Suspected Ransomware Operator Used Claude Code to Steal Data and Map Backups
Gambit observed Claude Code inside six intrusions. Hunt the test VPN account, rogue LDAP listeners, backup discovery, SQL staging, and firewall restores.
Read article →Reader view
Choose the default article length.
Threat actors, malware campaigns, phishing, exploitation, and incident activity.
Gambit observed Claude Code inside six intrusions. Hunt the test VPN account, rogue LDAP listeners, backup discovery, SQL staging, and firewall restores.
Read article →Attackers are exploiting a Zimbra SNMP flaw through crafted SMTP requests. Version 10.1.20 fixes it; exposed servers need log and file review.
Read article →A blank file entry bypasses Elementor Pro upload checks on exposed forms. Version 4.2.2 fixes the flaw, but patched sites still need to hunt for PHP left behind.
Read article →CISA now ties CVE-2025-60710 to ransomware. The local Windows flaw needs an existing foothold, then lets an attacker elevate to SYSTEM.
Read article →Pantheon counted 45 million wp2shell attempts in one week. Defenders should verify current WordPress builds and review exposed sites for persistent access.
Read article →A compromised crates.io account poisoned three Rust packages. Builds ran a downloader; 2,285 arrayref downloads now require cache, lockfile, and host checks.
Read article →CISA now links CVE-2026-45659 to ransomware. Check exact SharePoint builds, then investigate whether low-privilege access reached the farm before patching.
Read article →A signed ClickOnce app delivered two stealers and an hVNC RAT after a fake Web3 interview. Hunt per-user ClickOnce records, then rotate every secret reachable from affected hosts.
Read article →Microsoft's August updates fix an AFD.sys race used in attacks; defenders must verify fixed builds and investigate pre-patch privilege escalation.
Read article →Customer contact data is public after a social-engineering breach; defenders should harden support and identity checks against targeted impersonation.
Read article →August Windows updates fix a public registry-hive privilege escalation; defenders can hunt its staging files, virtual paths, and unusual DLL loads.
Read article →Exposed ASA and FTD remote-access services need release-specific hot fixes; Cisco offers no workaround for the exploited denial-of-service flaw.
Read article →Government agencies traced Gunra from exploited edge devices through credential theft, cloud exfiltration, backup deletion, and cross-platform ransomware.
Read article →