Cyware Daily Threat Intelligence - September 07, 2026

Ransomware groups are slashing through critical infrastructure, with Medusa sustaining a years-long extortion spree that has impacted over 500 organizations since 2021. Cyware spotlights how a single affiliate’s access can spiral into widespread outages, as seen in the University of Mississippi Medical Center attack that forced patient diversions and costly downtime.
Attackers are exploiting zero-day vulnerabilities in enterprise management tools, turning trusted platforms into single points of failure. In just 36 days, Interlock ransomware campaigns leveraged flaws in Cisco’s Secure Firewall Management Center, enabling threat actors to manipulate security policies and disrupt networks across multiple sites.
North Korean threat actors are embedding espionage toolkits in legitimate software, using a trojanized build of HAProxy 2.8.12 to surveil South Korean automotive and media organizations. Their campaign leverages watering-hole techniques and advanced persistence, exposing sensitive business communications and industrial supply chains.
Top Malware Reported in the Last 24 Hours
Medusa ransomware sustains years-long extortion spree
Medusa is a ransomware-as-a-service operation specializing in double and triple extortion attacks. Medusa encrypts systems and threatens to publish stolen data, and has a documented history of escalating to triple extortion. Medusa relies on initial access brokers to infiltrate networks, maintaining scalability as its affiliate model grows. The operation struck the University of Mississippi Medical Center in February 2026, causing healthcare disruptions and costly downtime. Medusa has impacted over 500 victims across critical infrastructure since June 2021, according to the FBI, CISA, and HHS.
Interlock ransomware rides Cisco management zero-days
Interlock is a ransomware family that exploits zero-day vulnerabilities in centralized Cisco management tools. Interlock abuses authentication failures and insecure deserialization to bypass protections and manipulate management-plane controls. Interlock leverages flaws including CVE-2026-20131, CVE-2026-20079, and CVE-2026-20316 to gain persistent access. The campaign targeted Cisco Secure Firewall Management Center and SD-WAN Controller, with Amazon’s MadPot honeypot network detecting the activity after a misconfigured staging server was exposed. Attribution points to threat actor UAT-8616.
Kimsuky shifts GitPower into finance
Kimsuky is a North Korea-linked threat actor running Operation GitPower, a campaign using malicious Windows shortcut files for persistent access. Kimsuky disguises LNK files as Korean business documents, points icons to Chrome’s executable path, and adds pseudorandom padding to evade analysis. Kimsuky uses PowerShell to fetch decoys and scripts from GitHub, with Pastebin as a backup channel, and runs anti-analysis checks to avoid detection. The campaign targets financial and corporate sectors, with Genians Security Center analyzing 13 malicious samples delivered between August 11 and 19, 2026.
Top Vulnerabilities Reported in Last 24 hours
Ransomware hits Cisco firewall management plane
CVE-2026-20131 is an insecure deserialization vulnerability in Cisco Secure Firewall Management Center that enables authentication bypass and management-plane takeover. Successful exploitation allows attackers to manipulate security policies and settings across enterprise environments. Attackers are actively exploiting this vulnerability in the wild. Amazon’s MadPot honeypot network detected the campaign, and threat actor UAT-8616 chained software downgrades for root escalation. Cisco urges customers to treat management-plane access as Tier 0, apply patches for all listed CVEs, and monitor for IoCs such as the presence of /var/tmp/license.tmp in logs.
ShinyHunters abuses Metabase cloud zero-day
A zero-day vulnerability in Metabase cloud systems allows attackers to reset passwords and inject malicious code, exposing customer data and business analytics. Exploitation of this flaw led to direct impact in Europe, with Uplift in Ireland disclosing compromise and the Data Protection Commission launching an investigation. Attackers exploited the vulnerability on August 3, with notifications to affected parties issued on August 17. The activity is attributed to the ShinyHunters hacker collective. Metabase users are advised to apply available fixes, review logs for unauthorized access, and enable multi-factor authentication.
MikroTik SSH bugs enable router takeovers
CVE-2026-67276 and CVE-2026-86060 are critical SSH vulnerabilities in MikroTik RouterOS that enable remote takeover without authentication and privilege escalation to full admin access. Attackers can use these flaws for surveillance, traffic manipulation, or as a launchpad into business networks. Both vulnerabilities are being actively exploited in the wild. CERT Polska identified the issues, and The Shadowserver Foundation reported over 122,000 routers accessible via SSH. MikroTik has released firmware updates, and defenders should update devices, avoid exposing SSH to the internet, and monitor logs for warnings.
Top Threat Actors Reported in Last 24 hours
North Korean hackers hide spyware in HAProxy
North Korean threat actors (linked to APT37 and Lazarus) are suspected to originate from North Korea and focus on espionage. North Korean threat actors disguise a Linux toolkit as a legitimate build of HAProxy 2.8.12 and deploy a “ted backdoor” for traffic interception and persistence. North Korean threat actors use watering-hole techniques, cookie theft, and drive-by downloads to maintain access and manipulate user sessions. The campaign targets South Korean automotive and media organizations. The operation leverages a Groupware login portal vulnerability and supports remote command execution, credential harvesting, and script injection.
Qilin leaks files stolen from ATF
Qilin (likely Russian-speaking) is a ransomware gang suspected to operate for financial gain. Qilin recently leaked sensitive files stolen from the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), including investigative material and phone analysis. Qilin referenced the ATF’s Houston Field Division, risking exposure of ongoing investigations. The group targets U.S. federal agencies, with previous incidents involving the U.S. Marshals Service and FBI’s New York field office. Cybersecurity firm Halcyon notes Qilin victim claims across manufacturing, retail, and healthcare.
Medusa ransomware hits 500-plus victims
Medusa is a ransomware operation suspected to originate from an unknown region and motivated by financial extortion. Medusa relies on initial access brokers to infiltrate networks before deploying encryption and data theft. Medusa uses double extortion—encrypting systems and threatening to publish stolen data—and has a documented history of triple extortion attempts. The group targets critical infrastructure, including hospitals and essential services. The FBI, CISA, and HHS report that Medusa has impacted over 500 victims since June 2021, with one example being the University of Mississippi Medical Center attack in February 2026.
Frequently Asked Questions
What is Medusa? Medusa has built a long-running ransomware-as-a-service operation that U.S. agencies say has hit over 500 victims across critical infrastructure since June 2021. It uses double extortion—locking systems while threatening to publish stolen data—and the advisory says it also has a documented history of triple extortion attempts.
What is Interlock? Interlock ransomware campaigns exploited a run of zero-day weaknesses in centralized Cisco management tools for 36 days, turning “single panes of glass” into a potential single point of enterprise failure. The activity targeted Cisco Secure Firewall Management Center and the SD-WAN Controller, abusing authentication failures alongside insecure deserialization to bypass protections and manipulate management-plane control.
What is Kimsuky? Kimsuky, a North Korea-linked threat actor, has expanded its Operation GitPower campaign into financial and corporate targets using booby-trapped Windows shortcut files. Genians Security Center analyzed 13 malicious LNK samples (August 11–19, 2026) delivered inside ZIP archives and disguised as Korean business documents.
What is ShinyHunters? A zero-day in Metabase cloud systems was exploited to reset passwords and inject malicious code, exposing customer data and putting organizations that rely on the business intelligence and analytics platform at risk. The incident’s fallout reached Europe directly: Ireland-based Uplift disclosed impact, and the country’s Data Protection Commission is investigating.
What is CVE-2026-67276? Attackers are actively exploiting critical SSH flaws in MikroTik RouterOS to remotely take over routers without authentication, a scenario that can quickly turn into surveillance, traffic manipulation, or a launchpad into business networks. The reported chain combines CVE-2026-67276 (SSH authentication bypass via improper public-key verification) with CVE-2026-86060 (a username-handling issue that enables privilege escalation to full admin access).
What is Qilin? Qilin, a likely Russian-speaking ransomware gang, has leaked sensitive files stolen from the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), including material tied to past investigations and analysis of phone communications. The group’s leak specifically references the ATF’s Houston Field Division, putting investigative details at risk even if day-to-day systems keep running.
What is Medusa? Medusa is a ransomware operation that has now impacted over 500 victims across critical infrastructure sectors since it emerged in June 2021, according to an updated advisory from the FBI, CISA, and HHS. The group runs as a ransomware-as-a-service model, relying on initial access brokers to help break into networks before deploying encryption and data theft.