Malware 2026-09-07
Malware & phishing activity digest — 2026-09-07
324 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Automated daily updates on newly exploited vulnerabilities, ransomware activity and malware indicators — from public sources.
Malware 2026-09-07
324 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-07
10 organizations were newly listed on ransomware leak sites, with the most active groups being dragonforce, Panzer, direwolf. Figures are aggregated from public
Malware 2026-09-06
274 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-06
21 organizations were newly listed on ransomware leak sites, with the most active groups being qilin, thegentlemen, pear. Figures are aggregated from public lea
Malware 2026-09-05
392 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-05
24 organizations were newly listed on ransomware leak sites, with the most active groups being qilin, lockbit5, Vexy Ransomware. Figures are aggregated from pub
Vulnerability 2026-09-04
CVE-2026-85046 (Google Chromium V8 Type Confusion Vulnerability) affecting Google was added to CISA's Known Exploited Vulnerabilities catalog, indicating active
Malware 2026-09-04
319 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-04
28 organizations were newly listed on ransomware leak sites, with the most active groups being settra, Storm, SilentRansomGroup. Figures are aggregated from pub
Malware 2026-09-03
498 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-03
27 organizations were newly listed on ransomware leak sites, with the most active groups being incransom, akira, SilentRansomGroup. Figures are aggregated from
Vulnerability 2026-09-02
CVE-2026-83549 (SonicWall SMA1000 Appliances OS Command Injection Vulnerability) affecting SonicWall was added to CISA's Known Exploited Vulnerabilities catalog
Vulnerability 2026-09-02
CVE-2026-83548 (SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability) affecting SonicWall was added to CISA's Known Exploited Vulnerabilities
Vulnerability 2026-09-02
CVE-2026-9586 (Sangoma Switchvox SQL Injection Vulnerability) affecting Sangoma was added to CISA's Known Exploited Vulnerabilities catalog, indicating active e
Vulnerability 2026-09-02
CVE-2026-82329 (JFrog Artifactory Improper Authentication Vulnerability) affecting JFrog was added to CISA's Known Exploited Vulnerabilities catalog, indicating
Vulnerability 2026-09-02
CVE-2026-49869 (Kestra OSS OS Command Injection Vulnerability) affecting Kestra was added to CISA's Known Exploited Vulnerabilities catalog, indicating active e
Vulnerability 2026-09-02
CVE-2026-48710 (Kludex Starlette HTTP Request/Response Smuggling Vulnerability) affecting Kludex was added to CISA's Known Exploited Vulnerabilities catalog, in
Vulnerability 2026-09-02
CVE-2026-59822 (BerriAI LiteLLM Improper Authentication Vulnerability) affecting BerriAI was added to CISA's Known Exploited Vulnerabilities catalog, indicating
Malware 2026-09-02
439 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-02
38 organizations were newly listed on ransomware leak sites, with the most active groups being krybit, thegentlemen, akira. Figures are aggregated from public l
Malware 2026-09-01
428 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-09-01
52 organizations were newly listed on ransomware leak sites, with the most active groups being settra, BrainCipher, lockbit5. Figures are aggregated from public
Vulnerability 2026-08-31
CVE-2026-81578 (PaperCut NG/MF Missing Authentication for Critical Function Vulnerability) affecting PaperCut was added to CISA's Known Exploited Vulnerabilitie
Vulnerability 2026-08-31
CVE-2026-82078 (PaperCut NG/MF Unsafe Reflection Vulnerability) affecting PaperCut was added to CISA's Known Exploited Vulnerabilities catalog, indicating activ
Malware 2026-08-31
374 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-08-31
45 organizations were newly listed on ransomware leak sites, with the most active groups being ZaWoo, thegentlemen, qilin. Figures are aggregated from public le
Malware 2026-08-30
359 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-08-30
23 organizations were newly listed on ransomware leak sites, with the most active groups being qilin, iah6477, incransom. Figures are aggregated from public lea
Malware 2026-08-29
422 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-08-29
30 organizations were newly listed on ransomware leak sites, with the most active groups being qilin, global, akira. Figures are aggregated from public leak-sit
Malware 2026-08-28
450 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-08-28
40 organizations were newly listed on ransomware leak sites, with the most active groups being qilin, Storm, medusalocker. Figures are aggregated from public le
Vulnerability 2026-08-27
CVE-2026-66384 (JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability) affecting JFrog was added to CISA's Known Exploited
Vulnerability 2026-08-27
CVE-2026-53362 (Linux Kernel Unspecified Vulnerability) affecting Linux was added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitat
Vulnerability 2026-08-27
CVE-2023-49105 (ownCloud Improper Authentication Vulnerability) affecting ownCloud was added to CISA's Known Exploited Vulnerabilities catalog, indicating activ
Malware 2026-08-27
452 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-08-27
46 organizations were newly listed on ransomware leak sites, with the most active groups being krybit, qilin, SilentRansomGroup. Figures are aggregated from pub
Vulnerability 2026-08-26
CVE-2019-1068 (Microsoft SQL Server Remote Code Execution Vulnerability) affecting Microsoft was added to CISA's Known Exploited Vulnerabilities catalog, indica
Vulnerability 2026-08-26
CVE-2026-8452 (Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability) affecting Citri
Vulnerability 2026-08-26
CVE-2022-0995 (Linux Kernel Out-of-Bounds Write Vulnerability) affecting Linux was added to CISA's Known Exploited Vulnerabilities catalog, indicating active ex
Vulnerability 2026-08-26
CVE-2015-5287 (Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability) affecting Red Hat was added to CISA's Known Exploited Vulnerabilities ca
Vulnerability 2026-08-26
CVE-2015-3246 (Red Hat Libuser Race Condition Vulnerability) affecting Red Hat was added to CISA's Known Exploited Vulnerabilities catalog, indicating active ex
Vulnerability 2026-08-26
CVE-2021-23758 (Ajax.NET Professional Deserialization of Untrusted Data Vulnerability) affecting Ajax.NET Professional was added to CISA's Known Exploited Vulne
Malware 2026-08-26
351 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-08-26
27 organizations were newly listed on ransomware leak sites, with the most active groups being qilin, ShadowByt3$, Global Secret Group. Figures are aggregated f
Vulnerability 2026-08-25
CVE-2026-60004 (Gitea Code Injection Vulnerability) affecting Gitea was added to CISA's Known Exploited Vulnerabilities catalog, indicating active exploitation
Malware 2026-08-25
407 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-08-25
29 organizations were newly listed on ransomware leak sites, with the most active groups being dragonforce, Booba Project, Dark Project. Figures are aggregated
Vulnerability 2026-08-24
CVE-2026-21962 (Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability) affecting Oracle was added to CISA's Known Ex
Malware 2026-08-24
273 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-08-24
50 organizations were newly listed on ransomware leak sites, with the most active groups being kazu, qilin, metaencryptor. Figures are aggregated from public le
Malware 2026-08-23
411 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-08-23
28 organizations were newly listed on ransomware leak sites, with the most active groups being coinbasecartel, spacebears, shinyhunters. Figures are aggregated
Malware 2026-08-22
349 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-08-22
48 organizations were newly listed on ransomware leak sites, with the most active groups being thegentlemen, direwolf, qilin. Figures are aggregated from public
Vulnerability 2026-08-21
CVE-2026-73570 (Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability) affecting Synacor was added to CISA's Known Exploited Vulnerabilities catal
Malware 2026-08-21
379 new malicious URLs and indicators were observed from public threat-intelligence feeds (abuse.ch URLHaus).
Ransomware 2026-08-21
45 organizations were newly listed on ransomware leak sites, with the most active groups being titan, DYSPHOR1A, everest. Figures are aggregated from public lea
Vulnerability 2026-08-20
CVE-2026-72529 (TrueConf Server Missing Authentication for Critical Function Vulnerability) affecting TrueConf was added to CISA's Known Exploited Vulnerabiliti
Vulnerability 2026-08-20
CVE-2026-72530 (TrueConf Server Code Injection Vulnerability) affecting TrueConf was added to CISA's Known Exploited Vulnerabilities catalog, indicating active
Run a free security report for any domain.
Get your free report