Report Date: 2026-06-18
New KEVs: 0 ▼ -7 vs last weekRansomware Victims: 163 ▲ +17 vs last week
No new vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog during this reporting window. Threat intelligence sources this period reference DragonForce. Ransomware activity is moderate with 163 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.
Top KEVs
No qualifying KEVs were identified in the current reporting window.
Security News
Advisories, threat research, and incident reports from 12 sources across government, commercial research, and security journalism — prioritized by source credibility.
- CISA ICS AdvisoryAdvisory · today – Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products
View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChute™ Serial Shutdown product. The [PowerChute Serial Shutdown](https://www.se.com/ww/en/product-range/137943580-powerchute-serial-shutdown/#p… - CISA ICS AdvisoryAdvisory · today – Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module
View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition in the affected product by continuously sending a large number of communication p… - CISA ICS AdvisoryAdvisory · today – Schneider Electric EasyLogic T150 and Saitel DP
View CSAF Summary Successful exploitation this vulnerability could allow an attacker to gain unauthorized access to sensitive files The following versions of Schneider Electric EasyLogic T150 and Saitel DP are affected: … - SANS ISCIncident · today – The Behavior of Coordinated SSH Brute Force Attacks over the last three months [Guest Diary], (Wed, Jun 17th)
[This is a Guest Diary by Adam Nason, an ISC intern as part of the SANS.edu BACS program]
 - Unit 42Research · 2 days ago – Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE
Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more. The post Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenan… - Unit 42Incident · 3 days ago – Inside the Modern SOC: The 72-Minute Race
Attackers can move from access to exfiltration in 72 minutes. Learn how modern SOC teams close the speed gap with Unit 42's AI-driven automation, threat hunting, MDR and Managed XSIAM. The post Inside the Modern SOC: The… - Sophos X-OpsResearch · yesterday – AI in the underground: Curiosity, claims, and concerns
Amid discussions about how artificial intelligence can facilitate cybercrime, some threat actors remain skeptical Categories: Threat Research Tags: AI, Dark Web, underground - Sophos X-OpsResearch · 7 days ago – June Patch Tuesday smashes past 500-CVE mark
209 patches + 388 advisories = welcome to summer 2026 Categories: Threat Research Tags: x-ops, Patch Tuesday, MICROSOFT PATCH TUESDAY - The RecordNews · today – Australian sugar producer works to restore operations as ransomware group claims attack
Mackay Sugar said it was "working urgently" to verify claims that a highly active ransomware group was behind a cyberattack that shut down harvesting and milling operations. - The RecordIncident · yesterday – Hostile states behind three-quarters of attacks on Britain's critical infrastructure, cyber chief warns
NCSC CEO Richard Horne warned that âkinetic targeting in any conflict tomorrow will be based on intelligence gathered todayâ and that nation-state adversaries were âprepositioningâ throughout British critical inf… - Security Affairs (APT)News · yesterday – China-Linked FishMonger Ports SprySOCKS to Windows With Kernel-Level Stealth and UEFI Bootkit Hints
China-linked FishMonger used two SprySOCKS Windows variants that leveraged kernel drivers and the Print Spooler to target governments in four countries. ESET researchers have found two previously undocumented Windows ver… - Security Affairs (APT)News · 2 days ago – China-linked actor spent two years inside medical research networks
China’s UNC6508 hid in North American medical research networks for 2 years, stealing credentials and forwarding emails to Gmail Google’s Threat Intelligence Group published a report this week on UNC6508, a C… - Security Affairs (Cybercrime)News · today – FortiBleed Exposes Admin Passwords for 75,000 Fortinet Firewalls
FortiBleed: Admin Passwords for 75,000 Fortinet Firewalls Are Out in the Wild. Half the Internet-Facing Fortinets on the Planet. Security researcher Bob Diachenko found a server sitting open on the internet containing wh… - Security Affairs (Cybercrime)News · yesterday – DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two Months
DragonForce hid for months by routing malware traffic through Microsoft Teams infrastructure, masking C2 activity and evading network detection. DragonForce ransomware operators hit a major U.S. services firm and stayed … - Bleeping ComputerNews · today – Gentlemen ransomware uses multiple EDR killers to disable defenses
The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks. […]
Ransomware Activity
Victim counts posted to ransomware group leak sites — use this to gauge which groups are most active and which sectors and regions are being targeted.
24 new victims posted today
7-day total: 163 via Ransomware.live
Infostealer Exposure: 1,226 employee credentials and 3,757,444 user credentials compromised via infostealer malware across victim organisations — indicating credential theft likely preceded these ransomware deployments.
Most Active Groups
Group Intelligence
- Thegentlemen — The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
- Shinyhunters — ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members.
- Qilin — Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
- Safepay — SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data.
- Dragonforce — DragonForce is a major ransomware-as-a-service operation first observed in August 2023 that launched a formal affiliate program offering 80% revenue share, then rebranded as a "ransomware cartel" in 2025, gaining notoriety for high-profile attacks on UK retailers Marks & Spencer, Co-op, and Harrods.
Most Targeted Sectors
Top Countries
US (47), DE (14), SG (4), MY (4), IT (4)
Notable Incidents
- Prince George County (Public Sector · US) — claimed by Ransomhouse. Prince George County is a local government entity focused on providing essential services and fostering community development. It offers a range of services including public safety, waste management, parks and recreation… Press coverage →
- Mackay Sugar (Agriculture and Food Production · AU) — claimed by Thegentlemen. ***.com.au zoominfo.com/c/mackay-sugar-ltd/1147904633 Mackay Sugar is Australia's second-largest sugar manufacturer, headquartered in tropical North Queensland with over 140 years of rich industry heritage. Owned primari… Press coverage →
- Novo Nordisk (Healthcare · DK) — claimed by Fulcrumsec. [AI generated] Novo Nordisk is a Danish multinational pharmaceutical company headquartered in Bagsværd, Denmark. Founded in 1923, it specializes in treatments for diabetes, obesity, hemophilia, and other chronic conditio… Press coverage →
- GITHUB INTERNAL (Technology · US) — claimed by Lapsus$. Everything for the main platform is there. No ransom, we do not care about extorting Github. If no buyer is found, we leak for free. Press coverage →
- musenet.co.jp (Technology · JP) — claimed by Safepay. Founded in the twentieth century, the company serves as an intermediary between publishers and music retailers throughout Japan. Its online … Press coverage →
Vendor-Specific Risks
No vendors with confirmed KEV exploitation were identified this reporting window — a quiet week for the KEV catalog.
Stay Ahead
Found this useful? Get the daily report in your reader.
Free. No account. No email. Follow in Feedly, Inoreader, or any RSS reader.