Cybersecurity Intelligence Report  2026-06-27

CRITICAL

[11] First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild (SecurityWeek)  CVEs: CVE-2026-12569

CISA has added the remote code execution flaw CVE-2026-12569 to its Known Exploited Vulnerabilities catalog.

The post First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild appeared first on SecurityWeek.

[11] Ransomware gangs find Europe’s weakest link in third-party suppliers (HelpNetSecurity)

Ransomware attacks against European organizations increased during the first months of 2026, with third-party suppliers becoming a major entry point for attackers. Black Kite examined 2,066 ransomware incidents across 31 countries between January 2025 and April 2026 in its 2026 European Cyber Risk Report. Country distribution of ransomware attacks (Source: Black Kite) “Three forces are converging on European organisations at once: ransomware is accelerating, supply chains are becoming a prima

[10] Chinese-Speaking APT Deploys New TinyRCT Backdoor in Southeast Asia Campaign (TheHackerNews)
A Chinese-speaking advanced persistent threat (APT) actor has been linked to a new custom backdoor called TinyRCT as part of cyber attacks aimed at government entities and critical infrastructure in Southeast Asia. The activity, particularly aimed at state-owned enterprises in the energy and government sectors, has been attributed to a threat actor called CL-STA-1062, which Palo Alto Networks

[10] CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue (TheHackerNews)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability in question is

CISA KEV (last 14 days)

CVEVendor/ProductScoreRequired Action

RANSOMWARE VICTIMS (today)

Unknown: [RANSOMWARE] dragonforce leaked Aptora (), [RANSOMWARE] incransom leaked callhorton.com (), [RANSOMWARE] incransom leaked johndufourlaw.com (), [RANSOMWARE] incransom leaked theswansonlawgroup.com (), [RANSOMWARE] play leaked Benchmark Industrial Supply (), [RANSOMWARE] akira leaked Precise Forms (), [RANSOMWARE] nova leaked NSW Rural Fire Service (), [RANSOMWARE] payload leaked Clínica La Sabana (), [RANSOMWARE] payload leaked Software Arge (), [RANSOMWARE] payload leaked Mosaic Partners (), [RANSOMWARE] chaos leaked ingerman.com (), [RANSOMWARE] Wallstreet leaked Omax Autos (), [RANSOMWARE] AiLock leaked Hokua (), [RANSOMWARE] nova leaked vslmarine (), [RANSOMWARE] cmdorganization leaked Kohinoor Mills ()

NEWS

[8] CISA sets urgent deadline to fix Cisco flaw exploited in attacks (BleepingComputer)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is giving federal agencies until Sunday to patch a vulnerability in Cisco Unified Communications Manager Server that is being actively exploited. [...]

[7] In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs (SecurityWeek)

Other noteworthy stories that might have slipped under the radar: Russia used Cellebrite to hack activist’s phone, Five Eyes issue urgent AI threat warning, macOS Gaslight backdoor, Scattered Spider guilty pleas.

The post In Other News: Chinese Mythos-Like AI, Tata Electronics Breach, Snyk Layoffs appeared first on SecurityWeek

[7] Critical open-source projects get a new security framework (HelpNetSecurity)

Open source software projects are getting a new framework for handling security vulnerabilities as AI shortens the time between flaw discovery and exploitation. The Linux Foundation has launched Akrites, an industry initiative that brings together technology companies, financial institutions, security vendors, AI companies, and open source projects to support the remediation and disclosure of vulnerabilities affecting widely used open source software. Akrites aims to establish a common proces

[7] [RANSOMWARE] dragonforce leaked Aptora (ransomware.live/dragonforce)
Victim: Aptora | Group: dragonforce | Website: aptora.com | Country: US | Details: Aptora is an aggressively growing software company in Lenexa, KS. The company offers award-winning software and consulting services to the service and contracting industries. In 2006, the company were voted one of the top twenty-five companies in the Kansas City area by the Business Journal. Aptora

[6] Polymarket customers lose $3 million in supply-chain attack (BleepingComputer)
Polymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platform's frontend following a breach at a third-party vendor. [...]

[6] Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack (TheHackerNews)
Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades malware family that has compromised a new set of npm packages, even as it has propagated to the Go ecosystem. "The latest activity includes malicious npm releases affecting LeoPlatform and RStreams packages, GitHub Actions workflow abuse, and a related Go

[6] Google Details Turla's New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks (TheHackerNews)
The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that has been deployed against government and military organizations in Ukraine, and entities that have an interest in Italian foreign policy. Describing the Windows backdoor as continually developed by the hacking group, Google Threat Intelligence Group (

[6] More Klue Breach Victims Identified as Hackers Get Hacked (SecurityWeek)

Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact.

The post More Klue Breach Victims Identified as Hackers Get Hacked appeared first on SecurityWeek.

[5] New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets (TheHackerNews)
DirtyClone is a new Linux kernel privilege escalation in the DirtyFrag family. JFrog Security Research published a working exploit walkthrough for the flaw on June 25, the first public demonstration for this variant. Tracked as CVE-2026-43503 (CVSS 8.8), it lets a local user corrupt file-backed memory through a cloned network packet and gain root. The patch landed in

[5] Synology issues critical fix for MailPlus Server vulnerabilities (HelpNetSecurity)

Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update fixes three flaws: CVE-2026-13136, stemming from faulty authorization checks, may allow remote attackers to read or write arbitrary files and conduct denial-of-service (DoS) attacks CVE-2026-13135, caused by improper restriction of communication channel to intended endpoints, may allow remote attackers to access internal s

[5] [RANSOMWARE] incransom leaked callhorton.com (ransomware.live/incransom)
Victim: callhorton.com | Group: incransom | Website: callhorton.com | Country: US | Details: Horton Personal Injury Lawyers is the premier law firm at not protecting it's clients confidential data.

[5] [RANSOMWARE] incransom leaked johndufourlaw.com (ransomware.live/incransom)
Victim: johndufourlaw.com | Group: incransom | Website: johndufourlaw.com | Country: US | Details: If you find yourself injured, disabled or deep in debt, the Law Office of John Dufour is ready to help. John brings 25 years of focused experience and favorable outcomes. Our success is built on attentive service and attention to the legal details.

[5] [RANSOMWARE] incransom leaked theswansonlawgroup.com (ransomware.live/incransom)
Victim: theswansonlawgroup.com | Group: incransom | Website: theswansonlawgroup.com | Country: US | Details: Meet Ben Swanson. The clients confidentiality worst nightmare.

[5] [RANSOMWARE] play leaked Benchmark Industrial Supply (ransomware.live/play)
Victim: Benchmark Industrial Supply | Group: play | Website: www.benchmarkinc.com | Country: US | Details: United States

[5] [RANSOMWARE] akira leaked Precise Forms (ransomware.live/akira)
Victim: Precise Forms | Group: akira | Website: preciseforms.com | Country: US | Details: Precise Forms, Inc. specializes in manufacturing high-quality aluminum forms for concrete construction, offering a complete line of standard and decorative forms along with necessary accessories. Their products cater to a variety of applications including residential homes, commercialbuildings, and

[5] [RANSOMWARE] nova leaked NSW Rural Fire Service (ransomware.live/nova)
Victim: NSW Rural Fire Service | Group: nova | Website: rfs.nsw.gov.au | Country: AU | Details: Data Leaked, Updated from Nova Team by investigate Affiliate provided informations.

[5] [RANSOMWARE] payload leaked Clínica La Sabana (ransomware.live/payload)
Victim: Clínica La Sabana | Group: payload | Website: clinicalasabana.com | Country: CR | Details: Clínica La Sabana (clinicalasabana.com) is a medical institution located in Bogotá, Colombia, specializing in the provision of comprehensive healthcare services. The company offers outpatient care, specialist consultations, surgical procedures, and physical therapy. Its primary areas of expertise in

[5] [RANSOMWARE] payload leaked Software Arge (ransomware.live/payload)
Victim: Software Arge | Group: payload | Website: softwarearge.com | Country: TR | Details: Software Arge is a leading technology company established in 2016, specializing in data analytics, data integration, data management, and artificial intelligence solutions tailored for enterprises. They offer a range of products including Qlik Cloud Analytics, Qlik Sense, and various Talend solution

[5] [RANSOMWARE] payload leaked Mosaic Partners (ransomware.live/payload)
Victim: Mosaic Partners | Group: payload | Website: mosaic-partners.com | Country: CH | Details: The Swiss company Mosaic Partners specializes in providing IT services, software development, and systems engineering. It creates tailored digital solutions and applications to optimize business processes, covering areas such as CRM, cloud computing, and process management (e.g., in winemaking). The

[5] [RANSOMWARE] chaos leaked ingerman.com (ransomware.live/chaos)
Victim: ingerman.com | Group: chaos | Website: ingerman.com | Country: DE | Details: Ingerman is a developer, builder and manager of multifamily housing communities throughout the Mid-Atlantic region.

[5] [RANSOMWARE] Wallstreet leaked Omax Autos (ransomware.live/Wallstreet)
Victim: Omax Autos | Group: Wallstreet | Website: omaxauto.com | Country: IN | Details: OMAX Autos Limited is a leading manufacturer of sheet metal components, specializing in the production of auto and non-auto components.

[5] [RANSOMWARE] AiLock leaked Hokua (ransomware.live/AiLock)
Victim: Hokua | Group: AiLock | Website: hokua.net | Country: CL | Details: Hokua Suites is a luxury resort-style residential condominium located in Honolulu, Hawaii. The complex offers upscale apartments with ocean views and a full range of premium amenities.

[5] [RANSOMWARE] nova leaked vslmarine (ransomware.live/nova)
Victim: vslmarine | Group: nova | Website: vslmarine.com | Country: IN | Details: VSL Marine Technology Pvt. Ltd. is an ISO 9001:2015 certified company specializing in 3D scanning and engineering services, particularly in marine and offshore sectors. They offer a range of services including marine retrofits, engineering design, naval architecture, and e-learning training solution

[5] [RANSOMWARE] cmdorganization leaked Kohinoor Mills (ransomware.live/cmdorganization)
Victim: Kohinoor Mills | Group: cmdorganization | Website: www.kohinoormills.com | Country: IN | Details: Kohinoor Mills Limited is a leading textile manufacturer in Pakistan, established in 1948, specializing in premium fabrics for global brands. The company offers a diverse range of products including western, ethnic, workwear, technical textiles, and upholstery, all produced with a commitment to sust

SUMMARY

Total new items: 52
Critical count: 4
Ransomware groups active: 1
Top CVEs to patch urgently: CVE-2026-12569, CVE-2026-43503, CVE-2026-13135, CVE-2026-13136, CVE-2026-46331

Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live