Related Threat Clusters
-
Critical RCE Vulnerabilities Under Active Exploitation
Multiple critical vulnerabilities are currently being exploited, including remote code execution (RCE) flaws in HPE AOS-CX (CVE-2026-73749), Citrix NetScaler (CVE-2026-19490), Sangoma Switchvox (CVE-2026-9586), and…
2 articles · Updated September 6, 2026 -
Critical Cleo Harmony Vulnerability Exploited for Privilege Escalation
A newly discovered authentication bypass vulnerability in Cleo Harmony, tracked as CVE-2026-84115, allows remote attackers to escalate privileges by manipulating JWT refresh tokens. The flaw, found in the…
6 articles · Updated September 2, 2026 -
PaperCut NG/MF Vulnerability Under Active Exploitation
On August 27, 2026, PaperCut issued an urgent advisory regarding a zero-day vulnerability affecting its NG and MF print management software. This flaw allows unauthenticated attackers to execute arbitrary Java code…
60 articles · Updated August 27, 2026 -
Critical Exploitation of Ruby on Rails Vulnerability CVE-2026-66066 Confirmed
Threat actors are actively exploiting CVE-2026-66066, a critical Ruby on Rails vulnerability known as KindaRails2Shell, which allows unauthenticated attackers to read arbitrary files from servers, potentially leading to…
5 articles · Updated August 31, 2026 -
Exploitation of PaperCut Vulnerabilities Threatens Educational Institutions
Attackers are exploiting two recently disclosed vulnerabilities in PaperCut, CVE-2026-81578 and CVE-2026-82078, to steal credentials and gain privileged access in educational institutions across the U.S. and Europe. The…
6 articles · Updated September 5, 2026 -
RevStealer Malware Distributed via Fake Claude Opus 5 App
RevStealer, a new Windows infostealer, is being distributed through a malicious GitHub repository masquerading as a free version of Anthropic's Claude Opus 5. This malware targets sensitive data such as passwords,…
7 articles · Updated August 31, 2026 -
Ransomware Fuels Surge in Global Cyberattacks
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
1922 articles · Updated February 12, 2026 -
Clop Ransomware Group Breaches University of Phoenix Data of 3.5 Million
The University of Phoenix experienced a data breach affecting 3.5 million individuals, attributed to the Clop ransomware group exploiting a zero-day vulnerability in Oracle's enterprise software. The attackers accessed…
3 articles · Updated December 30, 2025 -
Clop Ransomware Targets Gladinet CentreStack Servers for Data Theft
The Clop ransomware group is conducting a data extortion campaign against Gladinet CentreStack file servers. This attack exploits multiple security vulnerabilities in CentreStack and its related product, Triofox,…
6 articles · Updated December 19, 2025 -
Vali Cyber Enhances Hypervisor Security with ZeroLock 5 and CrowdStrike Integration
Vali Cyber announced the release of ZeroLock 5, focusing on hypervisor security, particularly against insider threats and credential theft. The hypervisor layer has become a primary target for ransomware operators and…
2 articles · Updated September 2, 2026
Recent Intelligence Reports
- [SecurityIntel] 06 Sep | Active Zero — Buttondown · September 6, 2026
- PaperCut Flaws Exploited in Attacks on U.S. and European Schools — cybernoz.com · September 6, 2026
- Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities — Ground.News · September 5, 2026
- PaperCut Flaws Exploited in Attacks on U.S. and European Schools — Securityaffairs.Co · September 5, 2026
- Exploit Published for Fresh Cleo Harmony Vulnerability — Securityweek · September 2, 2026
- Vali Cyber ZeroLock 5 brings MFA to the hypervisor command line — Helpnetsecurity · September 2, 2026
- Fake Claude Opus 5 app delivers malware and wipes its own tracks — Helpnetsecurity · September 1, 2026
- Critical Ruby on Rails Vulnerability in Attackers' Crosshairs — Securityweek · August 31, 2026