In April, Beazley Security’s incident response team was called in after a newly surfaced affiliate calling themselves CMD Organization deployed ransomware and exfiltrated data from a victim organization. By way of adding a bidding platform within its leak site, the group allows potential buyers to participate directly in the extortion process. In this post, we document what our responders uncovered about CMD Organization and explore their leaksite.
May 14 - 12 Min Read
An insider look at Vect 2.0, a rapidly emerging ransomware-as-a-service operation that has gone from forum post to full-fledged platform in a matter of months. We walk through the affiliate panel, commission structure, and the technical capabilities of its Windows and ESXi lockers.
Apr 24 - 18 Min Read
In late February, Beazley Security's Incident Response team responded to a ransomware intrusion at a U.S. healthcare organization attributed to Pay2key, an Iranian government-linked threat actor that has operated since 2020. Upon investigation, the attacker had maintained access to a compromised admin account for several days before deploying ransomware and encrypting the environment within three hours.
Mar 24 - 25 Min Read
A follow-up to a previous article on LoneNone and his PXA Stealer malware where we detail some rare insights into the malware author's back-end operations and the evolution of their capabilities.
Oct 30 - 17 Min Read
When you send phishing campaigns to a security company, you really shouldn't ask LLMs to build your infrastructure.
Oct 27 - 26 Min Read
On August 19th, Citrix published a security advisory detailing a critical authentication bypass vulnerability in their NetScaler ADC and NetScaler Gateway products. The vulnerability can be exploited remotely and without credentials, and given the typical deployment of these products, can provide threat actors initial access into targeted organizations’ networks.
Aug 19, 2026 - 3 Min Read
An unauthenticated, critical SQL injection flaw in Metabase’s password reset endpoint has been exploited in the wild to gain full administrator access to self-hosted and cloud instances.
Aug 11, 2026 - 4 Min Read
A new supply chain attack identified on multiple npm packages stemming from Keyv and Cacheable actively being exploited.
Aug 3, 2026 - 2 Min Read
N-able has confirmed active exploitation of an authentication bypass flaw in N-central that lets unauthenticated attackers take over administrator accounts and pivot into every managed endpoint beneath a compromised server.
Aug 3, 2026 - 4 Min Read
Check Point patched three vulnerabilities in its Security Management platform on July 22nd, 2026, (CVE-2026-16232, CVE-2026-62144, CVE-2026-62145). CVE-2026-16232 was already exploited in the wild as to seize full administrative control of firewall management servers.
Jul 22, 2026 - 3 Min Read