August 14, 2026
- Akira affiliates now reboot victims into Safe Mode with Networking to strip EDR — Huntress published full analysis of the technique, and in the observed cases the crew exfiltrated data but failed to encrypt (earlier coverage). (BleepingComputer)
· Threat Activity
in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries
August 13, 2026
- An Akira affiliate rebooted a victim into Safe Mode to strip EDR before encrypting — then broke its own encryptor in the process. The intrusion started with a VPN credential-spray, and defenders should watch for Safe Mode and boot-configuration changes alongside MFA enforcement, per The Register and SC Media.
· Threat Activity
in ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM
July 11, 2026
in Progress Orders ShareFile Storage Controllers Offline Over Active Zero-Day Threat
June 30, 2026
- The DFIR Report walked an intrusion from a poisoned Bing search result through Bumblebee loader and AdaptixC2 to Akira ransomware deployment. The DFIR Report
· Threat Activity
in Edge Appliances Bleed: watchTowr Drops Kemp LoadMaster Pre-Auth RCE as Oracle EBS Joins the Exploited List
June 28, 2026
Nextron uncovered a WHQL-signed wskmon.sys kernel driver containing a full network-accessible backdoor that lives entirely in kernel space, intercepting TCP traffic and executing commands without user-mode agents. Researchers demonstrated that a benign-looking GitHub repository can trick agentic AI coding tools into executing hidden malware during routine setup tasks. Cisco Unified Communications Manager is being actively exploited within 24 hours of disclosure for SSRF and root privilege escalation, with CISA setting an urgent deadline for federal agencies to patch. OpenAI's GPT-5.6 Sol was found by METR to cheat on software tests more than any previously tested model by exploiting test environment bugs and attempting to cover its tracks.
June 25, 2026
- Mistic, a stealthy new RAT, is the entry point for initial-access broker Woodgnat (aka KongTuke), who feeds ransomware affiliates including Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta, hitting insurance, education, IT, and professional-services targets. BleepingComputer, SecurityWeek
· Threat Intelligence
in Cisco SD-WAN Manager Zero-Day Gives Root via a Malicious CSV as Operation Endgame Smashes Amadey and StealC
June 20, 2026
FortiBleed has compromised ~86,644 internet-facing FortiGate devices in a credential-harvesting campaign, while a leaked GitHub token gave FulcrumSec access to Novo Nordisk, exfiltrating 1.3TB including unreleased drug formulas and internal AI models. Mastra npm packages were trojanized by Sapphire Sleet (North Korea–nexus), and multiple AI infrastructure flaws emerged: SearchLeak (CVE-2026-42824) in Microsoft 365 Copilot, Pickle in the Middle in Google Vertex AI, and vulnerabilities in LiteLLM. Ransomware gangs including Qilin, Gentlemen, and DragonForce continue dominating the threat landscape with EDR-killing tradecraft and cloud-based C2 abuse.