Articles

CMD Organization – New Ransomware Operator Moves to Place Public Bidding Wars on Ransomed Data

In April, Beazley Security’s incident response team was called in after a newly surfaced affiliate calling themselves CMD Organization deployed ransomware and exfiltrated data from a victim organization. By way of adding a bidding platform within its leak site, the group allows potential buyers to participate directly in the extortion process. In this post, we document what our responders uncovered about CMD Organization and explore their leaksite.

May 14 - 12 Min Read

Vect 2.0: An Insider Perspective On The New Ransomware Variant

An insider look at Vect 2.0, a rapidly emerging ransomware-as-a-service operation that has gone from forum post to full-fledged platform in a matter of months. We walk through the affiliate panel, commission structure, and the technical capabilities of its Windows and ESXi lockers.

Apr 24 - 18 Min Read

Pay2Key Iranian-Linked Ransomware is Back, Back Again

In late February, Beazley Security's Incident Response team responded to a ransomware intrusion at a U.S. healthcare organization attributed to Pay2key, an Iranian government-linked threat actor that has operated since 2020. Upon investigation, the attacker had maintained access to a compromised admin account for several days before deploying ransomware and encrypting the environment within three hours.

Mar 24 - 25 Min Read

Chasing a Ghost : PXA Stealer Part 2

A follow-up to a previous article on LoneNone and his PXA Stealer malware where we detail some rare insights into the malware author's back-end operations and the evolution of their capabilities.

Oct 30 - 17 Min Read

Quantum Redirect: Offense by Vibes

When you send phishing campaigns to a security company, you really shouldn't ask LLMs to build your infrastructure.

Oct 27 - 26 Min Read

Advisories

Critical Vulnerability in SAP Kernel (CVE-2026-44756)

On September 8th, 2026, SAP disclosed a critical vulnerability in the SAP kernel as part of its September Security Patch Day. Tracked as CVE-2026-44756, the vulnerability grants an unauthenticated attacker remote code execution on a target SAP host. SAP products are commonly deployed internet facing, and successful compromise provides threat actors initial access into an organization’s network.

Sep 10, 2026 - 3 Min Read

Critical Vulnerabilities in Cisco Secure Firewall Management Center Under Active Exploitation (CVE-2026-20079, CVE-2026-20316)

Two Cisco Secure Firewall Management Center flaws, an unauthenticated authentication bypass that grants root and a static credential for a built-in account, are being exploited together by state-sponsored and ransomware actors to take over firewall management consoles.

Sep 9, 2026 - 7 Min Read

Critical Vulnerabilities in Multiple Adobe Products Under Active Exploitation (CVE-2026-48273, CVE-2026-75746, CVE-2026-19232, CVE-2026-75650)

On September 8th, 2026, CISA added CVE-2026-75650 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation of a critical vulnerability in Adobe Commerce and Magento Open Source. The flaw lets an unauthenticated, remote attacker inject and execute arbitrary code through Magento's template engine. Magento is an E-commerce platform, and a compromise could expose confidential client financial data. It could also provide threat actors initial access into an organization’s internal network. It was one of four critical vulnerabilities Adobe addressed across its September 2026 security update cycle involving multiple products.

Sep 9, 2026 - 4 Min Read

Critical Remote Code Execution Vulnerabilities in Check Point Quantum Security Gateway and Security Management (CVE-2026-85102, CVE-2026-85103)

On September 9th, 2026, Check Point released emergency security updates for two critical vulnerabilities in the VPN certificate handling of its Quantum product line. The vulnerabilities could allow an unauthenticated, remote attacker to compromise and execute code on affected Check Point systems.

Sep 9, 2026 - 4 Min Read

Critical Vulnerabilities in SonicWall SMA1000 Series Appliances Under Active Exploitation (CVE-2026-83548, CVE-2026-83549)

On September 1, 2026 SonicWall PSIRT disclosed two critical vulnerabilities affecting SMA1000 series appliances. Tracked as CVE-2026-83548 and CVE-2026-83549, SonicWall confirmed that the vulnerabilities are being actively exploited in the wild.

Sep 1, 2026 - 2 Min Read