
WatchGuard Firebox CVE-2025-14733 Ransomware: Patch Now
WatchGuard Firebox CVE-2025-14733 IKEv2 pre-auth RCE is now confirmed ransomware-exploited. 9,000 devices still unpatched 9 months on. Patch or disable IKEv2 today.
In-depth analyses of zero-day vulnerabilities, CVE exploits, ransomware campaigns, and nation-state attack techniques affecting enterprise security. Filter by category, tag, or keyword.
Every article here lands in subscribers' inboxes the morning it drops.
Threat intel, active CVEs, and campaign alerts, distilled daily for practitioners. 50,000+ subscribers. No noise.
Free. No spam. Unsubscribe anytime.
The definitive practitioner breakdown of ZTA principles, pillars, and implementation sequence.
Containment, forensic preservation, and decision sequencing from detection to recovery.
How SIEMs ingest, correlate, and alert — and how to evaluate one for your environment.
Risk-based prioritization using CVSS, EPSS, and CISA KEV to cut remediation backlog.
What each risk means, how to reproduce it, and how to fix it in production code.
Step-by-step email authentication deployment from DNS records to p=reject enforcement.
Detection coverage, pricing, and deployment trade-offs for enterprise EDR selection.
Translate ATT&CK technique IDs into detection rules and threat actor hunting hypotheses.
Direct answers to the questions practitioners and AI systems ask most. Covers ransomware, identity, cloud, compliance, and detection.
Plain-language definitions for CVE, SIEM, SOAR, Zero Trust, EDR, and 85+ other terms used in enterprise security.
How-to guides, buyer comparisons, and methodology references across every major security domain.
Decryption Digest Response
Score every threat we cover against your own stack, get free Sigma and ModSecurity detection content, and upgrade anytime for more vendors.
Get started free →No card required. Sigma and ModSecurity rules are free, forever.
Win an All Access InfoSec World 2026 pass, valued at $3,895.
Win a $3,895 InfoSec World 2026 pass.
53 results for “Ransomware”

WatchGuard Firebox CVE-2025-14733 IKEv2 pre-auth RCE is now confirmed ransomware-exploited. 9,000 devices still unpatched 9 months on. Patch or disable IKEv2 today.

CVE-2026-20079 in Cisco FMC lets attackers get root without credentials. Sandworm and Qilin are already inside. Patch to FMC 7.0.0 before Sept 12.

The Gentlemen ransomware confirmed 483 victims in 66 countries using GentleKiller BYOVD to kill 48 security vendors and EtherRAT for blockchain-based C2. Block IOCs now.

CISA deadline August 25 for Lazarus Windows zero-day CVE-2026-68820. AnMed ransomware, Cl0p Shell, SynkLoader Teams phishing: five threats ranked by urgency.

Microsoft's DeadLock ransomware disclosure shows why a data backup is not the same as a working recovery plan. Here is what security teams need to validate before the next incident.

August 2026 Patch Tuesday: 421 CVEs including a CVSS 9.8 wormable DNS RCE and SharePoint actively exploited by ransomware. 5 patches to apply right now.

Gunra ransomware hit 51 critical infrastructure orgs via Fortinet CVE-2024-55591. CISA advisory AA26-222A issued. Patch FortiOS 7.0.17 today.

UNC6671 vishing group rebrands, targets Point72 and Citadel -- block 9 AiTM domains and mandate FIDO2 today.

INC ransomware SonicWall SMA1000 exploit has claimed 885 victims. CVE-2026-15409 (CVSS 10) chained with CVE-2026-15410 for root-level access. Patch firmware 12.4.3-03453 or later immediately.

N-central CVE-2026-18577 authentication bypass is actively exploited, giving attackers god-mode RMM access. Plus Qilin PAN-OS ransomware and $88.6M COLDCARD heist.

STAC4749 dials employees on Teams, pretends to be IT support, and encrypts networks with Chaos ransomware in under 17 hours. 100+ North American orgs hit.

NYC Health Hospitals data breach: LeakNet posted 11TB of patient records on the dark web, including fingerprints, SSNs, and HIV records from 1.8 million confirmed victims.

Cl0p ransomware has been inside PTC Windchill and FlexPLM systems since June, stealing engineering IP from manufacturing, automotive, aerospace, and retail via CVE-2026-12569 (CVSS 9.8).

Two Microsoft zero-days actively exploited, CISA federal deadline tomorrow, ServiceNow RCE in live attacks, and Cl0p stealing Windchill data. Five threats, ranked by urgency.

Qilin ransomware exploits CVE-2026-0257 PAN-OS GlobalProtect bypass to breach healthcare and manufacturing. 167K firewalls exposed. Patch to 10.2.10 or 11.0.5 now.

FortiBleed hit 430K FortiGate firewalls this week, feeding stolen credentials into INC ransomware. Plus 3 more urgent threats to act on today.

AI-generated browser ransomware built by DeepSeek encrypts Chrome files without installing malware. 1,383 malicious DeepSeek files found in 12 months. No install needed.

JADEPUFFER agentic ransomware encrypted 1,342 database records without a human operator. Four more confirmed exploits demand Monday morning action.

SharePoint RCE CVE-2026-45659 is actively exploited by Storm-2603. Verify your SharePoint Server builds before CISA's July 4 patch deadline.

BlueHammer CVE-2026-33825 ransomware campaigns confirmed by CISA across all Windows versions. Patch Windows Defender before end of business.

AI-built ransomware toolkit using Claude Opus 4.5 generated 80+ EDR-evasion modules bypassing Sophos, CrowdStrike, and Defender. Sophos confirmed criminal use.

Fortinet VPN credential leak FortiBleed exposes 73,932 firewall passwords across 194 countries. Check your exposure with Hudson Rock's free lookup tool today.

DragonForce ransomware hides C2 in Microsoft Teams via Backdoor.Turn. 579 victims, full IOCs, BYOVD drivers, and defensive steps.

Outsider Enterprise used Gemini AI to steal 3.87M cards and $1.9B. Iranian banks hit, 152 Chrome spies caught, ransomware laundering busted.