SecNoteMorning brief
Latest sync Aug 28, 10:22 PM
1 down

Reading Queue

Help
TodayActionsStack WatchFeedIntelligence
More
VendorMalwareRed TeamAIGlobal RiskUSWorld
HelpMethodologySourcesPrivacy

Queue triage

All feed: 9 matches for "ransomware"

Top item: PTC Windchill & FlexPLM RCE

Action filterAll items
Showing9Saved0Sources down1

Feed counts show matched items; visible rows may be lower when repeated EPSS/CVE-only items are grouped for readability.

Reading Queue

Showing 9 of 9 visible rows.

Current state
More filters
criticalVulnerabilityActive exploitRansomware

PTC Windchill & FlexPLM RCE

FortiGuard Threat Signal | Jul 28, 2026

What is the Attack? A critical unauthenticated remote code execution (RCE) vulnerability affecting PTC Windchill PDMlink and PTC FlexPLM is being actively exploited by Cl0p ransomware affiliates. The attackers are targeting vulnerable Internet-facing Product Lifecycle Manageme...

Evidence and analyst toolsscore 114
Sourcerss | ok | FortiGuard Threat Signal
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Jul 28, 2026, 11:57 PM UTC
Score inputsbase score 114, priority score 79, critical severity, 1 CVE, FortiGuard Threat Signal feed item, Mentions CVE-2026-12569, Watchlist: ransomware, Active exploit, Ransomware, RCE
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#ransomware#CVE-2026-12569#FortiGuard Threat Signal
Sigma searchNuclei searchSentinel search
criticalVulnerabilityActive exploitRansomware

WordPress Core Unauthenticated RCE (WP2Shell)

FortiGuard Threat Signal | Jul 30, 2026

What is the Attack? FortiGuard Labs is observing increasing exploitation activity targeting WP2Shell, a critical unauthenticated remote code execution (RCE) attack chain affecting WordPress Core. Unlike most WordPress attacks that rely on vulnerable plugins or themes, WP2Shell...

Evidence and analyst toolsscore 106
Sourcerss | ok | FortiGuard Threat Signal
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Jul 30, 2026, 4:33 AM UTC
Score inputsbase score 106, priority score 71, critical severity, FortiGuard Threat Signal feed item, Watchlist: ransomware, Active exploit, Ransomware, RCE
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#ransomware#FortiGuard Threat Signal
Sigma searchNuclei searchSentinel search
criticalVulnerabilityRansomwareRCE

In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions

SecurityWeek | Aug 28, 2026

Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims. The post In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions appeared...

Evidence and analyst toolsscore 99
Sourcerss | ok | SecurityWeek
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 3:35 PM UTC
Score inputsbase score 99, priority score 117, critical severity, SecurityWeek feed item, Watchlist: ransomware, sanctions, Ransomware, RCE
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#ransomware#sanctions#SecurityWeek
Sigma searchNuclei searchSentinel search
highCyber newsRansomware

ATF confirms cyberattack hit system containing info on its investigation targets

CyberScoop | Aug 28, 2026

The prolific ransomware group Qilin claimed responsibility for the attack. ATF insists the incident was limited to a standalone system and hasn’t impacted critical operations. The post ATF confirms cyberattack hit system containing info on its investigation targets appeared fi...

Evidence and analyst toolsscore 72
Sourcerss | ok | CyberScoop
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 8:29 PM UTC
Score inputsbase score 72, priority score 90, high severity, CyberScoop feed item, Watchlist: ransomware, Ransomware
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#ransomware#CyberScoop
Sigma searchNuclei searchSentinel search
highCyber newsRansomware

Winona County paid more than $128K following January ransomware attack

DataBreaches.net | Aug 28, 2026

WXOW in Minnesota reports: Winona County paid more than $128,000 following a January ransomware attack, according to a county news release. The county said it negotiated and paid $128,539.57 with assistance from its insurance carrier after ransomware was detected on its comput...

Evidence and analyst toolsscore 71
Sourcerss | ok | DataBreaches.net
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 1:59 PM UTC
Score inputsbase score 71, priority score 89, high severity, DataBreaches.net feed item, Watchlist: ransomware, Ransomware
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#ransomware#DataBreaches.net
Sigma searchNuclei searchSentinel search
highCyber newsRansomware

ATF Confirms Cyber Incident After Ransomware Group Claims Attack

SecurityWeek | Aug 28, 2026

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ. The post ATF Confirms Cyber Incident After Ransomware Group Claims Attack appeared first on SecurityWeek.

Evidence and analyst toolsscore 71
Sourcerss | ok | SecurityWeek
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 1:59 PM UTC
Score inputsbase score 71, priority score 89, high severity, SecurityWeek feed item, Watchlist: ransomware, Ransomware
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#ransomware#SecurityWeek
Sigma searchNuclei searchSentinel search
highCyber newsRansomware

Qilin claimed they attacked the ATF. Here’s what the ATF says.

DataBreaches.net | Aug 27, 2026

As many people have heard by now, the Qilin ransomware group claimed to have attacked the ATF. As is their regular practice, they provided no proof of their claims. Today, the ATF has issued a statement that sheds light on the incident and what ATF has found so far: WASHINGTON...

Evidence and analyst toolsscore 67
Sourcerss | ok | DataBreaches.net
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 27, 2026, 4:47 PM UTC
Score inputsbase score 67, priority score 77, high severity, DataBreaches.net feed item, Watchlist: ransomware, Ransomware
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#ransomware#DataBreaches.net
Sigma searchNuclei searchSentinel search
highVendor advisoryRansomware

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Security | Aug 10, 2026

Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to ...

Evidence and analyst toolsscore 62
Sourcerss | ok | Microsoft Security
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 10, 2026, 3:00 PM UTC
Score inputsbase score 62, priority score 35, high severity, Microsoft Security feed item, Watchlist: ransomware, Microsoft, Ransomware
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#ransomware#Microsoft#Microsoft Security
Sigma searchNuclei searchSentinel search
highAI newsRansomware

This month in security with Tony Anscombe – July 2026 edition

ESET WeLiveSecurity | Jul 31, 2026

OpenAI models going rogue, the first documented agentic ransomware operation, and an emergent AI-driven supply chain threat made for a packed July roundup

Evidence and analyst toolsscore 61
Sourcerss | ok | ESET WeLiveSecurity
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Jul 31, 2026, 2:14 PM UTC
Score inputsbase score 61, priority score 26, high severity, ESET WeLiveSecurity feed item, AI relevance match, Watchlist: ransomware, supply chain, AI, Ransomware
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#ransomware#supply chain#AI#OpenAI#ESET WeLiveSecurity
Sigma searchNuclei searchSentinel search
TrustSource health1 failed and 4 degraded sources in this run.

Source Health

69 sources
Coverage impact: failed: GDELT. degraded: NPR Politics, Defense.gov News, Federal Reserve Press, GovInfo Federal Register. Treat affected lanes as incomplete until refresh succeeds.

BleepingComputer

rss | 15 items

ok

The Hacker News

rss | 18 items

ok

SecurityWeek

rss | 10 items

ok

Dark Reading

rss | 18 items

ok

KrebsOnSecurity

rss | 10 items

ok

OpenAI News

rss | 8 items

ok

TechCrunch AI

rss | 10 items

ok

VentureBeat AI

rss | 7 items

ok

The Verge AI

rss | 8 items

ok

Google AI

rss | 10 items

ok

MIT News AI

rss | 8 items

ok

MIT Technology Review

rss | 6 items

ok

The Register AI/ML

rss | 8 items

ok

Google Project Zero

rss | 7 items

ok

CISA Advisories

rss | 18 items

ok

CISA ICS Advisories

rss | 8 items

ok

Microsoft Security

rss | 8 items

ok

Microsoft MSRC Updates

rss | 10 items

ok

Cisco Security Advisories

rss | 8 items

ok

Palo Alto Security Advisories

rss | 8 items

ok

FortiGuard Outbreak Alerts

rss | 8 items

ok

FortiGuard Threat Signal

rss | 8 items

ok

Chrome Releases

rss | 8 items

ok

Mozilla Security

rss | 8 items

ok

Unit 42

rss | 8 items

ok

Cisco Talos

rss | 8 items

ok

ESET WeLiveSecurity

rss | 8 items

ok

Malwarebytes Labs

rss | 8 items

ok

SentinelOne

rss | 6 items

ok

SANS Internet Storm Center

rss | 8 items

ok

CrowdStrike

rss | 7 items

ok

CyberScoop

rss | 8 items

ok

The Record

rss | 5 items

ok

DataBreaches.net

rss | 6 items

ok

BBC World

rss | 7 items

ok

BBC Business

rss | 6 items

ok

NPR World

rss | 3 items

ok

NPR Politics

rss | 0 items | Source responded but no relevant items matched.

degraded

Al Jazeera

rss | 8 items

ok

The Guardian World

rss | 6 items

ok

The Guardian US Politics

rss | 5 items

ok

The Guardian Business

rss | 6 items

ok

NYTimes World

rss | 6 items

ok

NYTimes Politics

rss | 3 items

ok

Defense.gov News

rss | 0 items | Source responded but no relevant items matched.

degraded

Federal Reserve Press

rss | 0 items | Source responded but no relevant items matched.

degraded

GovInfo Federal Register

rss | 0 items | Source responded but no relevant items matched.

degraded

GovInfo Congressional Bills

rss | 6 items

ok

NPR News

rss | 8 items

ok

NPR National

rss | 8 items

ok

NPR Politics

rss | 6 items

ok

NYTimes U.S.

rss | 6 items

ok

NYTimes Politics

rss | 6 items

ok

The Guardian U.S.

rss | 6 items

ok

BBC U.S. & Canada

rss | 6 items

ok

BBC World

rss | 8 items

ok

BBC Business

rss | 6 items

ok

NPR World

rss | 8 items

ok

Al Jazeera

rss | 8 items

ok

The Guardian World

rss | 6 items

ok

The Guardian Business

rss | 6 items

ok

NYTimes World

rss | 6 items

ok

NYTimes Business

rss | 6 items

ok

CISA KEV

structured | 22 items

ok

GitHub Advisories

api | 24 items

ok

NVD Recent CVEs

api | 18 items

ok

FIRST EPSS

api | 20 items

ok

Hacker News

api | 5 items

ok

GDELT

api | 0 items | fetch failed

failed

1 source currently timed out or rejected the request. Refresh reruns every source, including failed pulls.

ScopeWatchlist75 terms used to highlight recurring products, tactics, and security topics.

Watchlist

CISAKEVzero-dayransomwareregulationtarifftradeexport controlsupply chaininitial accessidentityphishingAI securityprompt injectionmodel poisoningagentic AIdeepfakeMicrosoftWindowsAzureEntraActive DirectoryOktaCiscoPalo AltoFortinetIvantiVMware