Fog is a ransomware_group tracked across 7 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity June 23, 2026.
Fog is a ransomware group known for running double-extortion campaigns and operating under a ransomware-as-a-service model with affiliate involvement. It typically targets enterprise networks by obtaining initial access and exfiltrating data before encryption, contributing to the ongoing evolution of ransomware threat activity. The current reporting ties focus to Cisco firewall exploit activity, underscoring Fog’s relevance in discussions about opportunistic network compromise and ransomware deployment.
CVE-2024-40766 is an improper access control vulnerability in SonicWall SonicOS affecting Gen 5, Gen 6, and Gen 7 firewalls. The vulnerability, with a CVSS score of 9.3, allows unauthorized access and can crash the…
Veeam has disclosed a critical vulnerability (CVE-2026-44963) affecting its Backup & Replication software, allowing authenticated domain users to execute remote code on domain-joined backup servers. This flaw impacts…
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
The Fog ransomware variant has been identified as a significant threat to US organizations, particularly in the education and recreation sectors. Since early May 2024, Arctic Wolf Labs has reported that 80% of affected…
Veeam has issued security updates to address multiple vulnerabilities in its Backup & Replication software, including a critical remote code execution (RCE) flaw tracked as CVE-2025-59470. This vulnerability affects…
Cisco Systems has issued a warning regarding a new attack variant targeting its Secure Firewall devices, leveraging vulnerabilities CVE-2025-20333 and CVE-2025-20362. These vulnerabilities could potentially lead to…
Cisco has reported ongoing attacks against its firewalls, specifically targeting vulnerabilities CVE-2025-20333 and CVE-2025-20362. These flaws allow remote code execution and unauthorized access, leading to potential…