Skip to main content
Techx4u Pvt Ltd

Threat intelligence · live

Live cyber threat report

Ransomware activity and actively exploited vulnerabilities from public threat sources — the same picture our analysts start the day with. Updated every 30 minutes.

Last updated 01 Oct, 16:45 UTC

Ransomware

Ransomware attacks claimed in the last 2 days

Totals from ransomware leak sites, by group, sector and country. We never name victims.

Claimed in the last 24 hours

36

Claimed in the last 2 days

100

Most hit sector

Manufacturing

Most active groups

  • thegentlemen25
  • Storm11
  • lamashtu10
  • incransom5
  • genesis4

Most targeted sectors

  • Manufacturing21
  • Healthcare17
  • Professional Services12
  • Technology10
  • Other10

Most targeted countries

  • United States42
  • Germany10
  • Italy4
  • United Kingdom4
  • Brazil3

Exploited vulnerabilities

Newly added to CISA's Known Exploited Vulnerabilities list

7 added in the last 7 days · 1,730 in the catalog. If you run any of these products, patch now.

  • CVE-2026-76504

    Added yesterday

    Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

    Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.

  • CVE-2026-86950

    Added 2 days ago

    Apple Multiple Products Out-of-Bounds Write Vulnerability

    Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

  • CVE-2026-88772

    Added 4 days ago

    Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

    Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service

  • CVE-2026-88771

    Added 4 days ago

    Citrix NetScaler Improper Input Validation Vulnerability

    Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands.

  • CVE-2026-67279

    Added 6 days ago

    Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

    Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060.

  • CVE-2026-65660

    Added 6 days ago

    Microsoft SharePoint Code Injection Vulnerability

    Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.

  • CVE-2026-87902

    Added 6 days ago

    WordPress Core Remote File Inclusion Vulnerability

    WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution.

  • CVE-2026-5430

    Added 7 days ago

    WSO2 Multiple Products Path Traversal Vulnerability

    WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution.

  • CVE-2026-71362

    Added 7 days ago

    Adobe Commerce and Magento Incorrect Authorization Vulnerability

    Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

  • CVE-2026-93952

    Added 9 days ago

    Arista VeloCloud Orchestrator Improper Input Validation Vulnerability

    Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

  • CVE-2026-94127

    Added 9 days ago

    F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability

    F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

  • CVE-2026-93616

    Added 9 days ago

    Check Point Multiple Products Path Traversal Vulnerability

    Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.

Not sure if you are exposed? Book a vulnerability assessment — we find affected systems and help you patch them.

FAQ

About this report

Where does this threat data come from?

Vulnerabilities come from the CISA Known Exploited Vulnerabilities (KEV) catalog — flaws the US Cybersecurity and Infrastructure Security Agency has confirmed are being exploited in real attacks. Ransomware figures come from ransomware.live, which tracks the leak sites ransomware groups use to publish their claims. Both are refreshed on this page every 30 minutes.

Why don't you list the names of ransomware victims?

Leak-site listings are part of the extortion. Repeating victim names puts more pressure on organisations that are already under attack, so we only show totals by group, sector and country.

What should I do if a vulnerability here affects my systems?

Patch or apply the vendor's mitigation as a priority — KEV entries are being used in real attacks, not just theoretically exploitable. If you are not sure whether you are exposed, our vulnerability assessment finds affected systems and our managed patching closes them. Contact us and an engineer will help.

Is a ransomware claim the same as a confirmed attack?

Not always. These are claims published by criminal groups. Most turn out to be real, but some are exaggerated or recycled from earlier breaches. Treat the trend as reliable and any single claim with caution.

Sources: CISA Known Exploited Vulnerabilities catalog (public domain) and ransomware.live. Ransomware figures are claims made by criminal groups and may include exaggerated or recycled claims.

Worried something on this list affects you?

Tell us what you run. An engineer will check your exposure and give you a straight answer — no obligation.