Related Threat Clusters
-
Active Exploitation of Vulnerabilities in Ivanti and SolarWinds Products
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding active exploitation of vulnerabilities in Ivanti Endpoint Manager, SolarWinds Web Help Desk, and VMware Workspace ONE. The…
12 articles · Updated March 10, 2026 -
Anubis Ransomware Attack Disrupts Adriatic Port Authority Operations
The Anubis ransomware group launched a cyberattack on the Adriatic Port Authority, crippling operations and causing significant disruptions in maritime logistics. The attack, attributed to Anubis in January 2026,…
8 articles · Updated June 15, 2026 -
Hackers Exploit QEMU VMs to Evade Detection and Deploy Ransomware
Hackers are utilizing QEMU, an open-source virtual machine emulator, to create hidden Linux environments within Windows systems, effectively evading endpoint security tools. This method allows for long-term access,…
8 articles · Updated April 17, 2026 -
Active Exploitation of SolarWinds Web Help Desk Vulnerability CVE-2025-40551
Users of SolarWinds Web Help Desk are at risk due to the active exploitation of vulnerability CVE-2025-40551. This vulnerability was published on January 28, 2026, and was added to CISA's Known Exploited Vulnerabilities…
76 articles · Updated February 5, 2026
Recent Intelligence Reports
- The Anubis Ransomware Attack On The Adriatic Port Authority — www.resecurity.com · June 26, 2026
- Adriatic Port Cyber — Infosecurity-Magazine · June 15, 2026
- Payouts King ransomware uses QEMU VMs to bypass endpoint security — Bleepingcomputer · April 17, 2026
- Attack warning for Ivanti Endpoint Manager, SolarWinds Web Help Desk and more — Heise.De · March 10, 2026
- SolarWinds, again: Critical RCE bugs reopen old wounds for enterprise security teams — Csoonline · January 29, 2026
- SolarWinds warns of critical Web Help Desk RCE, auth bypass flaws — Bleepingcomputer · January 28, 2026