Related Threat Clusters
-
Critical Cisco FMC Vulnerabilities Under Active Exploitation
Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079,…
13 articles · Updated September 9, 2026 -
Critical Check Point VPN Vulnerability Exploited by Ransomware Gang
Check Point Software Technologies disclosed a critical authentication bypass vulnerability (CVE-2026-50751) affecting its Remote Access VPN and Mobile Access products, with exploitation confirmed since May 7, 2026. The…
46 articles · Updated June 8, 2026 -
Qilin Ransomware Targets TaLachaim, Quasar, and Z-Tronix
Qilin ransomware has attacked multiple organizations, including TaLachaim, Quasar, and Z-Tronix, leading to unauthorized access to databases and sensitive information leaks. The attacks also involved DDoS attacks and…
1 article · Updated December 31, 2025 -
CISA Issues Urgent Directive to Patch Check Point VPN Vulnerability Exploited by Ransomware
CISA has mandated federal agencies to patch a critical vulnerability in Check Point VPN products within 72 hours due to active exploitation by the Qilin ransomware group. The vulnerability, tracked as CVE-2026-42271,…
8 articles · Updated June 9, 2026 -
Iranian APT MuddyWater Uses Chaos Ransomware as a False Flag for Espionage
In early 2026, the Iranian APT group MuddyWater, affiliated with the Ministry of Intelligence and Security, executed a sophisticated cyber operation disguised as a Chaos ransomware attack. Utilizing social engineering…
17 articles · Updated May 7, 2026 -
US Treasury Sanctions VPN and Malware Providers for Ransomware Support
On July 13, 2026, the U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned First VPN Service (1VPNS), its administrator Dmytro Rashevskyi, and malware provider Yegeniy Vladimirovich Silayev for enabling…
35 articles · Updated July 13, 2026 -
Qilin Ransomware Gang Exploits Critical Palo Alto VPN Vulnerability
The Qilin ransomware gang is actively exploiting a critical authentication bypass vulnerability (CVE-2026-0257) in Palo Alto Networks' PAN-OS GlobalProtect VPN software. This flaw allows attackers to bypass security…
17 articles · Updated July 21, 2026 -
Multiple Ransomware Attacks Target Diverse Industries in September 2026
In early September 2026, several ransomware groups executed attacks on various organizations, including Krybit's assault on Reignwood Park Thailand and Arab Maritime Petroleum Transport Company, Everest's attack on…
22 articles · Updated September 3, 2026 -
Data Breach at Manchester Airports Group Affects 8.7 Million Customers
The Manchester Airports Group (MAG) reported a cyber security incident affecting approximately 8.7 million customers across its three airports: Manchester, London Stansted, and East Midlands. The breach involved…
84 articles · Updated August 27, 2026 -
US, UK, and Australia Sanction Russian Cyber Firm Media Land for Ransomware Links
On November 19, 2025, the United States, United Kingdom, and Australia announced coordinated sanctions against the Russian web company Media Land, accusing it of facilitating ransomware operations. The sanctions include…
88 articles · Updated November 19, 2025
Recent Intelligence Reports
- Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers — Bleepingcomputer · September 10, 2026
- Three Threat Actor Clusters Including Sandworm Are Actively Exploiting Cisco FMC's CVSS ... — Forkast.News · September 10, 2026
- Organizations Warned of Cisco Secure FMC Exploitation — Securityweek · September 10, 2026
- DeXpose cybersecurity monitors — www.dexpose.io · September 4, 2026
- UK airports cyber attack exposes 8.7M customers' data — Cybernews · August 28, 2026
- Palo Alto Networks PAN — Filestore.Fortinet · July 21, 2026
- OFAC Sanctions FirstVPN and Ransomware Enablers Behind Attacks on Americans — Trmlabs · July 14, 2026
- CISA Gives Feds 3 Days to Patch Check Point VPN Bug Exploited as Zero — Ground.News · June 9, 2026