Cybersecurity Intelligence Report  01 July 2026

CRITICAL SECTION

[16] BlueHammer Vulnerability Exploited in Ransomware Attacks (SecurityWeek) — CVE-2026-33825

The Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released.

The post BlueHammer Vulnerability Exploited in Ransomware Attacks appeared first on SecurityWeek.

[14] Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817) (HelpNetSecurity) — CVE-2026-46817

Exploitation attempts targeting a critical vulnerability (CVE-2026-46817) in Oracle Payments, the payment-processing module within Oracle’s E-Business Suite (EBS), have been spotted over the weekend, threat intelligence company Defused warned on Monday. The detected exploitation attempts (Source: Defused) “On 27 June 2026 our Oracle E-Business Suite decoys recorded the first in-the-wild exploitation of CVE-2026-46817 — roughly six weeks after Oracle’s May 2026 patch and before any

[13] CISA: Windows BlueHammer flaw now exploited by ransomware gangs (BleepingComputer)
CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks. [...]

[13] Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints (TheHackerNews) — CVE-2026-33017
Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnerability in Langflow, indicating threat actors are scanning and targeting exposed artificial intelligence (AI)

[10] Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild (TheHackerNews) — CVE-2026-46817
A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper privilege management and authentication flaw in Oracle Payments that could be abused to take over susceptible instances. "Easily exploitable vulnerability allows

CISA KEV

No CISA KEV items in the last 14 days.

RANSOMWARE VICTIMS (DLS Monitoring)

Unknown: [RANSOMWARE] blacknevas leaked Arkin Group, [RANSOMWARE] pear leaked Sociedad Latina, [RANSOMWARE] aurora leaked Primed Halberstadt Medizintechnik, [RANSOMWARE] play leaked Western Construction, [RANSOMWARE] chaos leaked universalplant.com, [RANSOMWARE] BrainCipher leaked paipharma.com, [RANSOMWARE] genesis leaked Brooklyn Defender Services, [RANSOMWARE] settra leaked petradiamonds.com, [RANSOMWARE] settra leaked orion4value.com, [RANSOMWARE] incransom leaked https://sza.it/, [RANSOMWARE] settra leaked clc-tn.com, [RANSOMWARE] settra leaked joyconstructionnyc.com, [RANSOMWARE] settra leaked wilfley.com, [RANSOMWARE] qilin leaked Chamco, [RANSOMWARE] qilin leaked Hemmersbach GmbH & Co. KG, [RANSOMWARE] pear leaked Spector and Lenz, PC, [RANSOMWARE] pear leaked ORA Group Information, [RANSOMWARE] gunra leaked Pirámide Seguros, [RANSOMWARE] gunra leaked on-us, [RANSOMWARE] gunra leaked Yuditec S.A., [RANSOMWARE] akira leaked About Todd Hamaker & Johnson, [RANSOMWARE] settra leaked rcfassoc.com, [RANSOMWARE] akira leaked Advanced Business Systems, [RANSOMWARE] settra leaked owensborograin.com, [RANSOMWARE] settra leaked ilex-paysages.com, [RANSOMWARE] settra leaked touredge.com, [RANSOMWARE] settra leaked vcnyhome.com, [RANSOMWARE] settra leaked infinedi.net, [RANSOMWARE] cmdorganization leaked Medlink Georgia, [RANSOMWARE] cmdorganization leaked Port Angeles Composite, [RANSOMWARE] embargo leaked www.maytrucking.com

NEWS

[9] SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) (HelpNetSecurity) —

Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. The malware is capable of targeting Windows, macOS, and Linux systems, and “collects credentials associated with cloud platforms, source control, package registries, infrastructure tooling, AI development assistants, browsers, SSH, and cryptocurrency wallets,” BlackPoint Cyber’s researchers discovered.

[8] Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer (TheHackerNews) — An unknown threat actor has been observed exploiting a recently disclosed maximum-severity security flaw in SimpleHelp to deliver two previously unreported malware families, TaskWeaver and Djinn Stealer. The intrusion involves the exploitation of CVE-2026-48558 (CVSS score: 10.0), a critical authentication bypass vulnerability impacting the OpenID Connect (OIDC) flow that an unauthenticated

[8] Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks (SecurityWeek) —

Decades-old Bash shell tricks can bypass safeguards in most open source AI coding agents, potentially turning malicious repositories into supply chain attack vectors.

The post Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks appeared first on SecurityWeek.

[8] Aikido Security acquires Root to expand backported fixes for open source vulnerabilities (HelpNetSecurity) —

Aikido Security has acquired Root, uniting behind a shared mission to make it easy for developers and agents to build with secure open source and tackle the growing threat of supply chain attacks. Open source is the foundation of almost every application in the world, and it has become the primary entry point for attackers. Organizations face two converging threats: attackers hide malware inside the open source packages that applications depend on, and vulnerabilities sit …

[7] [RANSOMWARE] pear leaked Sociedad Latina (ransomware.live/pear) — Victim: Sociedad Latina | Group: pear | Website: sociedadlatina.org | Country: US | Details: Support in education, civic engagement, workforce development, and arts and culture, specifically tailored for multilingual learners

[5] [RANSOMWARE] aurora leaked Primed Halberstadt Medizintechnik (ransomware.live/aurora) — Victim: Primed Halberstadt Medizintechnik | Group: aurora | Website: Primed Halberstadt Medizintechnik | Country: DE | Details: [manufacturer] *** GmbH — a German manufacturer of medical devices founded in 1946 and now part of the PE-backed PP Medtech group (Wiesmann & Co. KG). The exfiltration captured four entire server volumes: Daten (883 GB) — File server: 289 employee home directories (547 GB), Czech subsidiary data (

[5] [RANSOMWARE] play leaked Western Construction (ransomware.live/play) — Victim: Western Construction | Group: play | Website: www.wciboise.com | Country: US | Details: United States

[5] [RANSOMWARE] chaos leaked universalplant.com (ransomware.live/chaos) — Victim: universalplant.com | Group: chaos | Website: www.zoominfo.com/c/universal-plant-services-inc/353963066 | Country: US | Details: FINAL NOTICE: UNIVERSAL PLANT SERVICES (UPS) We are in possession of 315 GB of your corporate, financial, and operational data. Our analysis confirms that this archive contains highly sensitive information, including: Financial & Accounting: Full audits, tax filings (ADP), payroll, bank transa

[5] [RANSOMWARE] BrainCipher leaked paipharma.com (ransomware.live/BrainCipher) — Victim: paipharma.com | Group: BrainCipher | Website: paipharma.com | Country: BR | Details: [AI generated] N/A

[5] [RANSOMWARE] genesis leaked Brooklyn Defender Services (ransomware.live/genesis) — Victim: Brooklyn Defender Services | Group: genesis | Website: . | Country: US | Details: A legal organization dedicated to safeguard the rights of its clients

[5] [RANSOMWARE] settra leaked petradiamonds.com (ransomware.live/settra) — Victim: petradiamonds.com | Group: settra | Website: petradiamonds.com | Country: GB | Details: THE DIAMOND ARCHIVE: Petra Diamonds Limited Documents PROLOGUE A complete employee directory with na...

[5] [RANSOMWARE] settra leaked orion4value.com (ransomware.live/settra) — Victim: orion4value.com | Group: settra | Website: orion4value.com | Country: DE | Details: THE CERTIFICATE AS A VULNERABILITY: Documents of Orion Registrar Inc. PROLOGUE Financial reports and...

[5] [RANSOMWARE] incransom leaked https://sza.it/ (ransomware.live/incransom) — Victim: https://sza.it/ | Group: incransom | Country: IT | Details: client, contracts, personal, NDA and other

[5] [RANSOMWARE] settra leaked clc-tn.com (ransomware.live/settra) — Victim: clc-tn.com | Group: settra | Website: clc-tn.com | Country: TN | Details: City Lumber Company: Building Materials in Tennessee — What Lies Behind the Small Sign PROLOGUE In o...

[5] [RANSOMWARE] settra leaked joyconstructionnyc.com (ransomware.live/settra) — Victim: joyconstructionnyc.com | Group: settra | Website: joyconstructionnyc.com | Country: US | Details: Joy Construction Corp: $1.3 Billion in Affordable Housing — and $8.7 Million to a Shareholder in Six...

[5] [RANSOMWARE] settra leaked wilfley.com (ransomware.live/settra) — Victim: wilfley.com | Group: settra | Website: wilfley.com | Country: US | Details: SEAL FAILURE A company that builds pumps for chemical and defense production — and undertakes to con...

[5] [RANSOMWARE] qilin leaked Chamco (ransomware.live/qilin) — Victim: Chamco | Group: qilin | Website: www.chamco.com | Details: N/A

[5] [RANSOMWARE] qilin leaked Hemmersbach GmbH & Co. KG (ransomware.live/qilin) — Victim: Hemmersbach GmbH & Co. KG | Group: qilin | Website: www.hemmersbach.com | Country: DE | Details: N/A

[5] [RANSOMWARE] pear leaked Spector and Lenz, PC (ransomware.live/pear) — Victim: Spector and Lenz, PC | Group: pear | Website: spectorandlenz.com | Country: US | Details: Firm provides legal representation to clients facing disability, injury, or serious illness

[5] [RANSOMWARE] pear leaked ORA Group Information (ransomware.live/pear) — Victim: ORA Group Information | Group: pear | Website: groupe-ora.com | Country: FR | Details: Specializing in retail and the point-of-sale experience

[5] [RANSOMWARE] gunra leaked Pirámide Seguros (ransomware.live/gunra) — Victim: Pirámide Seguros | Group: gunra | Website: segurospiramide.com | Country: VE | Details: [AI generated] N/A

[5] [RANSOMWARE] gunra leaked on-us (ransomware.live/gunra) — Victim: on-us | Group: gunra | Website: on-us.com | Country: HK | Details: [AI generated] N/A

[5] [RANSOMWARE] gunra leaked Yuditec S.A. (ransomware.live/gunra) — Victim: Yuditec S.A. | Group: gunra | Website: yuditec.com | Country: UY | Details: [AI generated] N/A

[5] [RANSOMWARE] akira leaked About Todd Hamaker & Johnson (ransomware.live/akira) — Victim: About Todd Hamaker & Johnson | Group: akira | Details: Todd, Hamaker & Johnson, LLP is a professional tax and accounting firm based in Lufkin, Texas, dedicated to providing personalized services to both individuals and businesses. The firm offer s a comprehensive range of services including tax, accounting, audit, and financial guidance. We will uploa

[5] [RANSOMWARE] settra leaked rcfassoc.com (ransomware.live/settra) — Victim: rcfassoc.com | Group: settra | Website: rcfassoc.com | Country: US | Details: R.C. FIELDS & ASSOCIATES: Client Data, Hidden Development Risks, and Uninvestigated Security Inc...

[5] [RANSOMWARE] akira leaked Advanced Business Systems (ransomware.live/akira) — Victim: Advanced Business Systems | Group: akira | Details: Advanced Business Systems, Inc. is a locally owned business serving the Quad Cities area, speci alizing in a wide range of office products and solutions including copiers, printers, IT servic es, phone systems, and furniture. We will upload 31gb of corporate data soon. Employee personal information

[5] [RANSOMWARE] settra leaked owensborograin.com (ransomware.live/settra) — Victim: owensborograin.com | Group: settra | Website: owensborograin.com | Country: US | Details: PROCESSING: GRAIN IN SOMEONE ELSE'S MILL PROLOGUE Tax returns filed with the IRS under threat of "fi...

[5] [RANSOMWARE] settra leaked ilex-paysages.com (ransomware.live/settra) — Victim: ilex-paysages.com | Group: settra | Website: ilex-paysages.com | Country: FR | Details: LANDSCAPE ARCHIVE: How Ilex Paysages et Urbanisme Stores Its Own — and Others' — Secrets PROLOGUE Th...

[5] [RANSOMWARE] settra leaked touredge.com (ransomware.live/settra) — Victim: touredge.com | Group: settra | Website: touredge.com | Country: US | Details: The Breaking Point A golf club manufacturer sells precision, durability, and control as a philosophy...

[5] [RANSOMWARE] settra leaked vcnyhome.com (ransomware.live/settra) — Victim: vcnyhome.com | Group: settra | Website: vcnyhome.com | Details: THE VCNY HOME ARCHIVE The company that sells home comfort failed to protect its own home — its inter...

[5] [RANSOMWARE] settra leaked infinedi.net (ransomware.live/settra) — Victim: infinedi.net | Group: settra | Website: infinedi.net | Details: Clearinghouse The company doctors pay to keep their patients' data safe. This article presents only ...

[5] [RANSOMWARE] cmdorganization leaked Medlink Georgia (ransomware.live/cmdorganization) — Victim: Medlink Georgia | Group: cmdorganization | Website: www.medlinkga.org | Country: GE | Details: We have proudly been serving northeast Georgia since 1976. As a federally qualified health center, we are able to offer uninsured and underinsured patients a sliding fee scale. No one is denied services due to lack of income or insurance status.At MedLink Georgia, we strive to provide comprehensive,

[5] [RANSOMWARE] cmdorganization leaked Port Angeles Composite (ransomware.live/cmdorganization) — Victim: Port Angeles Composite | Group: cmdorganization | Website: www.pacomposite.com | Country: US | Details: Port Angeles Composite LLC (PAC) is a leading supplier of advanced structural composite assemblies and components, serving the global commercial and business aerospace markets. Originally founded in 1996 as Angeles Composite Technologies, PAC was acquired by Honda Aircraft Company in October 2025. T

[5] [RANSOMWARE] embargo leaked www.maytrucking.com (ransomware.live/embargo) — Victim: www.maytrucking.com | Group: embargo | Website: www.maytrucking.com | Country: US | Details: May Trucking Company is a family-owned interstate transport carrier founded in 1945, headquartered in Brooks, Oregon. They provide dry freight and temperature-c... - TOTAL QUANTITY OF DATA 1 TB

SUMMARY

Total new items: 76. Critical: 5. Ransomware groups active: 1.

Top CVEs to patch urgently: CVE-2026-33825, CVE-2026-46817, CVE-2026-33017, CVE-2026-48558, CVE-2026-8037.

Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live