The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical authentication bypass vulnerability in SimpleHelp, tracked as CVE-2026-48558, which is actively being exploited. This flaw…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding the active exploitation of three vulnerabilities in Cisco's Catalyst SD-WAN Manager, specifically CVE-2026-20122,…
The Gentlemen ransomware, a Go-based RaaS, has been active since mid-2025 and employs aggressive propagation methods. It utilizes 21 remote execution techniques, including PsExec, WMIC, and PowerShell Remoting, to…
Proofpoint has identified a sophisticated crypter service named Cruciferra, first sold in autumn 2025, that is utilized by various cybercriminal groups to cloak malware. The service employs advanced techniques such as…
The Gentlemen ransomware-as-a-service (RaaS) gang has developed a sophisticated suite of endpoint detection and response (EDR) killers, including a tool called GentleKiller, which has at least eight variants. These…
On December 26, 2025, Oltenia Energy Complex, Romania's largest coal-based energy producer, suffered a ransomware attack known as 'Gentlemen'. The attack disrupted the company's IT infrastructure, encrypting several…
The Gentlemen ransomware operation has affected at least 17 countries across the Americas, Asia-Pacific, and the Middle East, targeting sectors such as manufacturing, healthcare, construction, and insurance. This…
The new ransomware group known as 'Gentlemen' has emerged as a significant threat to corporate networks, utilizing a double extortion model that combines data theft with advanced encryption. First identified in August…