Relevant vulnerabilities selected by criticality, active exploitation and how widely the affected technology is used, written automatically from NVD, CISA KEV and vendor advisory data. RSS
A previously unknown actor calling itself Zawoo began publishing victims on 29 August 2026 and has now listed 26 posts on its leak site. Most of the named organisations are European SMEs, with a clear German majority.
Ransomware ZawooAlemaniaIndustria y tecnologíaPymes europeas
A previously unknown actor calling itself Endzone began listing victims on its leak site on 18 September 2026 and has posted four claims so far, including telecoms, technology and professional services firms, mostly in the United States.
Grupo EndzoneExtorsión de datosSector telecomunicacionesEstados Unidos
A previously unknown actor calling itself Spirals launched its leak site on 14 September 2026 and has posted seven entries, most of them healthcare organisations in North America. Its sudden arrival is a good reason to revisit basic anti-extortion defences.
A previously undocumented actor known as Blacklocks opened its leak site on 6 September 2026 and has since posted three claimed victims in South Korea and South Africa. Its lack of known history calls for caution and for tightening basic security controls.
Ransomware BlacklocksCorea del SurSudáfricaNuevo grupo de extorsión
A previously unknown actor calling itself Shiba activated its leak site on 28 September 2026 and has posted two entries so far. No link to earlier groups has been established, marking it as an emerging threat worth monitoring.
CVE-2026-100758, rated 9.6 on the CVSS scale, allows attackers to break out of the browser sandbox via the DOM: Navigation component. It affects Firefox, Firefox ESR and Thunderbird, and is already fixed in the releases Mozilla published on 29 September 2026.
Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdCVE-2026-100758
A recently emerged extortion group, Emperador, listed Swedish manufacturer Electrolux among its victims on 28 September 2026. The claim is unverified, but it highlights the growing pressure on European manufacturing.
Grupo EmperadorSector industrialSueciaExtorsión de datos
A previously unknown ransomware actor identified as Vexy began publishing victims on 3 September 2026 and has since listed 18 entries on its leak site, including a French telecoms company. Its rapid publishing pace makes it an emerging threat worth watching.
Ransomware VexyExtorsión con filtración de datosSector telecomunicacionesFrancia
CISA has added the critical authentication bypass in the Cisco Catalyst SD-WAN Manager API to its KEV catalog, with a federal remediation deadline of 3 October 2026. Any organisation running this platform, especially if internet-facing, should patch immediately and hunt for indicators of compromise.
Cisco has issued an advisory for CVE-2026-76504, a critical flaw (CVSS 9.8) in the Catalyst SD-WAN Manager API that lets an unauthenticated remote attacker access the system with administrator privileges. A software update is available, but there is no workaround.
CISA has added CVE-2026-86950, the CoreGraphics vulnerability Apple patched on 28 September, to its KEV catalogue, confirming it is being exploited in real-world attacks. It affects iPhone, iPad and Mac, with a federal remediation deadline of 2 October 2026.
Google has released a Stable channel update for Chrome on desktop that fixes 95 vulnerabilities. Twenty-three of them carry a CVSS score of 9.6 and could allow code execution outside the browser sandbox simply by visiting a malicious page. Chromium-based browsers such as Microsoft Edge are also affected.
Google ChromeGoogle Chrome for AndroidGoogle Chrome for iOSChromiumMicrosoft Edge95 CVEs