Insikt Group identified 60 high-impact vulnerabilities in June 2026 (a 49% increase from May), with 23 listed in CISA's KEV catalog and 53 having public PoC exploits. The dominant theme was exploitation of externally reachable enterprise applications and appliances by multiple threat actors: StrikeShark chained 13 CVEs to deploy SharkLoader and Cobalt Strike, Lazarus exploited CVE-2025-55182 (React2Shell, CVSS 10.0) to deploy COPPERHEDGE and EtherRAT, APT36 targeted India via Microsoft Office/Windows CVEs, and Qilin ransomware was linked to Check Point gateway exploitation. 25 of the 60 vulnerabilities enabled RCE across 18 vendors, with CWE-22 (Path Traversal) being the most common flaw class.
Qilin
24 posts
June 2026 CVE Landscape Ransom & Dark Web Issues Week 4, June 2026 This weekly roundup from AhnLab's ASEC team highlights three notable dark web and ransomware developments: BreachForums is experiencing internal issues with staff impersonation and unauthorized sales, Lapsus$ claims to have leaked data from a Myanmar bank, and Qilin ransomware targeted a South Korean law firm. No technical IOCs, detection rules, or vulnerability details are provided in the public article; full analysis is available via AhnLab TIP subscription.
Killing me gently: Inside Gentlemen’s EDR killer framework ESET researchers analyzed the Gentlemen ransomware-as-a-service (RaaS) operation, highlighting their unique approach of providing an in-house developed EDR killer framework, GentleKiller, directly to affiliates. The framework leverages Bring Your Own Vulnerable Driver (BYOVD) techniques to terminate over 400 security processes and is augmented by third-party tools like HexKiller and HavocKiller, all standardized with a shared defense-evasion layer.
15th June – Threat Intelligence Report This threat intelligence report highlights multiple critical vulnerabilities and active exploits, including a zero-day in Oracle PeopleSoft (CVE-2026-35273) exploited by ShinyHunters and an IKEv1 authentication bypass in Check Point VPNs (CVE-2026-50751) linked to Qilin ransomware. Additionally, the report details emerging AI-driven threats, a supply-chain compromise in the Arch User Repository deploying eBPF rootkits, and widespread patching efforts by Microsoft and Veeam.
- 7 minWeekly Recap — 2026-06-08 -> 2026-06-15
Perimeter Auth Collapse and AI-Driven Deception Shift the Battlefield The security perimeter cracked open this week as critical authentication bypasses in Check Point VPNs, Ivanti Sentry, and Palo Alto GlobalProtect gave attackers a free pass into corporate networks, with Qilin ransomware already exploiting one to launch real attacks. At the same time, AI became the year's most versatile weapon: criminals used ChatGPT and Claude brands as phishing lures, researchers proved AI email assistants will hand over corporate secrets to impersonators, and the Shai-Hulud campaign began injecting fake prompts to blind AI-powered security scanners. Patch edge VPN appliances immediately, treat AI agents as high-risk insiders, and hunt for device-code authentication events that bypass normal credential checks.
Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) Check Point Remote Access VPNs are vulnerable to a critical authentication bypass (CVE-2026-50751, CVSS 9.3) within the IKEv1 key exchange process. By sending a crafted 'VPNExtFeatures' Vendor ID payload, an attacker can manipulate the negotiation state to skip certificate signature verification, allowing full network access using only a valid username and the gateway's public ICA organization string.
25th May – Threat Intelligence Report This threat intelligence report highlights multiple high-profile breaches, including 7-Eleven and GitHub, alongside the active exploitation of vulnerabilities in Windows Defender, Trend Micro, and Drupal. It also details emerging threats such as the Kali365 phishing kit, AI-driven prompt injection attacks, the Nimbus Manticore IRGC-linked campaign deploying the MiniFast backdoor, and a supply chain attack on Laravel Lang packages.
18th May – Threat Intelligence Report This threat intelligence report highlights a surge in ransomware activity, critical zero-day vulnerabilities in Windows, and the active exploitation of Cisco Catalyst SD-WAN controllers. Additionally, it details emerging AI-driven threats, including malicious Hugging Face repositories and the abuse of AI website generators for phishing, alongside an APT intrusion by FamousSparrow targeting the energy sector.
Beyond the RaaS Headlines: The Reality of Ransomware Tradecraft The Ransomware-as-a-Service (RaaS) ecosystem relies heavily on affiliates who dictate the actual intrusion tradecraft, meaning a single ransomware brand can be associated with vastly different attack chains. Affiliates frequently abuse legitimate Remote Monitoring and Management (RMM) tools, exposed RDP, and vulnerable edge appliances for initial access, followed by the use of LOLBins and open-source utilities for persistence and data exfiltration.
Exposing Fox Tempest: A malware-signing service operation Fox Tempest is a financially motivated threat actor providing malware-signing-as-a-service (MSaaS) to the cybercrime ecosystem. By abusing Microsoft Artifact Signing via stolen identities, they generate short-lived, fraudulent code-signing certificates that allow threat actors like Vanilla Tempest to bypass security controls and deploy payloads such as the Oyster backdoor and Rhysida ransomware.
WantToCry ransomware remotely encrypts files WantToCry is a remote ransomware operation that targets internet-exposed SMB services using brute-force authentication. Instead of deploying local malware, attackers exfiltrate files, encrypt them on their own infrastructure, and write the encrypted versions back to the victim's network via authenticated SMB sessions, effectively bypassing traditional process-based EDR detections.
IT threat evolution in Q1 2026. Non-mobile statistics Kaspersky's Q1 2026 threat report highlights significant law enforcement actions against major ransomware operators, alongside the emergence of new ransomware groups like The Gentlemen. The quarter also saw active zero-day exploitation of Cisco Secure FMC (CVE-2026-20131) by the Interlock group, a rise in macOS-targeted crypto stealers and supply chain attacks via the Axios npm package, and persistent IoT botnet activity dominated by Mirai variants.
The State of Ransomware – Q1 2026 In Q1 2026, the ransomware ecosystem experienced significant consolidation, with top groups like Qilin, Akira, The Gentlemen, and LockBit 5.0 dominating the landscape. Notably, The Gentlemen leveraged a massive stockpile of pre-exploited FortiGate devices (CVE-2024-55591) to rapidly scale operations, while LockBit 5.0 returned with multi-platform capabilities and a strategic shift away from US targets to evade law enforcement.
Critical Minerals and Cyber Operations The geopolitical competition for critical minerals and rare earth elements is driving an increase in cyber operations targeting the mining sector. State-sponsored actors, particularly from China, alongside financially motivated ransomware groups, are conducting espionage, extortion, and disruptive attacks to gain strategic advantages in global supply chains.
Intelligence Center Talos IR's Q1 2026 trends report highlights the resurgence of phishing as the primary initial access vector, heavily targeting public administration and healthcare. The quarter saw novel abuses of AI tools like Softr for credential harvesting, the emergence of the Crimson Collective extortion group leveraging valid accounts and TruffleHog, and Rhysida ransomware deploying the MeowBackConn backdoor.
The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscape In 2025, Germany became the primary focus for cyber extortion in Europe, experiencing a 92% surge in data leak site victims. The disruption of major ransomware cartels has given rise to agile mid-tier groups like SAFEPAY and Qilin, who are heavily targeting the German Mittelstand (SMEs) and critical supply chain sectors such as manufacturing and professional services.
Intelligence Center Advancements in AI have democratized Business Email Compromise (BEC) attacks, allowing threat actors to efficiently target smaller organizations with tailored social engineering. Concurrently, attackers are exploiting the React2Shell vulnerability (CVE-2025-55182) in Next.js applications to harvest cloud and database credentials, while Qilin ransomware has been observed deploying a sophisticated EDR-killing payload.
Intelligence Center Ransomware tactics in 2025 have shifted heavily toward 'Living off the Land' (LotL) techniques, with threat actors leveraging valid accounts and built-in administrative tools like RDP, PowerShell, and PsExec to evade detection. Qilin has emerged as the most prolific ransomware group, utilizing double-extortion tactics, while manufacturing remains the most targeted industry.
Case Study: When Forum Disruption Reshapes the Ransomware Market The disruption of a major cybercrime forum has led to a fragmented ransomware market, prompting groups like Nova RaaS to artificially inflate their perceived status. Despite aggressive recruitment and branding efforts, structural indicators reveal Nova's operational scale remains far below established market leaders.
Intelligence Center The Talos 2025 Year in Review highlights a significant shift towards attackers targeting identity infrastructure and network components to bypass MFA and gain privileged access. Key threats include widespread exploitation of React2Shell, supply chain attacks targeting CI/CD pipelines, and the dominance of Qilin ransomware.
M-Trends 2026: Data, Insights, and Strategies From the Frontlines Mandiant's M-Trends 2026 report highlights a severe divergence in adversary tactics. Cybercriminals are optimizing for speed, with initial access hand-offs collapsing to 22 seconds, and focusing on recovery denial by targeting hypervisors and backup infrastructure. Conversely, espionage groups are prioritizing extreme persistence by exploiting zero-days and deploying in-memory malware on unmonitored edge devices, while voice phishing has emerged as a primary vector for bypassing MFA and compromising SaaS environments.
EDR killers explained: Beyond the drivers Ransomware affiliates increasingly rely on EDR killers—ranging from BYOVD exploits and abused anti-rootkits to driverless tools—to disrupt security solutions prior to deploying encryptors. This approach allows encryptors to remain simple while the EDR killers handle complex defense evasion, complicating attribution and defense strategies.
Ransomware Under Pressure: Tactics, Techniques, and Procedures in a Shifting Threat Landscape In 2025, ransomware operators increasingly relied on vulnerability exploitation for initial access and heavily targeted virtualization infrastructure like ESXi. While overall ransomware profitability appears to be declining, threat actors have adapted by increasing data theft extortion, targeting smaller organizations, and utilizing cross-platform ransomware families like REDBIKE, AGENDA, and INC.
Iranian MOIS Actors & the Cyber Crime Connection Iranian Ministry of Intelligence and Security (MOIS) affiliated threat actors, including Void Manticore and MuddyWater, are increasingly integrating cybercriminal tools, infrastructure, and affiliate models into their operations. This strategic shift, which includes the use of commercial infostealers like Rhadamanthys and RaaS platforms like Qilin, enhances their operational capabilities while complicating attribution efforts.