate Network Active Across UK Healthcare and Professional Services

Despite Operation Cronos and the February 2024 infrastructure seizure, LockBit-affiliated actors continue to operate under the LockBit 3.0 and successor infrastructure. UK healthcare and professional services organisations have been among the most recent confirmed victims.

high RansomHub affiliates

NHS Trusts Targeted in Coordinated Ransomware Wave as RaaS Affiliates Shift Focus

A cluster of ransomware affiliates, several previously linked to ALPHV/BlackCat, has targeted three NHS trusts in the past six weeks. Attackers are exploiting legacy VPN appliances and unpatched remote access infrastructure.

critical

First Confirmed AI-Built Zero-Day: Google Thwarts Mass Exploitation Campaign

A threat actor used a large language model to write a working 2FA bypass exploit for a widely deployed open-source admin tool. Google's threat intelligence team detected the planned mass exploitation campaign before it launched. The code left distinctive LLM fingerprints.

Deep Analysis

high Akira 12 min read

Akira Ransomware: The VPN-First Playbook Behind a $244 Million Operation

Akira has become one of the most prolific ransomware operations of 2025-26 by sticking to a disciplined playbook: compromised VPN credentials, ESXi encryptors, and a short negotiation window. Here's how the group operates, who it targets, and what defenders can do about it.

high Storm-2755 11 min read

Storm-2755: Inside the Malware-Free Payroll Fraud Group Redirecting Canadian Salaries to Attacker Accounts

Microsoft disclosed Storm-2755 in April 2026 — a financially motivated threat actor conducting adversary-in-the-middle phishing campaigns against Canadian employees to redirect payroll deposits to attacker-controlled bank accounts. The group operates without traditional malware, using stolen session tokens to bypass MFA and modify direct deposit settings in HR portals.

high DPRK IT Worker Networks (UNC5267 / Nickel Tapestry) 14 min read

DPRK IT Worker Networks: North Korea's Industrial-Scale Employment Fraud Operation

North Korea is running an industrial-scale programme in which thousands of operatives pose as freelance software developers and remote employees to generate revenue, conduct espionage, and extort companies they infiltrate. Tracked as UNC5267 and Nickel Tapestry, this threat has graduated from a revenue scheme to a direct enterprise security risk.

critical Anubis 13 min read

Anubis Ransomware: The RaaS Platform Weaponising Healthcare Regulators Against Its Own Victims

Anubis is a Go-based ransomware-as-a-service operation that emerged in late 2024 and has rapidly focused on healthcare organisations, deploying a novel pressure tactic: threatening to notify data protection regulators and HIPAA enforcement bodies unless victims pay. This deep dive covers Anubis's affiliate model, technical profile, targeting patterns, and the regulatory weaponisation that distinguishes its extortion approach.

critical Cicada3301 14 min read

Cicada3301: The Rust-Based RaaS That Emerged From the ALPHV Collapse

Cicada3301, tracked by Palo Alto Unit 42 as Repellent Scorpius, emerged in mid-2024 as a technically sophisticated ransomware-as-a-service operation bearing strong similarities to the ALPHV/BlackCat platform. This deep dive examines the evidence for an ALPHV connection, the technical profile of the Rust-based encryptor, targeting patterns, and what the group's structure tells us about resilience in the ransomware ecosystem.

critical RansomHub 14 min read

RansomHub: The RaaS Platform That Inherited the Ransomware Ecosystem

RansomHub launched in February 2024 as a direct beneficiary of two simultaneous law enforcement disruptions — the FBI's LockBit takedown and the ALPHV/BlackCat collapse — and in less than a year became the most prolific ransomware group by victim count. This deep dive covers how RansomHub built its dominance, the multi-platform technical architecture, the affiliate model that makes it resilient to law enforcement pressure, and what defenders should prioritise.

critical Qilin 15 min read

Qilin: The Ransomware Group Behind the NHS Synnovis Attack and the Chrome Credential Theft Innovation

Qilin emerged in 2022 as Agenda ransomware and has evolved through a complete Rust rewrite, a defining attack on NHS blood supply services in 2024, a novel Chrome browser credential theft technique, and a 2026 VPN exploitation campaign hitting four major vendors simultaneously. This deep dive covers the full operational and technical profile.

high Pioneer Kitten / Fox Kitten 12 min read

Pioneer Kitten: How Iran's IRGC Became an Access Broker for Ransomware Gangs

Pioneer Kitten — tracked as Fox Kitten, Lemon Sandstorm, and UNC757 — is an Iranian state-sponsored group that exploits network perimeter devices to establish persistent access, then sells that access to criminal ransomware affiliates. This deep dive examines the group's dual mandate, tradecraft, and what a compromise looks like in practice.

high RomCom / Storm-0978 (Russia) 18 min read

RomCom / Storm-0978: Russia's Hybrid Espionage-Criminal Threat Actor

RomCom — tracked by Microsoft as Storm-0978, by Unit 42 as Tropical Scorpius, by Mandiant as UNC2596 — is a Russian threat actor that operates across the line between state-sponsored espionage and organised cybercrime. The group exploited two chained zero-days to target NATO governments in 2023, runs Underground ransomware operations for revenue, and has maintained continuous campaigns against Ukrainian government and European defence targets through 2026.

high INC Ransom 10 min read

INC Ransomware: Rust Encryptors, Veeam Credential Theft, and 830 Victims

INC Ransom has quietly become one of the most prolific ransomware operations of 2025-2026, combining purpose-rebuilt Rust encryptors, a modified Veeam DPAPI credential dumper, and deliberate use of living-off-the-land techniques to evade detection. With over 830 confirmed victims across healthcare, legal, and manufacturing, this group deserves closer examination than it typically receives.

high APT42 14 min read

APT42: Iran's Elite Social Engineering Unit Targeting Western Officials and Research

APT42 is Iran's most operationally sophisticated espionage actor — an IRGC-IO-sponsored group that has compromised US presidential campaigns, nuclear researchers, journalists, and Western diplomats through highly targeted social engineering rather than technical exploitation.

high FulcrumSec 11 min read

FulcrumSec: Deep Dive into the Data Extortion Group Exploiting Developer Credential Sprawl

FulcrumSec emerged in October 2025 running pure data extortion with no ransomware component. Confirmed victims include Avnet (1.3TB), youX (300GB), and Novo Nordisk (1.3TB, $25M demand). Their initial access technique — GitHub PATs exposed in client-side JavaScript — is simple, scalable, and rapidly becoming a template for other extortion groups. This deep dive covers their attack chain, operational history, tooling characteristics, and defensive countermeasures.

critical APT41 10 min read

APT41 / Winnti / Double Dragon: China's Dual-Mandate Cyber Threat Group

APT41 operates simultaneously as a state-directed espionage actor targeting strategic industries for Beijing and a financially motivated cybercriminal enterprise — a combination unique among Chinese threat groups. A 2026 ELF cloud credential backdoor with zero VirusTotal detections is the latest evidence of the group's continued operational sophistication.

critical Cl0p 11 min read

Cl0p: The Group That Turned File Transfer Vulnerabilities Into a Mass Exploitation Business

Cl0p is a financially motivated cybercriminal group that has systematically identified and mass-exploited zero-day vulnerabilities in enterprise file transfer software, compromising thousands of organisations globally. Their MOVEit campaign in 2023 was the largest data theft operation in the history of ransomware. This deep dive covers their operational model, technical approach, and what comes next.

critical LockBit 12 min read

LockBit: The Ransomware Operation That Survived Its Own Takedown

LockBit is the world's most prolific ransomware-as-a-service operation, responsible for more confirmed attacks than any other RaaS group. Despite Operation Cronos seizing its infrastructure and unmasking its administrator in 2024, the affiliate network remains active. This deep dive covers LockBit's operational model, technical capabilities, and what the post-Cronos resurgence means for defenders.

high Silk Typhoon 12 min read

Silk Typhoon: China's IT Supply Chain Pivot and the Downstream Threat to Every Sector

Silk Typhoon — the Chinese state actor behind the 2021 Exchange ProxyLogon campaign and the 2024 US Treasury breach — has fundamentally changed how it operates. A deep dive into the group's shift to IT supply chain targeting and what it means for every organisation that relies on a managed service provider.

high The Gentlemen 10 min read

The Gentlemen: From Zero to 340 Victims in Nine Months -- Inside the RaaS Group Rewriting the Ransomware Playbook

Launched in mid-2025 by a disgruntled Qilin affiliate, The Gentlemen ransomware-as-a-service operation reached third place globally in Q1 2026 through pre-stockpiled FortiGate access, a 90% affiliate commission, and a deliberate strategy to target non-US markets that most groups neglect.

high 18 min read

AI in the Attack Chain: How Threat Actors Are Using Language Models Operationally

AI-assisted exploitation is no longer theoretical. From automated vulnerability research to AI-generated spear-phishing, the adoption of LLMs across the offensive lifecycle is accelerating. This analysis examines what is confirmed, what is emerging, and what it means for defenders.

Commentary

8 min read

The Agentic Attack Surface: Your AI Assistant Is the New Endpoint

Enterprise AI assistants now hold privileged access to code repositories, cloud credentials, internal APIs, and production systems. Security teams are not monitoring them. This is a structural blind spot with material consequences — and it's arriving faster than most organisations realise.

7 min read

The AI Patch Wave Is Already Here -- and Defenders Are Already Behind

The NCSC warned in May that AI-accelerated vulnerability discovery would create a forced correction of technical debt. One month later, Anthropic's Project Glasswing has already found over 10,000 critical vulnerabilities in open source. The bottleneck is no longer finding bugs. It's fixing them.

7 min read

Why Ransomware Groups Don't Die When You Arrest Their Leaders

The ransomware-as-a-service model has created a resilient criminal infrastructure that survives law enforcement actions, FBI seizures, and individual prosecutions. Understanding why is the first step to defending against it.

8 min read

The Real Cost of a Critical Infrastructure Attack: Beyond the Ransom

When a critical infrastructure operator is hit, the ransom payment is usually the smallest line on the eventual damage assessment. The true costs -- operational, regulatory, reputational, and systemic -- are far larger and far longer-lasting.