Report Date: 2026-06-17
New KEVs: 0 ▼ -6 vs last weekRansomware Victims: 187 ▲ +44 vs last week
No new vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog during this reporting window. Threat intelligence sources this period reference DragonForce. Ransomware activity is moderate with 187 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.
Top KEVs
No qualifying KEVs were identified in the current reporting window.
Security News
Advisories, threat research, and incident reports from 12 sources across government, commercial research, and security journalism — prioritized by source credibility.
- CISA ICS AdvisoryAdvisory · yesterday – Rockwell Automation CompactLogix
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix are affected: CompactLogix 537… - CISA ICS AdvisoryAdvisory · yesterday – Rockwell Automation FactoryTalk Analytics PavilionX
View CSAF Summary Successful exploitation of this vulnerability could result in an attacker executing privileged operations. The following versions of Rockwell Automation FactoryTalk Analytics PavilionX are affected: Fac… - CISA ICS AdvisoryAdvisory · yesterday – Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP
View CSAF Summary Successful exploitation of this vulnerability could cause a denial-of-service condition that may result in a major nonrecoverable fault (MNRF). The following versions of Rockwell Automation Logix 5370 &… - Unit 42Research · yesterday – Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE
Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more. The post Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenan… - Unit 42Incident · 2 days ago – Inside the Modern SOC: The 72-Minute Race
Attackers can move from access to exfiltration in 72 minutes. Learn how modern SOC teams close the speed gap with Unit 42's AI-driven automation, threat hunting, MDR and Managed XSIAM. The post Inside the Modern SOC: The… - Sophos X-OpsResearch · today – AI in the underground: Curiosity, claims, and concerns
Amid discussions about how artificial intelligence can facilitate cybercrime, some threat actors remain skeptical Categories: Threat Research Tags: AI, Dark Web, underground - Sophos X-OpsResearch · 6 days ago – June Patch Tuesday smashes past 500-CVE mark
209 patches + 388 advisories = welcome to summer 2026 Categories: Threat Research Tags: x-ops, Patch Tuesday, MICROSOFT PATCH TUESDAY - The RecordIncident · today – Hostile states behind three-quarters of attacks on Britain's critical infrastructure, cyber chief warns
NCSC CEO Richard Horne warned that âkinetic targeting in any conflict tomorrow will be based on intelligence gathered todayâ and that nation-state adversaries were âprepositioningâ throughout British critical inf… - The RecordIncident · today – EU grants Ukraine access to cybersecurity reserve for major attacks
As Kyiv takes steps toward formal accession to the EU, the bloc is integrating Ukraine with its pool of pre-approved cybersecurity incident response companies. - Security Affairs (APT)News · today – China-Linked FishMonger Ports SprySOCKS to Windows With Kernel-Level Stealth and UEFI Bootkit Hints
China-linked FishMonger used two SprySOCKS Windows variants that leveraged kernel drivers and the Print Spooler to target governments in four countries. ESET researchers have found two previously undocumented Windows ver… - Security Affairs (APT)News · yesterday – China-linked actor spent two years inside medical research networks
China’s UNC6508 hid in North American medical research networks for 2 years, stealing credentials and forwarding emails to Gmail Google’s Threat Intelligence Group published a report this week on UNC6508, a C… - Security Affairs (Cybercrime)News · today – DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two Months
DragonForce hid for months by routing malware traffic through Microsoft Teams infrastructure, masking C2 activity and evading network detection. DragonForce ransomware operators hit a major U.S. services firm and stayed … - Security Affairs (Cybercrime)Research · today – New Rokarolla Android Trojan Targets 217 Banking and Crypto Apps
Rokarolla Android malware targets 217 banking and crypto apps, steals credentials, blocks bank calls, intercepts SMS, and disables Play Protect. Zimperium’s zLabs researchers have published a detailed analysis of R… - Bleeping ComputerNews · today – FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.
A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide. […] - The Hacker NewsNews · today – Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments
An unknown threat actor has been observed leveraging paid or promoted posts on legitimate news websites to drum up buzz for their warez, according to new findings from Check Point Research. The threat actor also has at t…
Ransomware Activity
Victim counts posted to ransomware group leak sites — use this to gauge which groups are most active and which sectors and regions are being targeted.
16 new victims posted today
7-day total: 187 via Ransomware.live
Infostealer Exposure: 1,239 employee credentials and 3,763,759 user credentials compromised via infostealer malware across victim organisations — indicating credential theft likely preceded these ransomware deployments.
Most Active Groups
Group Intelligence
- Thegentlemen — The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
- Shinyhunters — ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members.
- Dragonforce — DragonForce is a major ransomware-as-a-service operation first observed in August 2023 that launched a formal affiliate program offering 80% revenue share, then rebranded as a "ransomware cartel" in 2025, gaining notoriety for high-profile attacks on UK retailers Marks & Spencer, Co-op, and Harrods.
- Safepay — SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data.
- Threeam — A new Ransomware family identified by the name '3AM' or 'ThreeAM' in September 2023. The ransomware operation was observed by the Symantec team, in which a ransomware affiliate attempted to deploy another ransomware, LockBit, on the target network and then switched to 3AM when LockBit was reportedly blocked.<BR>
> <BR>
> The ransomware operation, according to the publication on its Tor-based website, has been operating since mid-August 2023, according to the publication from its first victim.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
Most Targeted Sectors
Top Countries
US (44), DE (18), JP (6), BR (6), AR (5)
Notable Incidents
- Mackay Sugar (Agriculture and Food Production · AU) — claimed by Thegentlemen. ***.com.au zoominfo.com/c/mackay-sugar-ltd/1147904633 Mackay Sugar is Australia's second-largest sugar manufacturer, headquartered in tropical North Queensland with over 140 years of rich industry heritage. Owned primari… Press coverage →
- Novo Nordisk (Healthcare · DK) — claimed by Fulcrumsec. [AI generated] Novo Nordisk is a Danish multinational pharmaceutical company headquartered in Bagsværd, Denmark. Founded in 1923, it specializes in treatments for diabetes, obesity, hemophilia, and other chronic conditio… Press coverage →
- elumax.com (Not Found · DE) — claimed by Lockbit5. Lumax International Corp. is a Taiwanese supplier of industrial solutions and equipment, founded in… Press coverage →
- GITHUB INTERNAL (Technology · US) — claimed by Lapsus$. Everything for the main platform is there. No ransom, we do not care about extorting Github. If no buyer is found, we leak for free. Press coverage →
- delano.k12.mn.us (Education · US) — claimed by Lockbit5. Delano Public Schools is dedicated to providing systemic growth toward educational excellence for ev… Press coverage →
Vendor-Specific Risks
No vendors with confirmed KEV exploitation were identified this reporting window — a quiet week for the KEV catalog.
Stay Ahead
Found this useful? Get the daily report in your reader.
Free. No account. No email. Follow in Feedly, Inoreader, or any RSS reader.