Report Date: 2026-06-19
New KEVs: 0 ▼ -7 vs last weekRansomware Victims: 148 ▼ -15 vs last week
No new vulnerabilities were added to the CISA Known Exploited Vulnerabilities catalog during this reporting window. Threat intelligence sources this period reference Evil Corp. Ransomware activity is moderate with 148 new victims posted to leak sites over the last 7 days, with Thegentlemen posting the most victims.
Top KEVs
No qualifying KEVs were identified in the current reporting window.
Security News
Advisories, threat research, and incident reports from 12 sources across government, commercial research, and security journalism — prioritized by source credibility.
- CISA ICS AdvisoryAdvisory · yesterday – Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products
View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChute™ Serial Shutdown product. The [PowerChute Serial Shutdown](https://www.se.com/ww/en/product-range/137943580-powerchute-serial-shutdown/#p… - CISA ICS AdvisoryAdvisory · yesterday – Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module
View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition in the affected product by continuously sending a large number of communication p… - CISA ICS AdvisoryAdvisory · yesterday – Schneider Electric EasyLogic T150 and Saitel DP
View CSAF Summary Successful exploitation this vulnerability could allow an attacker to gain unauthorized access to sensitive files The following versions of Schneider Electric EasyLogic T150 and Saitel DP are affected: … - SANS ISCResearch · today – eBanking Phishing Delivered Through IPv4-Mapped IPv6 Address, (Fri, Jun 19th)
I detected an interesting phishing email this morning. It targets a major Belgian bank:
 - SANS ISCIncident · yesterday – The Behavior of Coordinated SSH Brute Force Attacks over the last three months [Guest Diary], (Wed, Jun 17th)
[This is a Guest Diary by Adam Nason, an ISC intern as part of the SANS.edu BACS program]
 - Unit 42Research · 3 days ago – Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenant RCE
Unit 42 discovered a Vertex AI Python SDK vulnerability that allows remote code execution via bucket squatting. Read the article for more. The post Pickle in the Middle – Hijacking Vertex AI Model Uploads for Cross-Tenan… - Unit 42Incident · 4 days ago – Inside the Modern SOC: The 72-Minute Race
Attackers can move from access to exfiltration in 72 minutes. Learn how modern SOC teams close the speed gap with Unit 42's AI-driven automation, threat hunting, MDR and Managed XSIAM. The post Inside the Modern SOC: The… - Sophos X-OpsResearch · 2 days ago – AI in the underground: Curiosity, claims, and concerns
Amid discussions about how artificial intelligence can facilitate cybercrime, some threat actors remain skeptical Categories: Threat Research Tags: AI, Dark Web, underground - Sophos X-OpsResearch · 8 days ago – June Patch Tuesday smashes past 500-CVE mark
209 patches + 388 advisories = welcome to summer 2026 Categories: Threat Research Tags: x-ops, Patch Tuesday, MICROSOFT PATCH TUESDAY - The RecordNews · today – Police raid malware network tied to Russia's Evil Corp hacker group
An international operation targeted the SocGholish botnet, which has been linked to the Russia-based cybercrime group Evil Corp. - The RecordNews · yesterday – Australian sugar producer works to restore operations as ransomware group claims attack
Mackay Sugar said it was "working urgently" to verify claims that a highly active ransomware group was behind a cyberattack that shut down harvesting and milling operations. - Security Affairs (APT)News · 2 days ago – China-Linked FishMonger Ports SprySOCKS to Windows With Kernel-Level Stealth and UEFI Bootkit Hints
China-linked FishMonger used two SprySOCKS Windows variants that leveraged kernel drivers and the Print Spooler to target governments in four countries. ESET researchers have found two previously undocumented Windows ver… - Security Affairs (APT)News · 3 days ago – China-linked actor spent two years inside medical research networks
China’s UNC6508 hid in North American medical research networks for 2 years, stealing credentials and forwarding emails to Gmail Google’s Threat Intelligence Group published a report this week on UNC6508, a C… - Security Affairs (Cybercrime)News · today – 14,971 WordPress Sites Cleaned in Global SocGholish Takedown
Operation EndGame disrupted SocGholish, taking down 106 servers and cleaning 14,971 WordPress sites used to spread fake-update malware. On June 18, 2026, law enforcement agencies from the Netherlands, Canada, the United … - Security Affairs (Cybercrime)News · yesterday – FortiBleed Exposes Admin Passwords for 75,000 Fortinet Firewalls
FortiBleed: Admin Passwords for 75,000 Fortinet Firewalls Are Out in the Wild. Half the Internet-Facing Fortinets on the Planet. Security researcher Bob Diachenko found a server sitting open on the internet containing wh…
Ransomware Activity
Victim counts posted to ransomware group leak sites — use this to gauge which groups are most active and which sectors and regions are being targeted.
15 new victims posted today
7-day total: 148 via Ransomware.live
Infostealer Exposure: 1,110 employee credentials and 3,756,776 user credentials compromised via infostealer malware across victim organisations — indicating credential theft likely preceded these ransomware deployments.
Most Active Groups
Group Intelligence
- Thegentlemen — The Gentlemen is a RaaS group that emerged in July–August 2025, rapidly claiming over 320 victims across 17+ countries by offering affiliates a 90% revenue share, deploying a Go-based locker against Windows, Linux, NAS, and BSD systems; a compromised C2 server in 2026 revealed more than 1,570 linked victims.
- Qilin — Qilin ransomware was first observed in July of 2022. Qilin Ransomware is written in Golang and supports multiple encryption modes; all of which are controlled by the operator. Qilin actors practice double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data.
- Shinyhunters — ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members.
- Safepay — SafePay emerged in September 2024 as a rapidly growing ransomware operation that explicitly disavows the RaaS model and manages all operations internally, claiming over 300 victims worldwide by mid-2025 with a high-profile early attack against UK telematics firm Microlise stealing 1.2 TB of data.
- Krybit — Krybit is an emerging RaaS group that launched in late March 2026, offering affiliates an 80/20 revenue split with support for Windows, Linux, ESXi, and NAS device encryption, and became notable for a public feud with rival group 0APT in which each breached and leaked the other's operator data.
Most Targeted Sectors
Top Countries
US (42), DE (13), CA (4), MY (4), SG (4)
Notable Incidents
- www.courdescomptes.sn (Public Sector · SN) — claimed by Krybit. La Cour des Comptes du Sénégal (The Court of Auditors of Senegal) is an independent supreme audit institution of Seneg… Press coverage →
- Prince George County (Public Sector · US) — claimed by Ransomhouse. Prince George County is a local government entity focused on providing essential services and fostering community development. It offers a range of services including public safety, waste management, parks and recreation… Press coverage →
- Mackay Sugar (Agriculture and Food Production · AU) — claimed by Thegentlemen. ***.com.au zoominfo.com/c/mackay-sugar-ltd/1147904633 Mackay Sugar is Australia's second-largest sugar manufacturer, headquartered in tropical North Queensland with over 140 years of rich industry heritage. Owned primari… Press coverage →
- Novo Nordisk (Healthcare · DK) — claimed by Fulcrumsec. [AI generated] Novo Nordisk is a Danish multinational pharmaceutical company headquartered in Bagsværd, Denmark. Founded in 1923, it specializes in treatments for diabetes, obesity, hemophilia, and other chronic conditio… Press coverage →
- Commune d'Eyguires (Public Sector · FR) — claimed by Qilin. N/A Press coverage →
Vendor-Specific Risks
No vendors with confirmed KEV exploitation were identified this reporting window — a quiet week for the KEV catalog.
Stay Ahead
Found this useful? Get the daily report in your reader.
Free. No account. No email. Follow in Feedly, Inoreader, or any RSS reader.