SMB is a technology platform tracked across 15 threat clusters and 13 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity July 7, 2026.
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
A local privilege escalation vulnerability named 'CIFSwitch' has been discovered in the Linux kernel, enabling low-privileged users to gain root access. This flaw affects multiple Linux distributions that use vulnerable…
The WantToCry ransomware campaign exploits exposed Server Message Block (SMB) services to remotely encrypt files without deploying malware on victim systems. Attackers scan for open SMB ports and use brute-force methods…
DragonForce, a new ransomware operation derived from Conti's leaked source code, has emerged with a cartel-like structure. The group retains Conti's core encryption and network-spreading capabilities while recruiting…
In 2025, ransomware groups Medusa and DragonForce targeted UK organizations by exploiting three critical vulnerabilities in the SimpleHelp Remote Monitoring and Management platform. These vulnerabilities…
Microsoft has published information on two critical vulnerabilities affecting SMB protocol implementations. CVE-2024-46742 relates to a potential null pointer dereference in the server component, while CVE-2024-46686…
Microsoft has published updates addressing deadlock issues in two components: SMB and HNS3. CVE-2025-38244, published on July 9, 2025, resolves a potential deadlock when reconnecting SMB channels, while CVE-2024-44995,…
Microsoft has published information on two vulnerabilities affecting the SMB client. CVE-2023-52434, published on February 20, 2024, addresses potential out-of-bounds issues in the smb2_parse_contexts() function.…
The Sophos State of Ransomware in Enterprise 2025 report reveals that ransomware recovery costs for enterprises have exceeded $2 million, highlighting the ongoing challenge organizations face with this pervasive threat.…
The Vortex Werewolf cyber espionage group has been actively targeting Russian government and defense organizations since at least December 2025. This group utilizes social engineering and legitimate software utilities…