Threat Intel Briefing Zero-Day Ransomware Data Leaks

Executive Summary

Weekly CTI Report Executive Summary

This report summarizes key cyber developments observed during the past week, covering widespread exploitation attempts, supply chain compromises, shifts in adversary operations, and other security incidents.

Key Developments

  • A critical Microsoft Exchange zero-day vulnerability is under active attack, with no immediate patch available. This affects organizations globally running on-premise Exchange servers, creating opportunities for remote code execution and system control.
  • The "Megalodon" supply chain attack compromised over 5,500 GitHub repositories within six hours. This event affects developer ecosystems by risking the exfiltration of sensitive credentials and tokens during continuous integration processes.
  • Global law enforcement actions successfully disrupted a major VPN service widely used by ransomware groups. This operation significantly affects the operational anonymity and infrastructure of at least 25 identified ransomware collectives.
  • A large dataset containing 340 million user records, linked to OnlyFans and compiled from older breaches, surfaced on underground forums. This information presents an increased risk for individuals susceptible to downstream fraud and account compromise.

Business Impact

The observed activities present varied risks across organizational functions. The Exchange zero-day poses direct risks to communication infrastructure and data integrity. The GitHub supply chain compromise affects software development lifecycles and intellectual property security. The broad availability of personal data from past breaches increases the potential for social engineering and identity-based attacks against employees and customers. Ransomware operations continue to disrupt business operations across multiple sectors, including manufacturing, healthcare, professional services, and logistics, often involving data theft.

Notable Trends and Changes vs Last Week

Ransomware activity maintained a consistent volume of reported victims and active groups. They frequently employed double-extortion tactics and exploited exposed VPN appliances for initial access. A notable change this week is the successful law enforcement disruption targeting a key VPN provider, which could alter the operational environment for numerous ransomware actors. Identity data from historical breaches remains a common commodity on underground forums. The emergence of advanced industrial control system (ICS/SCADA) attack utilities suggests adversary capabilities are evolving in specific areas.

Outlook

Ransomware activity is expected to remain prevalent, with groups adapting their operational methods following recent infrastructure disruptions. Continued exploitation of unpatched public-facing applications and vulnerabilities within supply chain ecosystems is anticipated. The ongoing circulation of extensive identity datasets will sustain social engineering and account compromise attempts. Increased development and deployment of specialized offensive tooling, including those targeting industrial systems, are also expected.


Key Threat Intelligence Highlights

Fast16 malware tampered with nuclear weapons simulations preceding the Stuxnet attacks. This early, state-backed digital intrusion aimed to subtly corrupt sensitive defense data, showing advanced cyber operations against critical national security systems. The program's discovery shows how sophisticated cyber weaponry designed for strategic sabotage has evolved historically.


A zero-day vulnerability in Microsoft Exchange servers is actively exploited, leaving affected organizations exposed to attacks. This critical flaw allows malicious actors to compromise email systems, potentially leading to data breaches and service interruptions. With no official patch released, immediate mitigation actions are crucial for securing impacted Exchange environments.


A Megalodon supply chain attack compromised 5,561 GitHub repositories in just six hours, injecting malicious code into developer projects and showing the increasing risk to software development pipelines. This widespread compromise could propagate malware to countless downstream users, exposing vulnerabilities in the interconnected developer ecosystem.


Global law enforcement recently dismantled a VPN service, directly addressing its widespread use by 25 ransomware groups. This operation significantly affects cybercriminals' ability to operate anonymously and conduct their attacks. This shows continuous efforts to disrupt the digital infrastructure supporting cybercrime.


A hacker is offering to sell 340 million OnlyFans user records, a collection compiled from multiple prior data breaches rather than a new system compromise. This broad availability of user information, including names and emails, increases the risk of phishing attacks, scams, identity theft, and account compromises for the affected individuals. The incident shows the ongoing danger of previously compromised data, demonstrating how old information can be repurposed and continue to endanger users long after its initial exposure.

Additional Threat Intelligence Context

CVE-2026-26980 | CVSS: 8.2 (CRITICAL) - (Ghost CMS SQL injection): Actively exploited at scale to inject malicious JavaScript into high-trust websites for ClickFix malware distribution.

Available Exploits:

  • CVE-2026-26980 Exploit
  • CVE-2026-26980 Exploit
  • [[webapps] Ghost CMS 6.19.0 - SQLi](https://www.exploit-db.com/exploits/52555)
  • CVE-2026-26980 Exploit

Analysis: # CVE Analysis Report: CVE-2026-26980

GitHub Link:

  • Title: Ghost CMS Content API SQL Injection PoC
  • CVE: CVE-2026-26980 (CVSS: 8.2, CRITICAL)
  • CVSS Score: 8.2
  • CVSS Severity: CRITICAL

Based on the analysis:

  • Complexity Score: Easy
  • Remote/Local: Remote
  • Authenticated/Unauthenticated: Unauthenticated
  • Privilege Required: None

Risk Score: 100/100

_Based on ease of use, potential impact, how wide...

Multi-vector supply chain campaigns (Megalodon, Cross-platform NPM Stealer): Target PHP and GitHub ecosystems, embedding credential stealers in popular packages (e.g., Laravel Lang) and utilizing poisoned VS Code extensions (e.g., Nx Console) to exfiltrate CI secrets, cloud credentials, and developer tokens.

CVE-2026-9082 | CVSS: 6.5 (CRITICAL) - Critical web application vulnerabilities: Includes actively exploited Drupal Core SQL injection (), Langflow origin validation bypass (CVE-2025-34291) leading to RCE, and a maximum severity RCE in LiteSpeed User-End cPanel Plugin (CVE-2026-48172). All added to CISA KEV.

Available Exploits:

  • CVE-2026-9082 Exploit
  • CVE-2026-9082 Exploit
  • CVE-2026-9082 Exploit
  • CVE-2026-9082 Exploit
  • CVE-2026-9082 Exploit

Analysis: # CVE Analysis Report: CVE-2026-9082

GitHub Link:

  • Title: SA-CORE-2026-004 Detection PoC (Drupal JSON:API IN filter SQLi)
  • CVE: CVE-2026-9082 (CVSS: 6.5, CRITICAL)
  • CVSS Score: 6.5
  • CVSS Severity: CRITICAL

Based on the analysis:

  • Complexity Score: Easy
  • Remote/Local: Remote
  • Authenticated/Unauthenticated: Unauthenticated
  • Privilege Required: None

Risk Score: 100/100

_Based on ease of use, potentia...

CVE-2026-34926 | CVSS: 6.7 (PROBLEMATIC) - Trend Micro Apex One on-prem directory traversal (): Actively exploited flaw enabling pre-authenticated attackers to deploy arbitrary code to endpoints. Listed in CISA KEV.

Available Exploits:

  • CVE-2026-34926 Exploit

Analysis: # CVE Analysis Report: CVE-2026-34926

GitHub Link:

  • Title: CVE-2026-34926 PoC - Readme Disclaimer
  • CVE: CVE-2026-34926 (CVSS: 6.7, PROBLEMATIC)
  • CVSS Score: 6.7
  • CVSS Severity: PROBLEMATIC

Based on the analysis:

  • Complexity Score: NA
  • Remote/Local: Remote
  • Authenticated/Unauthenticated: Unauthenticated
  • Privilege Required: None

Risk Score: 75/100

_Based on ease of use, potential impact, how widel...

CVE-2026-41091 | CVSS: 7.8 (CRITICAL) - Microsoft Defender zero-days (, CVE-2026-45498): Actively exploited for privilege escalation and denial of service on Windows systems.

Available Exploits:

  • CVE-2026-41091 Exploit
  • CVE-2026-41091 Exploit

Analysis: # CVE Analysis Report: CVE-2026-41091

GitHub Link:

  • Title: RedSun PoC (CVE-2026-41091)
  • CVE: CVE-2026-41091 (CVSS: 7.8, CRITICAL)
  • CVSS Score: 7.8
  • CVSS Severity: CRITICAL

Based on the analysis:

  • Complexity Score: Easy
  • Remote/Local: Local
  • Authenticated/Unauthenticated: Authenticated
  • Privilege Required: Low

Risk Score: 100/100

_Based on ease of use, potential impact, how widely it could spread...

P2Pinfect botnet: Persists within Google Kubernetes Engine (GKE) clusters, initially accessed via exposed Redis instances and weak management interfaces.

CVE-2018-5999 - RondoDox botnet: Actively using ASUS router for unauthenticated RCE, compromising numerous devices for DDoS activities.

User-friendly ICS offensive tooling (TRK25 ADVANCED): Emergence lowers the barrier for intrusions into industrial control systems.

CVE-2026-0265 | CVSS: None (CRITICAL) - PAN-OS / Panorama CAS authentication bypass (): A critical bypass affecting GlobalProtect portals, enabling unauthorized access.

Available Exploits:

  • CVE-2026-0265 Exploit
  • CVE-2026-0265 Exploit

Analysis: # CVE Analysis Report: CVE-2026-0265

GitHub Link:

  • Title: PAN-OS CVE-2026-0265 Risk Checker
  • CVE: CVE-2026-0265 (CVSS: None, CRITICAL)
  • CVSS Score: None
  • CVSS Severity: CRITICAL

Based on the analysis:

  • Complexity Score: Easy
  • Remote/Local: Remote
  • Authenticated/Unauthenticated: Authenticated
  • Privilege Required: Low

Risk Score: 100/100

_Based on ease of use, potential impact,...

CVE-2023-28252 | CVSS: NA (NA) - (Windows CLFS LPE): Actively used by ransomware groups for post-compromise privilege elevation.

Available Exploits:

  • Windows Common Log File System Driver (clfs.sys) Elevation of Privilege Vulnerability
  • CVE-2023-28252 Exploit
  • CVE-2023-28252 Exploit
  • CVE-2023-28252 Exploit
  • CVE-2023-28252 Exploit

Analysis: # CVE Analysis Report: CVE-2023-28252

GitHub Link:

  • Title: CLFS Privilege Escalation PoC
  • CVE: CVE-2023-28252

Based on the analysis:

  • Complexity Score: High
  • Remote/Local: Local
  • Authenticated/Unauthenticated: Authenticated
  • Privilege Required: User

Risk Score: 48/100

_Based on ease of use, potential impact, how widely it could spread, and whether special access or user actions are needed. Note: Scanners (...

Ransomware Activity Overview

Ransomware groups, including Bravox, The_Gentelman, DragonForce, NightSpire, Qilin, Nova (RALord), and INC_Ransom, were observed operating globally across multiple sectors such as NGOs, local government, healthcare, manufacturing, logistics, telecoms, higher education, and professional services. Tactics often involved double-extortion with extensive data theft, using Windows local-privilege-escalation exploits, and exploiting FortiGate VPNs and unpatched SonicWall instances for initial access. Notable data breaches included ShinyHunters leaking 15M+ Odido NL & Ben.nl customer records, 500M "Chinese Taobao delivery" records, 10M+ Israeli National Insurance Institute data, and civil registry data for Indonesia. Extortion claims against Baker Distributing over a Salesforce breach and the sale of a 340M-record "OnlyFans"-linked dataset also surfaced. Geopolitical cyber activity involved 404Crew threatening Israeli and South African entities, Keymous and PKA291 forming an alliance while targeting Moroccan infrastructure, Nullsec Philippines signaling interest in South African government targets, and the Yemen Cyber Army voicing support for Russian military operations. The underground market showed significant activity, with an advanced ICS/SCADA attack tool ("TRK25 ADVANCED") advertised, consistent demand for red-team C2 frameworks, RATs, and stealer logs, and discussions involving AI-assisted exploitation methods. Large national datasets, such as the Iraq census and Georgian citizenship data, were actively traded, alongside numerous corporate and customer record databases.

During the reporting period, 160 total victims were identified across 32 active ransomware groups. The top 5 most active groups accounted for 69 victims.

Top 5 Ransomware Groups

Qilin - 20 victim(s)

  • Notable victims: Air conditioning florida & mrdsllc & rte stucco & mr drywall services, Alpert slobin & rubenstein, Alpha group holdings, Branded products, Cj architects (and 15 more)

The_Gentelman - 19 victim(s)

  • Notable victims: Acam systemautomation, Caka grup lojistik, Devo-tech, E-control systems, Grupo pasquel (and 14 more)

Nova (RALord) - 12 victim(s)

  • Notable victims: Adensa teknoloji, Amaccao, Asian lite international, Hoy construction, Neubox (and 7 more)

Akira - 9 victim(s)

  • Notable victims: Acton electrical, Buffalo niagara convention center, Function enterprises, Gitis, Healthtrax fitness & wellness (and 4 more)

CMD - 9 victim(s)

  • Notable victims: Advanced Software Products Group, Goodstone Group, Holy Name of Jesus, Houston Eye Associates, Ira & Larry Goldberg Coins & Collectibles (and 4 more)

Deep Web

Deep Web Activity Overview

The past week revealed persistent and extensive deep web activity, primarily centered on governmental entities and large-scale personal data exposures. Data indicates a wide array of compromised information, ranging from national security and citizen identification records to financial credentials and critical infrastructure details. Several data sets with global reach were disseminated, alongside regionally concentrated incidents affecting specific countries.

What major data leaks appeared on deep web forums this week?

This week saw several notable data leaks impacting governmental organizations across multiple continents. These included confidential details related to the US military, complete citizen data from the Iraqi Ministry of Interior, and extensive information concerning Indonesian government bodies, military, and police forces. A large compilation of data pertaining to government officials from 27 European Union and United Kingdom countries was also circulated.

  • US Military Operational Data: An actor identified as "RuskiNet" posted five files purporting to contain US military data. The content describes information about US military bases (in the US and Persian Gulf), military contractors, and vessels tracked globally. This incident suggests a potential compromise of operational security details.
  • Iraqi Ministry of Interior Database: The user "rcon" released an 11.6 GB database (1.1 GB compressed) from the Iraqi Ministry of Interior, with data dated October 16, 2021. This collection comprises extensive Personally Identifiable Information (PII) for Iraqi citizens across all 18 provinces, including full names, dates of birth, ID numbers, family member details, and residence information. The actor stated this database was "stolen from the internal government devices," rather than an online breach, suggesting an insider threat or advanced internal network infiltration.
  • Indonesian Government and Security Apparatus Breaches: An actor named "C10F./x404" was linked to two separate disclosures targeting the Indonesian state. One post offered a "COMPLETE DATABASE" encompassing the DPR-RI (House of Representatives), KPU DUKCAPIL (General Election Commission and Civil Registry), and the Ministry of Air Transportation. A second post from the same actor provided "Complete military and police" databases, including personnel names, ranks, task forces, usernames, emails, phone numbers, NRPs (service numbers), device information, operating systems, application versions, and hashed passwords for military personnel, alongside similar PII for police. Separately, an actor named "DarkMafiaX" claimed administrative access to the Indonesian government website ciptakarya.pu.go.id. These incidents suggest a coordinated campaign against Indonesian government and security assets.
  • European Government Officials Data: A new actor, "APT511," distributed a collection of emails, full names, roles (ministries, presidents, members of parliament), and phone numbers belonging to government officials from 27 European countries, including EU member states and the United Kingdom. This aggregation of valuable contact information presents a risk for targeted attacks.

What personal and financial data was exposed?

Deep web forums also featured a wide release of personal and financial information impacting millions of individuals globally. This included a large United States citizen data compilation, a large credit card database, and phone numbers associated with multi-factor authentication.

  • Large US Citizen Data Compilation: An actor named "sm4rt" shared a large data compilation containing over 250 million records related to US citizens. This large dataset includes full names, phone numbers, email addresses, dates of birth, marital status, gender, house details (cost, rent, built year), addresses, geolocation, credit capacity, political affiliation, salary, income details, and the number of owned vehicles, children, and pets. This content was indicated as a re-share of data originally leaked by "pompompurin."
  • BIDENCASH Credit Card Database: The user "MrZoro" facilitated the distribution of a credit card database reportedly containing 1,221,551 cards. The compromised data includes Primary Account Numbers (PANs), CVV2s, expiration dates, cardholder names, shipping addresses, and emails. The leak identifies numerous banks and countries affected, with the United States, India, and Brazil seeing the highest number of exposed cards.
  • Twilio Authy Phone Numbers: A dataset attributed to the known actor "ShinyHunters" (despite their forum account being banned as "Retired") was posted, containing 33 million phone numbers linked to Twilio Authy accounts. This information, including account IDs, device lock status, account status, and device count, presents a vector for social engineering and SIM swapping.

What is the nature and scope of these incidents?

This week's deep web activity is broad, encompassing national security intelligence, detailed citizen PII, enablers of financial fraud, and administrative access credentials. The scope spans multiple continents, demonstrating both geographically concentrated attacks on specific national infrastructure and widely distributed releases affecting millions of individuals and high-level officials. Many of the releases contain granular data, enabling targeted malicious activities. The explicitly stated method of compromise for the Iraqi Ministry of Interior data - theft from internal government devices - shows the continued importance of insider threats or advanced persistent infiltration methods, contrasting with more common online breach vectors.

Several patterns emerge from this week's deep web breach data. First, government entities and national security organizations remain a primary target, with intelligence and operational data sought after. Second, widespread PII leaks continue, often comprising detailed profiling data that extends beyond basic contact details. Third, a mix of relatively new or low-reputation actors (e.g., RuskiNet, rcon, C10F./x404, APT511, MrZoro, sm4rt) are disseminating large data collections, suggesting either easy access to compromised data or a decentralized network of initial compromise actors. This also includes the re-sharing of older, but still potent, data collections (e.g., the US leak from pompompurin). Lastly, there is interest in data that facilitates secondary attacks, such as credit card details for financial fraud and phone numbers tied to multi-factor authentication for account takeover attempts.

What is the potential impact of this week's deep web activity?

The deep web activity observed has significant consequences for national security, citizen privacy, financial stability, and public trust.

  • National Security and Geopolitical Implications: The exposure of US military data, Iraqi Ministry of Interior records, and Indonesian military/police information can be used for espionage, targeted surveillance, disruption of critical operations, and disinformation campaigns. Data on European government officials provides adversaries with useful intelligence for targeted phishing campaigns, social engineering, and potential foreign interference.
  • Widespread Citizen Vulnerability: The widespread PII leaks for US and Iraqi citizens create many opportunities for identity theft, financial fraud, sophisticated social engineering schemes, and malicious activities. The detail within these datasets allows for personalized and convincing attacks. The Indonesian citizen data further exacerbates these risks within the region.
  • Financial Compromise: The large BIDENCASH credit card database directly enables financial fraud, leading to large monetary losses for individuals and financial institutions worldwide.
  • Increased Risk of Account Takeover: The release of 33 million Twilio Authy phone numbers makes affected users more susceptible to SIM swapping and other multi-factor authentication bypass techniques, leading to account takeovers across various online services.
  • Operational Disruption and Trust Erosion: Administrative access to a government website, as seen in Indonesia, poses risks for defacement or data manipulation. These compromises erode public trust in government and critical service providers' ability to protect sensitive data.

Sources

  1. Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations
  2. Microsoft Exchange Zero-Day Under Attack, No Patch Available
  3. 5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours
  4. First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
  5. Hacker Selling 340 Million OnlyFans User Records Built From Old Breaches