Beazley Security DFIR and MXDR teams recently responded to an INC ransomware case where a multitude of BYOVD packages were deployed to disable EDR and a backdoor was smuggled in a modified EDR software library file. This article details those observed methods and discusses the gradual evolution of capability of ransomware operators.
Sep 23 - 12 Min Read
In April, Beazley Security’s incident response team was called in after a newly surfaced affiliate calling themselves CMD Organization deployed ransomware and exfiltrated data from a victim organization. By way of adding a bidding platform within its leak site, the group allows potential buyers to participate directly in the extortion process. In this post, we document what our responders uncovered about CMD Organization and explore their leaksite.
May 14 - 12 Min Read
An insider look at Vect 2.0, a rapidly emerging ransomware-as-a-service operation that has gone from forum post to full-fledged platform in a matter of months. We walk through the affiliate panel, commission structure, and the technical capabilities of its Windows and ESXi lockers.
Apr 24 - 18 Min Read
In late February, Beazley Security's Incident Response team responded to a ransomware intrusion at a U.S. healthcare organization attributed to Pay2key, an Iranian government-linked threat actor that has operated since 2020. Upon investigation, the attacker had maintained access to a compromised admin account for several days before deploying ransomware and encrypting the environment within three hours.
Mar 24 - 25 Min Read
A follow-up to a previous article on LoneNone and his PXA Stealer malware where we detail some rare insights into the malware author's back-end operations and the evolution of their capabilities.
Oct 30 - 17 Min Read
Drupal released fixes on September 23rd for 36 vulnerabilities across 16 contributed modules, five critical that can lead to remote code execution.
Sep 23, 2026 - 5 Min Read
A critical pre-authentication path traversal flaw in Check Point Management Servers lets remote attackers upload and run arbitrary scripts on the system that administers enterprise firewall policy, and attackers have been exploiting it since July
Sep 22, 2026 - 5 Min Read
A critical unauthenticated path traversal in WordPress Core lets a remote attacker force a site to include a local PHP file from outside its theme directories, which on common server configurations leads to remote code execution.
Sep 22, 2026 - 4 Min Read
On September 22nd, 2026, F5 published an advisory for a critical vulnerability in BIG-IP Access Policy Manager (APM) and confirmed active exploitation in the wild. Tracked as CVE-2026-94127, the flaw lets an unauthenticated, remote attacker send crafted traffic to an affected virtual server and execute code on the appliance.
Sep 22, 2026 - 4 Min Read
On September 16th, 2026, Cisco disclosed a critical vulnerability in Identity Services Engine (ISE) and confirmed it is under active exploitation. Tracked as CVE-2026-76460, the flaw stems from insufficient authentication control on an API endpoint.
Sep 17, 2026 - 3 Min Read