Ransomware

CVE Vulnerability Alerts
Metabase Zero-Day SQL Injection Exploited Against Framework, Tally
Metabase confirmed an exploited CVSS 10.0 zero-day SQL injection vulnerability that let attackers access customer data at Framework, Tally, and LexisNexis.
Cybersecurity
Attackers Reach Managed Endpoints as N-able Ships N-central Hotfix 2
Attackers who compromised N-able N-central reached managed endpoints and installed Cloudflare Tunnel persistence, prompting the vendor to release Hotfix 2.
Cybersecurity
UNC6671 Extortion Group Rebrands After Targeting Hedge Funds
Google Threat Intelligence ties hedge fund vishing attacks to UNC6671 (BlackFile), an extortion group rebranding across Redact, Pink, Helix, and Falcon.
Cybersecurity
Ransom Cartel Creator Sentenced to 16 Years for RaaS Operation
A federal judge in Virginia sentenced Belarusian Maksim Silnikau, the creator of Ransom Cartel, to 16 years for running a ransomware-as-a-service operation.
Cybersecurity
INC Ransomware Becomes Top Exploiter of SonicWall SMA1000 Zero-Days
INC Ransomware is now the most active group exploiting SonicWall SMA1000 zero-days, breaching victims in the US, Australia, UAE, Colombia, and Switzerland.
Cybersecurity
ENCFORGE Ransomware Targets PyTorch, SafeTensors Model Files
Sysdig documented ENCFORGE, a Go ransomware targeting 180 AI file formats including PyTorch, SafeTensors, and GGUF, deployed by the JADEPUFFER threat operator.
CVE Vulnerability Alerts
Qilin Affiliates Exploit PAN-OS CVE-2026-0257 GlobalProtect Bypass
Arctic Wolf documented Qilin affiliates exploiting CVE-2026-0257, a PAN-OS GlobalProtect auth bypass, to gain trusted VPN access for double-extortion attacks.
Cybersecurity
PEAR Ransomware Breach at MCBS Hits 1.26 Million Patients
PEAR ransomware group claimed 3 TB stolen from MCBS, a medical billing firm whose breach exposed 1.26 million patients at seven healthcare organizations.
Application Security
SourTrade Malvertising Assembles Malware in Browser Memory
SourTrade malvertising downloads encrypted fragments and assembles a Windows executable in browser memory, evading file-based detection across 12 countries.
Cybersecurity
DragonForce Posts Eighteen Victims Across Eight Countries in 48 Hours
DragonForce posted eighteen victims across eight countries in 48 hours, including a US defense subcontractor, four law firms, and chemical manufacturers.

Threat actors