Ransomware

Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
U.S. and South Korean intelligence agencies warn Gunra ransomware exploits Fortinet firewall flaws alongside a previously undocumented MFA bypass technique.
Application Security
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
CISA confirms ransomware operators exploit a CVSS 9.1 SharePoint Server RCE requiring no authentication and granting administrator access worldwide today.
CVE Vulnerability Alerts
Metabase Zero-Day SQL Injection Exploited Against Framework, Tally
Metabase confirmed an exploited CVSS 10.0 zero-day SQL injection vulnerability that let attackers access customer data at Framework, Tally, and LexisNexis.
Cybersecurity
Attackers Reach Managed Endpoints as N-able Ships N-central Hotfix 2
Attackers who compromised N-able N-central reached managed endpoints and installed Cloudflare Tunnel persistence, prompting the vendor to release Hotfix 2.
Cybersecurity
UNC6671 Extortion Group Rebrands After Targeting Hedge Funds
Google Threat Intelligence ties hedge fund vishing attacks to UNC6671 (BlackFile), an extortion group rebranding across Redact, Pink, Helix, and Falcon.
Cybersecurity
Ransom Cartel Creator Sentenced to 16 Years for RaaS Operation
A federal judge in Virginia sentenced Belarusian Maksim Silnikau, the creator of Ransom Cartel, to 16 years for running a ransomware-as-a-service operation.
Cybersecurity
INC Ransomware Becomes Top Exploiter of SonicWall SMA1000 Zero-Days
INC Ransomware is now the most active group exploiting SonicWall SMA1000 zero-days, breaching victims in the US, Australia, UAE, Colombia, and Switzerland.
Cybersecurity
ENCFORGE Ransomware Targets PyTorch, SafeTensors Model Files
Sysdig documented ENCFORGE, a Go ransomware targeting 180 AI file formats including PyTorch, SafeTensors, and GGUF, deployed by the JADEPUFFER threat operator.
CVE Vulnerability Alerts
Qilin Affiliates Exploit PAN-OS CVE-2026-0257 GlobalProtect Bypass
Arctic Wolf documented Qilin affiliates exploiting CVE-2026-0257, a PAN-OS GlobalProtect auth bypass, to gain trusted VPN access for double-extortion attacks.
Cybersecurity
PEAR Ransomware Breach at MCBS Hits 1.26 Million Patients
PEAR ransomware group claimed 3 TB stolen from MCBS, a medical billing firm whose breach exposed 1.26 million patients at seven healthcare organizations.

Threat actors