Beazley Security DFIR and MXDR teams recently responded to an INC ransomware case where a multitude of BYOVD packages were deployed to disable EDR and a backdoor was smuggled in a modified EDR software library file. This article details those observed methods and discusses the gradual evolution of capability of ransomware operators.
Sep 23 - 12 Min Read
In April, Beazley Security’s incident response team was called in after a newly surfaced affiliate calling themselves CMD Organization deployed ransomware and exfiltrated data from a victim organization. By way of adding a bidding platform within its leak site, the group allows potential buyers to participate directly in the extortion process. In this post, we document what our responders uncovered about CMD Organization and explore their leaksite.
May 14 - 12 Min Read
An insider look at Vect 2.0, a rapidly emerging ransomware-as-a-service operation that has gone from forum post to full-fledged platform in a matter of months. We walk through the affiliate panel, commission structure, and the technical capabilities of its Windows and ESXi lockers.
Apr 24 - 18 Min Read
In late February, Beazley Security's Incident Response team responded to a ransomware intrusion at a U.S. healthcare organization attributed to Pay2key, an Iranian government-linked threat actor that has operated since 2020. Upon investigation, the attacker had maintained access to a compromised admin account for several days before deploying ransomware and encrypting the environment within three hours.
Mar 24 - 25 Min Read
A follow-up to a previous article on LoneNone and his PXA Stealer malware where we detail some rare insights into the malware author's back-end operations and the evolution of their capabilities.
Oct 30 - 17 Min Read
Citrix has disclosed a critical memory overflow in SAML-enabled NetScaler ADC and NetScaler Gateway appliances that can lead to remote code execution, compounding security risks following weeks of zero-day exploitation targeting these appliances.
Oct 8, 2026 - 4 Min Read
A pre-authentication server-side request forgery flaw in SonicWall SMA1000 remote access appliances lets an unauthenticated attacker make the appliance reach internal functionality and perform unauthorized operations.
Oct 6, 2026 - 4 Min Read
A critical flaw in self-hosted Crowd, Jira, Confluence, Bitbucket, and five other Atlassian products lets unauthenticated attackers read files from the application web root.
Oct 6, 2026 - 4 Min Read
A critical FortiMail zero-day disclosed October 1st lets unauthenticated attackers write arbitrary files to the appliance and is already being exploited, with fixed releases not yet available
Oct 1, 2026 - 6 Min Read
On September 30th, 2026, Cisco disclosed a critical vulnerability in Cisco Catalyst SD-WAN Manager and confirmed it has been exploited in the wild. Tracked as CVE-2026-76504, the flaw lets an unauthenticated, remote attacker bypass authentication on the Manager's API and gain access with the privileges of the admin user. The vulnerability affects SD-WAN Manager regardless of system configuration.
Sep 30, 2026 - 4 Min Read