Cyware at Billington CyberSecurity Summit
Weekly Threat Briefing
Diamond Trail

Cyware Weekly Threat Intelligence - August 22 - 28, 2026

16 min read
shutterstock 1453727786

Ransomware crews are slashing through global defenses with new extortion tactics and cross-platform payloads, as Medusa ransomware alone has impacted over 500 organizations and now tailors ransom demands to victim revenue. Cyware spotlights how these actors are leveraging both unpatched software and legitimate remote access tools to maintain persistence, with the healthcare sector facing a surge in targeted attacks and North Korean involvement flagged in recent advisories.

Critical vulnerabilities are being weaponized at speed, with SonicWall SMA 1000 zero-days (CVSS 10.0) exploited by ransomware groups to steal session tokens and MFA seeds, driving a shift toward zero trust architectures. Over 8,500 SharePoint servers remain exposed online, and VMware vCenter, Microsoft Exchange, and Windows Winsock flaws are under active attack, underscoring the urgency for immediate patching across enterprise environments.

State-sponsored espionage is sweeping Western and Central Asian networks, as Laundry Bear exploits a Zimbra zero-click flaw to steal 90 days of emails from defense and government targets, while Chinese and Iranian actors escalate router and Microsoft 365 intrusions. This week’s cyware.com briefing details the evolving TTPs and cross-sector impact shaping the global threat landscape.

Top Malware Reported This Week

Medusa ransomware expands global impact and refines extortion tactics

Medusa ransomware is a ransomware family that encrypts victim data and threatens to leak or sell exfiltrated information unless a ransom is paid. Medusa ransomware exploits vulnerabilities in Fortra GoAnywhere, BeyondTrust, Fortinet EMS, and ScreenConnect, and leverages legitimate remote access tools such as AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, and Splashtop to maintain persistence and evade detection. Medusa ransomware uses phishing to steal credentials and opportunistically targets organizations with unpatched software, employing access brokers and living off the land techniques for lateral movement. Medusa ransomware actors determine ransom amounts based on victim revenue, offer a "discount" for quick payment, and charge $10,000 to extend the ransom deadline by a day. Medusa ransomware has impacted over 500 organizations, with a significant focus on the healthcare and public health sectors, and recent advisories highlight involvement from North Korean hackers. The FBI, CISA, and HHS have issued updated warnings detailing these tactics and the increasing number of victims.

Eclipse Ransomware-as-a-Service targets hybrid enterprise environments

Eclipse Ransomware is a Ransomware-as-a-Service (RaaS) platform that targets Windows, Linux, NAS devices, VMware ESXi, and Nutanix environments, using a Rust-based payload for Windows and C++ variants for other platforms. Eclipse Ransomware employs ChaCha20 encryption, Kyber-based key exchange, automated lateral movement, defense evasion, and process termination, with configurable modes for speed and stealth. Eclipse Ransomware provides affiliates with management features such as separate Bitcoin and Monero wallets, dedicated Tor .onion addresses, and direct leak-site publishing options, while prohibiting sample submissions to public multi-scanner portals. EclipseSupport recruits affiliates with a 90/10 revenue split for the first 10 successful extortion cases, shifting to 80/20 thereafter, and requires a $300 entry fee refundable upon the first ransom payout. Eclipse Ransomware is designed to compromise hybrid enterprise environments, including ESXi and Nutanix, and actively seeks to expand its affiliate network.

Gunra ransomware targets global critical infrastructure sectors

Gunra ransomware is a ransomware-as-a-service operation that encrypts data and employs double-extortion tactics, threatening to leak stolen information via a Tor-based data leak site. Gunra ransomware gains initial access by exploiting known vulnerabilities in internet-facing devices such as firewalls and VPNs, and leverages penetration testers and ethical hackers as initial access brokers. Gunra ransomware operations are influenced by Conti ransomware code and have historically collaborated with North Korean hackers, sharing techniques and tools since at least 2024. Gunra ransomware targets a wide range of sectors, including academia, financial services, government services, healthcare, manufacturing, media, retail, transportation, and utilities. Gunra ransomware has affected organizations across Africa, the Americas, the Asia-Pacific, Europe, and the Middle East, prompting joint alerts from U.S. and South Korean cyber agencies.

DeadLock ransomware leverages decentralized infrastructure and geofencing

DeadLock ransomware is an emerging Rust-based ransomware threat that uses decentralized infrastructure and double extortion to pressure victims. DeadLock ransomware employs resource-aware throttling, language geofencing to avoid execution in Russia, Ukraine, and Iran, and privilege escalation via command-line processing. DeadLock ransomware executes configuration parsing, privilege escalation, event log clearing, and encrypts data using Curve25519 and XChaCha20, while communicating with victims through a decentralized recovery chat system. DeadLock ransomware spreads across IT, mining, transportation, manufacturing, hospitality, and consumer goods sectors in Europe, Asia, North America, South America, and Africa. DeadLock ransomware has compromised over 80 organizations since July 2025, with more than half of the victims in Europe, and uses the following IOCs: deadlock[.]liveblog365[.]com, dlock[.]liveblog365[.]com, deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd[.]onion, deadlockblog[.]great-site[.]net, deadlockblog[.]medianewsonline[.]com, and SHA-256 hash a1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f4.

Aurora ransomware exploits AI-powered tools for post-compromise operations

Aurora ransomware is a ransomware family that leverages SpaceX's AI Cursor Agent to facilitate post-compromise activities, including credential acquisition and internal reconnaissance. Aurora ransomware operators use tools such as NetExec’s BloodHound collector, PetitPotam, Coerce Plus, and PrinterBug to conduct NTLM relay attacks and lateral movement. Aurora ransomware employs the Cursor Agent for domain enumeration and internal subnet scanning, refining commands iteratively to optimize attack success. Aurora ransomware recently deployed a new Linux variant targeting ESXi environments, encrypting virtual machine files while skipping system volumes to maintain hypervisor operability. Aurora ransomware has targeted organizations in Israel, Germany, Austria, Spain, the United States, and Argentina.

Top Vulnerabilities Reported This Week

CVE-2026-15409 and CVE-2026-15410 exploited in SonicWall SMA 1000 series

CVE-2026-15409 and CVE-2026-15410 are critical pre-authentication server-side request forgery and path traversal vulnerabilities in the SonicWall SMA 1000 series, each carrying a CVSS score of 10.0. Successful exploitation of CVE-2026-15409 and CVE-2026-15410 enables attackers to gain root access without authentication, steal session tokens, and extract MFA seed data, resulting in persistent unauthorized access. CVE-2026-15409 and CVE-2026-15410 have been actively exploited as zero-days by the INC ransomware group, with initial access brokers selling access to compromised devices and driving a broader market shift towards zero trust network access architectures. The vulnerabilities were discovered through analysis of exploitation activity targeting telecommunications, manufacturing, professional services, and public sector organizations. Organizations are advised to update SMA 1000 firmware to version 12.4.3-03453 or 12.5.0-02835 or later, regenerate MFA TOTP seeds, rotate administrator credentials, and audit logs for signs of exploitation. The scope of impact includes multiple sectors, with attackers leveraging server-side request forgery in the /wsproxy component and path traversal in the remove_hotfix workflow.

CVE-2026-59310 actively exploited in VMware vCenter servers

CVE-2026-59310 is a critical path traversal vulnerability in VMware vCenter servers, with a CVSS score of 9.8. Exploitation of CVE-2026-59310 allows unauthenticated attackers to execute arbitrary code, leading to full compromise of affected systems. CVE-2026-59310 is actively exploited in the wild, with attacks linked to a suspected advanced persistent threat (APT) group demonstrating a high level of sophistication and persistence. Hundreds of servers have been compromised globally, with 361 unique IP addresses identified across 47 countries, and the most affected systems located in Germany, the United States, and Turkey. Broadcom has released security updates to address CVE-2026-59310, and organizations should apply these patches immediately, review server logs, and implement network segmentation. Attackers have been observed installing a reverse SSH framework on compromised vCenter servers to maintain persistent access.

CVE-2026-68820 exploited by Lazarus Group in Microsoft Winsock

CVE-2026-68820 is a critical privilege escalation vulnerability in the Winsock component of Microsoft Windows, with a CVSS score of 8.8. Exploitation of CVE-2026-68820 enables attackers to escalate privileges from a low-privileged foothold to complete control over Windows systems. CVE-2026-68820 is being actively exploited by the Lazarus Group as part of Operation 'Dream Job', targeting sectors such as surveillance sensors, drones, and robotics in France, Germany, Brazil, and India, and follows a history of similar exploits by this group. Check Point discovered and reported CVE-2026-68820, initially confusing it with a past vulnerability. Microsoft has released a patch for CVE-2026-68820, and organizations should ensure all Windows endpoints are updated and restarted, enhance detection for phishing and kernel-driver race abuse, and conduct security awareness training. Federal agencies have been given a two-week deadline to patch, reflecting the significant threat to national security and critical infrastructure.

CVE-2026-45659 ransomware attacks target Microsoft SharePoint

CVE-2026-45659 is a high-severity remote code execution vulnerability in Microsoft SharePoint, caused by deserialization of untrusted data, with a CVSS score of 8.8. Exploitation of CVE-2026-45659 allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers, posing a significant risk of ransomware deployment. CVE-2026-45659 is actively exploited by ransomware gangs, and Microsoft SharePoint vulnerabilities have historically been frequent targets for such attacks. CISA has added CVE-2026-45659 to its Known Exploited Vulnerabilities Catalog, emphasizing the urgency for Federal Civilian Executive Branch agencies to secure their servers. Microsoft has released patches for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition, and organizations should apply these updates, enable AMSI integration, and monitor for exploitation. Shadowserver reports over 8,500 exposed SharePoint servers online, with more than 200 unpatched against CVE-2026-45659.

CVE-2026-62911 authentication bypass in Microsoft Exchange Server

CVE-2026-62911 is a critical authentication bypass vulnerability in Microsoft Exchange Server 2016, 2019, and SE, discovered by Orange Tsai and a Microsoft researcher, with a CVSS score of 9.8. Exploitation of CVE-2026-62911 allows attackers to access user mailboxes without authorization, enabling reading, sending, and downloading of emails and attachments, which can result in severe data breaches. CVE-2026-62911 was initially assessed as 'less likely' to be exploited, but the risk was elevated to 'High/High' by the NCSC following the release of proof-of-concept exploit code. Attackers can exploit CVE-2026-62911 using a capture-replay authentication bypass method, and the availability of PoC code increases the likelihood of exploitation. Microsoft released a security update on August 11, 2026, and organizations should apply this update, monitor Exchange Server logs for unusual activity, and consider implementing multi-factor authentication. The vulnerability affects all supported versions of Microsoft Exchange Server, increasing the urgency for remediation.

Top Threat Actors Reported This Week

Laundry Bear exploits Zimbra zero-click flaw in Western espionage campaign

Laundry Bear (Russian state-sponsored) conducts cyber espionage by exploiting a zero-click cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite. Laundry Bear deploys malicious JavaScript via email to execute code when messages are displayed, leveraging the Flowerbed framework for data exfiltration through DNS requests and adversary-in-the-middle phishing kits to capture credentials and session cookies. Laundry Bear targets unpatched Zimbra systems in the defense, education, energy, and government sectors, with confirmed attacks on the Dutch National Police and Ukrainian military personnel. The campaign uses Proton Mail accounts for phishing and can steal 90 days of emails, create unauthorized application passcodes, and maintain persistent access. Laundry Bear employs phishing domains such as mailnalysis[.]com, zimbrastat[.]com, zimbra-metadata[.]com, and zmailanalytics[.]com.

Lazarus Group leverages Windows zero-day in Operation Dream Job targeting defense sector

Lazarus Group (also tracked as Hidden Cobra), believed to be North Korea-affiliated, pursues cyber espionage and financial gain through Operation Dream Job, exploiting a Windows zero-day (CVE-2026-68820) to target the defense, aerospace, and aviation sectors. Lazarus Group utilizes DLL sideloading and trojanized PDF viewers to deploy MISTPEN and ForestTiger or Troy backdoors, supporting file operations, process management, and in-memory DLL injection. Lazarus Group targets organizations in France, Germany, Brazil, India, and other countries across Europe, Asia, and South America. The campaign uses sophisticated social engineering with fake job offers and compromised infrastructure, including Roundcube webmail and CMS platforms, for command and control via RelayShell. Researchers recommend applying Microsoft's security update for CVE-2026-68820, reviewing and monitoring IOC indicators, scrutinizing unsolicited recruiting outreach, verifying download requests, and monitoring for leaked credentials and exposed internet-facing systems.

Salt Typhoon infiltrates global telecom infrastructure in espionage operation

Salt Typhoon, a Chinese state-backed threat actor, conducts telecom espionage by targeting routers and telecom infrastructure to access sensitive communication data. Salt Typhoon exploits routing relationships and equipment managed across interconnected organizations, with logical controls proving insufficient and necessitating physical disconnection, as demonstrated by T-Mobile's security team physically cutting a network cable. Salt Typhoon targets at least 200 organizations across 80 countries, focusing on systems supporting lawful intercept obligations containing sensitive call records and metadata. The campaign highlights the challenges of removing nation-state actors from complex telecom environments. Recommended actions include continuous monitoring of router telemetry and anomalous traffic, strict segmentation between network environments, rapid validation of third-party network trust relationships, incident-response procedures that include onsite isolation options, and regular threat hunting to detect persistent access post-remediation.

BlueDelta deploys HOOKEDGE backdoor against European diplomatic targets

BlueDelta, a Russian state-sponsored threat group, engages in cyber espionage by deploying the HOOKEDGE backdoor against European government and diplomatic organizations. BlueDelta delivers HOOKEDGE via macro-enabled Microsoft Word documents with diplomatic-themed lures, using webhook[.]site for command and control and Microsoft Edge to disguise malicious traffic as legitimate web activity. BlueDelta targets organizations in Romania, Spain, and Türkiye, timing phishing documents with significant political events such as the Spanish and Moldovan meeting and Moldova's parliamentary elections. The malware employs a two-tier setup for high-value targets, increases beaconing intervals, and uses canary tracking pixels for document and email open monitoring. Recommended actions include blocking macros in internet-delivered documents, monitoring scheduled tasks launching scripts from user-writable folders, and flagging headless Microsoft Edge or automated requests to unknown webhooks or file-sharing services.

SilkParasite campaign uses AI-assisted malware against Central Asian governments

SilkParasite, linked to China, conducts cyber espionage by leveraging AI-assisted malware development to target government entities in Uzbekistan, Turkmenistan, Kyrgyzstan, Tajikistan, and Kazakhstan. SilkParasite employs DLL sideloading and phishing documents impersonating government entities, delivering malicious Microsoft Office files often packaged in password-protected RAR archives. SilkParasite focuses on Central Asian governments, continuing the intelligence-gathering efforts of UAC-0063 and FamousSparrow. The malware is modular, with AI-generated lures, test functions left in GoginRAT, and hardcoded AES keys, enabling dynamic loading of additional capabilities. The strategic use of AI allows SilkParasite to produce high-quality, low-footprint malware that enhances operational sophistication and evasion.

Frequently Asked Questions

  1. What is Medusa ransomware? Medusa ransomware is a ransomware family that encrypts victim data and threatens to leak or sell exfiltrated information unless a ransom is paid. Medusa ransomware exploits vulnerabilities in Fortra GoAnywhere, BeyondTrust, Fortinet EMS, and ScreenConnect, and leverages legitimate remote access tools such as AnyDesk, Atera, ConnectWise, eHorus, N-able, BeyondTrust, SimpleHelp, and Splashtop to maintain persistence and evade detection.

  2. What is Eclipse Ransomware? Eclipse Ransomware is a Ransomware-as-a-Service (RaaS) platform that targets Windows, Linux, NAS devices, VMware ESXi, and Nutanix environments, using a Rust-based payload for Windows and C++ variants for other platforms. Eclipse Ransomware employs ChaCha20 encryption, Kyber-based key exchange, automated lateral movement, defense evasion, and process termination, with configurable modes for speed and stealth.

  3. What is Gunra ransomware? Gunra ransomware is a ransomware-as-a-service operation that encrypts data and employs double-extortion tactics, threatening to leak stolen information via a Tor-based data leak site. Gunra ransomware gains initial access by exploiting known vulnerabilities in internet-facing devices such as firewalls and VPNs, and leverages penetration testers and ethical hackers as initial access brokers.

  4. What is DeadLock ransomware? DeadLock ransomware is an emerging Rust-based ransomware threat that uses decentralized infrastructure and double extortion to pressure victims. DeadLock ransomware employs resource-aware throttling, language geofencing to avoid execution in Russia, Ukraine, and Iran, and privilege escalation via command-line processing.

  5. What is Aurora ransomware? Aurora ransomware is a ransomware family that leverages SpaceX's AI Cursor Agent to facilitate post-compromise activities, including credential acquisition and internal reconnaissance. Aurora ransomware operators use tools such as NetExec’s BloodHound collector, PetitPotam, Coerce Plus, and PrinterBug to conduct NTLM relay attacks and lateral movement.

  6. What is CVE-2026-15409? CVE-2026-15409 and CVE-2026-15410 are critical pre-authentication server-side request forgery and path traversal vulnerabilities in the SonicWall SMA 1000 series, each carrying a CVSS score of 10.0. Successful exploitation of CVE-2026-15409 and CVE-2026-15410 enables attackers to gain root access without authentication, steal session tokens, and extract MFA seed data, resulting in persistent unauthorized access.

  7. What is CVE-2026-15410? CVE-2026-15409 and CVE-2026-15410 are critical pre-authentication server-side request forgery and path traversal vulnerabilities in the SonicWall SMA 1000 series, each carrying a CVSS score of 10.0. Successful exploitation of CVE-2026-15409 and CVE-2026-15410 enables attackers to gain root access without authentication, steal session tokens, and extract MFA seed data, resulting in persistent unauthorized access.

  8. What is CVE-2026-59310? CVE-2026-59310 is a critical path traversal vulnerability in VMware vCenter servers, with a CVSS score of 9.8. Exploitation of CVE-2026-59310 allows unauthenticated attackers to execute arbitrary code, leading to full compromise of affected systems.

  9. What is CVE-2026-68820? CVE-2026-68820 is a critical privilege escalation vulnerability in the Winsock component of Microsoft Windows, with a CVSS score of 8.8. Exploitation of CVE-2026-68820 enables attackers to escalate privileges from a low-privileged foothold to complete control over Windows systems.

  10. What is CVE-2026-45659? CVE-2026-45659 is a high-severity remote code execution vulnerability in Microsoft SharePoint, caused by deserialization of untrusted data, with a CVSS score of 8.8. Exploitation of CVE-2026-45659 allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers, posing a significant risk of ransomware deployment.

  11. What is CVE-2026-62911? CVE-2026-62911 is a critical authentication bypass vulnerability in Microsoft Exchange Server 2016, 2019, and SE, discovered by Orange Tsai and a Microsoft researcher, with a CVSS score of 9.8. Exploitation of CVE-2026-62911 allows attackers to access user mailboxes without authorization, enabling reading, sending, and downloading of emails and attachments, which can result in severe data breaches.

  12. What is CVE-2026-63077? CVE-2026-63077 is a critical pre-authentication remote code execution vulnerability in JetBrains TeamCity On-Premises before versions 2025.11.7 and 2026.1.3, with a CVSS score of 9.8. Exploitation of CVE-2026-63077 allows attackers to compromise the TeamCity server, access build secrets, modify build configurations, and disrupt the software supply chain.

  13. What is Laundry Bear? Laundry Bear, a Russian state-sponsored group, conducts cyber espionage by exploiting a zero-click cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite. Laundry Bear deploys malicious JavaScript via email to execute code when messages are displayed, leveraging the Flowerbed framework for data exfiltration through DNS requests and adversary-in-the-middle phishing kits to capture credentials and session cookies.

  14. What is Lazarus Group? Lazarus Group (also tracked as Hidden Cobra), believed to be North Korea-affiliated, pursues cyber espionage and financial gain through Operation Dream Job, exploiting a Windows zero-day (CVE-2026-68820) to target the defense, aerospace, and aviation sectors. Lazarus Group utilizes DLL sideloading and trojanized PDF viewers to deploy MISTPEN and ForestTiger or Troy backdoors, supporting file operations, process management, and in-memory DLL injection.

  15. What is Salt Typhoon? Salt Typhoon, a Chinese state-backed threat actor, conducts telecom espionage by targeting routers and telecom infrastructure to access sensitive communication data. Salt Typhoon exploits routing relationships and equipment managed across interconnected organizations, with logical controls proving insufficient and necessitating physical disconnection, as demonstrated by T-Mobile's security team physically cutting a network cable.

Discover Related Resources