Related Threat Clusters
-
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
SonicWall has reported two critical vulnerabilities, CVE-2026-15409 and CVE-2026-15410, affecting its SMA1000 Series appliances, which are currently being actively exploited. The first vulnerability, CVE-2026-15409, is…
62 articles · Updated July 15, 2026 -
Akira Ransomware Group Targets Critical Infrastructure, Extracts $42 Million
The Akira ransomware group has been identified as a significant threat to critical infrastructure, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the FBI warning of its active ransomware…
9 articles · Updated November 14, 2025 -
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
Exploitation of Remote Services in Cyber Attacks
Adversaries are increasingly leveraging external remote services like VPNs and Citrix to gain unauthorized access to networks. These attacks often involve using valid accounts obtained through credential harvesting or…
2 articles · Updated June 3, 2026 -
Ransomware Group Targets SonicWall Gen 7 Firewalls via CVE-2024-40766
In June 2026, a surge in attacks targeting SonicWall Gen 7 firewalls has been reported, exploiting CVE-2024-40766, an improper access control flaw. This vulnerability allows threat actors to gain unauthorized access,…
2 articles · Updated June 23, 2026 -
CVE-2024-40766 Exploited by Ransomware Groups Targeting SonicWall Firewalls
CVE-2024-40766 is an improper access control vulnerability in SonicWall SonicOS affecting Gen 5, Gen 6, and Gen 7 firewalls. The vulnerability, with a CVSS score of 9.3, allows unauthorized access and can crash the…
2 articles · Updated June 23, 2026 -
Global Law Enforcement Dismantles AudiA6 Crypto Laundering Network
On June 11, 2026, international law enforcement agencies, including the U.S. Secret Service and Europol, announced the dismantling of the AudiA6 cryptocurrency laundering network, which laundered over $389 million from…
20 articles · Updated June 11, 2026 -
SonicWall SSL VPN Vulnerability CVE-2024-12802 Actively Exploited Despite Patching
A wave of attacks exploiting CVE-2024-12802, an authentication bypass vulnerability in SonicWall SSL VPN appliances, began in February 2026. Despite a firmware patch issued in 2025, attackers were able to bypass…
6 articles · Updated May 19, 2026 -
Critical RCE Vulnerability in Veeam Backup Exposes Organizations to Attacks
Veeam has disclosed a critical vulnerability (CVE-2026-44963) affecting its Backup & Replication software, allowing authenticated domain users to execute remote code on domain-joined backup servers. This flaw impacts…
11 articles · Updated June 9, 2026 -
Marquis Software Solutions Data Breach Exposes Customer Data of US Banks
Marquis Software Solutions experienced a ransomware attack on August 14, 2025, leading to the exposure of sensitive customer information, including Social Security Numbers and names. The company serves numerous banks…
6 articles · Updated December 3, 2025
Recent Intelligence Reports
- Node Js Returns Ransomware — www.security.com · September 3, 2026
- Node.js: Old Technique Makes a Comeback — Security · September 3, 2026
- Industrial cyber incidents climb 12% as cover gap widens — Insurancebusinessonline.Au · August 17, 2026
- Industrial cyber incidents climbs 12% as cover gap widens — Insurancebusinessmag · August 17, 2026
- Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt — Bleepingcomputer · August 13, 2026
- Akira Affiliate Crashes Ransomware After Attempting EDR Evasion — Infosecurity-Magazine · August 13, 2026
- Akira ransomware attacker uses Safe Mode reboot to evade EDR | news — Scworld · August 12, 2026
- Akira Hits Safe Mode: Ransomware Rebooting Around EDR — Huntress · August 12, 2026