| New Threats Detection Added | • 10FXRAT • AsyncRAT • DarkSwordEK • Win32 DarkCloud • SocGholish • AMOS Stealer • Lumma Stealer • BlueMoonEK • Reverse Loader • MakinoLoader • Cobalt Strike |
| New Threat Protection | 81 |
| Newly Detected Threats | 13 |
Weekly Detected Threats
The following threats were added to Crystal Eye this week:
|
Threat name:
|
10FXRAT | |||||||||||||||||||||
|
10FXRAT is highly evasive modular Remote Access Trojan (RAT) that is primarily used in sophisticated, targeted cyberespionage campaigns. 10FXRAT is commonly delivered through spear-phishing campaigns and is usually deployed along side with PoisonX to establish persistence access, execute remote commands, steal credentials, gather system information and download additional payloads. 10FXRAT incorporates multiple defence-evasion capabilities, including the disabling of security products and the abuse of vulnerable drivers through Bring Your Own Vulnerable Driver (BYOVD) techniques, enabling it to evade detection and bypass Endpoint Detection and Response (EDR) solutions.
|
||||||||||||||||||||||
|
Threat Protected:
|
13 | |||||||||||||||||||||
|
Rule Set Type:
|
|
|||||||||||||||||||||
|
Class Type:
|
Trojan-activity | |||||||||||||||||||||
|
Kill Chain:
|
|
|||||||||||||||||||||
Known Exploited Vulnerabilities (Week 3 - September 2026)
For more information, please visit the Red Piranha Forum:
https://forum.redpiranha.net/t/known-exploited-vulnerabilities-catalog-3rd-week-of-september-2026/698.
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
7.8
|
Race Condition - Linux Kernel contains a race condition vulnerability within crypto af_alg that can allow concurrent writes to the same af_alg socket which may create inconsistencies of the internal socket state.
|
Check vendor advisory for affected products and versions.
|
|||
|
8.8
|
Privilege Escalation - Linux Kernel contains a privilege escalation vulnerability that can allow an attacker to escalate to root level privileges on the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
9.8
|
Memory Disclosure - Linux Kernel contains a vulnerability that can allow a local attacker to read data from memory and can cause a denial of service on the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
8.8
|
Privilege Escalation - Google Pixel devices contain a privilege escalation vulnerability that can allow an attacker to escalate privileges on the device.
|
Check vendor advisory for affected products and versions.
|
|||
|
10
|
Authentication Bypass - Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an authentication bypass vulnerability that can allow an unauthenticated remote attacker to gain access to the system.
|
Check vendor advisory for affected products and versions.
|
|||
|
8.8
|
Privilege Escalation - Acronis Backup plugin for cPanel, WHM, Plesk and DirectAdmin contain a privilege escalation vulnerability that can allow a local attacker to escalate privileges on the system.
|
cPanel/WHM: < 1.9.3.1021
Plesk: < 1.8.11.638 DirectAdmin: < 1.2.3.238 |
1.9.3.1021
1.8.11.638 1.2.3.238 |
||
|
9.8
|
Unauthenticated RCE - Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains an SQL Injection vulnerability that can allow an unauthenticated remote attacker to execute operating system commands with root level privileges on the system.
|
Check vendor advisory for affected versions.
|
|||
ICS Advisories
|
Vulnerability
|
CVSS
|
Description | Affected Version | Fixed Version | |
|
Digital Watchdog
|
VMAX DVR and NVR
CVE-2026-68953 (CVSS: 7.1)
CVE-2026-66890 (CVSS: 9.4)
CVE-2026-68070 (CVSS: 8.7)
CVE-2026-68950 CVSS: 8.7)
CVE-2026-66887 (CVSS: 9.4)
CVE-2026-66372 (CVSS: 7.6)
|
Contains vulnerabilities that can allow an unauthenticated remote attacker to gain access to the system through disclosure of plaintext administrative credentials in a HTTP request. Additional vulnerabilities can allow the ftpd service with root privileges, which can provide elevated access to an attacker.
|
Check vendor advisory for affected products and versions.
|
||
|
Wärtsilä
|
FOS-Onboard
CVE-2026-78225 (CVSS: 9.5)
CVE-2026-81855 (CVSS: 9.3)
|
Contains hardcoded credentials which can allow an unauthenticated remote attacker to execute code on the system.
|
5.07.0923.01
|
||
|
mySCADA
|
myPRO Manager
CVE-2026-73807 (CVSS: 9.3)
CVE-2026-82567 (CVSS: 5.3)
|
Contains a vulnerability that can allow an unauthenticated remote attacker to gain access to the system and can enable sending SMS messages through a connected GSM modem without authentication.
|
<= 2.1
|
2.2
|
|
|
Schneider Electric
|
SCADAPack
CVE-2026-81861 (CVSS: 6.5)
|
Contains a vulnerability that allow an unauthenticated attacker to obtain authentication information and gain access to the system.
|
Check vendor advisory for affected products and versions.
|
||
|
Modicon M340 Controller and Communication Modules
CVE-2025-6625 (CVSS: 7.5)
|
Contains a denial-of-service vulnerability that can allow an attacker to crash the device via a specially crafted FTP command.
|
Check vendor advisory for affected products and versions
|
|||
|
NetBotz 5 750/755
CVE-2026-13336 (CVSS: 6.4)
CVE-2026-13337 (CVSS: 4.6)
|
Contains vulnerabilities that can allow an authenticated attacker to execute operating system commands on the device upon restoring a configuration backup, and to inject malicious HQL queries into the database.
|
<= 5.5.2
|
5.6.0
|
||
|
PowerChute Serial Shutdown
CVE-2026-13348 (5.3)
|
Contains a vulnerability that can allow an unauthenticated remote attacker to gain access to the device by attempting multiple authentication attempts when redirect handling is disabled.
|
<= 1.5
|
1.6
|
||
|
Siemens
|
Reyrolle 7SR5
Multiple CVEs (CVSS: 4 - 9.8)
|
Contains vulnerabilities that can allow an unauthenticated remote attacker to bypass authentication and gain access to the device, and to escalate privileges. Additionally, denial of service vulnerabilities can be used to crash the system.
|
< V2.70
|
V2.70
|
|
|
Mendix SAML
CVE-2026-80465 (CVSS: 8.7)
|
Contains a vulnerability that can allow an unauthenticated remote attacker to gain access to the system due to improper validation of the SAML response signature.
|
Check vendor advisory for affected products and version.
|
|||
|
Teamcenter
CVE-2026-58113 (CVSS: 6.1)
|
Contains a cross-site scripting vulnerability that can allow an unauthenticated remote attacker to execute JavaScript in the context of the session upon visiting a specially crafted URL.
|
Check vendor advisory for affected versions.
|
|||
|
CareCam
|
CM2507
Multiple CVEs (CVSS: 3.1 - 7.5)
|
Contains vulnerabilities that can allow an unauthenticated remote attacker to gain access to the device, view camera footage and execute code on the device without authentication.
|
v251211.1507
|
N/A
|
|
|
Mitsubishi Electric
|
CC-Link IE TSN Communication Protocol (Update A)
CVE-2026-13584 (CVSS: 7.1)
|
Contains a vulnerability that can allow an unauthenticated attacker on the same network to tamper with communication data which can result in a denial of service.
|
Check vendor advisory for affected products and versions.
|
||
|
GX Works3 and Motion Control Settings
CVE-2026-15688 (CVSS: 9.2)
|
Contains a vulnerability that can allow an unauthenticated remote attacker to gain access to the system.
|
Check vendor advisory for affected versions.
|
|||
|
Bransys
|
ELD
CVE-2026-86520 (CVSS: 7.5)
CVE-2026-86689 (CVSS: 5.9)
CVE-2026-77960 (CVSS: 5.3)
|
Contains a vulnerability that can allow an attacker to read data from the device through hardcoded MQTT and FTP credentials.
|
< 11.00.00
< 1.1.54
|
11.00.00
1.1.54
|
|
|
Hitachi Energy
|
FACTS Control Platform (FCP)
CVE-2024-4872 (CVSS: 9.9)
CVE-2024-3980 (CVSS: 9.9)
CVE-2024-3982 (CVSS: 8.2)
CVE-2024-7940 (CVSS: 8.3)
CVE-2024-7941 (CVSS: 4.3)
|
Contains vulnerabilities that can allow an authenticated attacker to execute code on the system, and a path traversal vulnerability that can allow access or modification of system files.
|
Check vendor advisory for affected products and versions.
|
||
|
ABB
|
Ability Edgenius
CVE-2026-31431 (CVSS: 7.8)
|
Contains a privilege escalation vulnerability within the Linux kernel that can allow an authenticated attacker to escalate to root level privileges.
|
<= 3.2
|
3.2.4.1
|
|
Updated Malware Signature (Week 3 - September 2026)
|
Threat
|
Description | |
|
ACR Stealer
|
ACR Stealer is a malware-as-a-service info stealer written in C++ that is designed to collect sensitive information including browser credentials, cookies, cryptocurrency wallets, system information, and application data from infected Windows devices. This malware is also known for using Dead Drop Resolvers (DDR) method to hide the actual IP address of their command-and-control servers and use of anti-analysis techniques making detection more difficult.
|
| Ransomware Report | |
|
The Red Piranha Team conducts continuous surveillance across the dark web and other threat intelligence channels to identify global organisations impacted by ransomware attacks. In the past week, this monitoring revealed multiple ransomware incidents spanning a diverse range of threat groups, underscoring the persistent and widespread nature of today's cyber threat landscape. Presented below is a detailed breakdown of ransomware group activity, victim geographies, and targeted industries observed during this period. Ransomware Hits Last WeekLast week’s ransomware activity shows that The Gentlemen was the most active ransomware group, impacting 30 victims, which accounted for 14.85% of the total ransomware hits. This made The Gentlemen the leading ransomware actor during the reporting period. Qilin recorded the second-highest activity, affecting 29 victims and contributing 14.36% of the total ransomware activity. Krybit followed with 15 victims, representing 7.43%, while Inc Ransom impacted 11 victims, accounting for 5.45%. A significant level of activity was observed from SafePay and Akira, each recording 10 victims, contributing 4.95% individually. Storm and N0n each affected 9 victims, representing 4.46% individually. Moderate ransomware activity was observed from Panzer and Audit Team, each impacting 7 victims, accounting for 3.47% individually. Lockbit5 recorded 5 victims, contributing 2.48%, while Emperador affected 4 victims, representing 1.98%. Several ransomware groups showed lower but notable activity. Direwolf, Nightspire, Vexy, Insomnia, Chaos, Ransomhouse, and Brain Cipher each impacted 3 victims, contributing 1.49% individually. Groups including Unsafe, Rhysida, Securotrop, Eclipse, Booba Team, Anubis, Genesis, Interlock, Arcus Media, DragonForce, Wallstreet, Endzone, and Play each recorded 2 victims, representing 0.99% individually. The remaining ransomware groups, including ShinyHunters, Doommageddon, Iah647, Dark Project, Kairos, Black Nevas, Gammax, and Spirals, each recorded 1 victim, accounting for 0.50% individually. Overall, ransomware activity last week was primarily driven by The Gentlemen, Qilin, Krybit, Inc Ransom, SafePay, and Akira, which accounted for a significant portion of the observed ransomware activity. The distribution indicates continued activity from both established ransomware operators and smaller emerging groups, reflecting a diverse and evolving ransomware threat landscape. |

Worldwide Ransomware Victims
Worldwide ransomware victim distribution shows that the United States was the most affected country, with 69 victims, accounting for 34.16% of the total ransomware activity. This indicates that the United States remained the primary target region during this period, representing more than one-third of all reported ransomware incidents.
Canada recorded the second-highest number of victims, with 9 cases, contributing 4.46% of the total. Argentina followed with 7 victims, representing 3.47%, while France, Germany, and the United Kingdom each recorded 6 victims, accounting for 2.97% individually.
Other countries with notable ransomware impact included India, with 5 victims, contributing 2.48%, along with Italy, Brazil, Japan, and Australia, each reporting 5 victims and representing 2.48% individually.
Moderate ransomware activity was observed in Mexico, Türkiye, Spain, and Peru, each recording 4 victims, accounting for 1.98% individually. United Arab Emirates, Finland, Bulgaria, Singapore, Viet Nam, Switzerland, Sweden, and Bulgaria each reported 3 victims, contributing 1.49% individually.
Several countries recorded lower but notable activity, including Croatia, Colombia, Taiwan, Russian Federation, South Korea, Czechia, and Chile, each with 2 victims, representing 0.99% individually.
The remaining countries recorded 1 victim each, accounting for 0.50% individually. These included Malaysia, Georgia, South Africa, Morocco, Haiti, Saudi Arabia, Kenya, Portugal, Israel, Romania, New Zealand, Costa Rica, Norway, Ukraine, Iran, Thailand, Indonesia, Netherlands, Philippines, Namibia, Luxembourg, Trinidad and Tobago, and Ireland.
Overall, the data shows that ransomware activity was concentrated primarily in the United States, which accounted for a significant share of global victims. However, the distribution of victims across North America, Europe, Asia-Pacific, the Middle East, Africa, and South America demonstrate the continued global reach of ransomware operations and the persistent targeting of organisations across multiple regions.

Industry-wide Ransomware Victim
Industry-wide ransomware victim data shows that Manufacturing was the most affected sector, with 35 victims, accounting for 17.33% of total ransomware activity. This makes Manufacturing the primary target industry during this period.
IT and Business Services recorded the second-highest number of victims, each with 25 cases, representing 12.38% individually. Retail followed with 24 victims, contributing 11.88%, while Healthcare recorded 14 victims, accounting for 6.93% of overall ransomware activity.
Other sectors with significant ransomware impact included Finance, with 13 victims, representing 6.44%, and Education, with 12 victims, contributing 5.94%. Federal recorded 10 victims, accounting for 4.95% of total activity.
Moderate ransomware activity was observed in Transportation, Hospitality, and Agriculture, each reporting 9 victims, representing 4.46% individually. Construction and Energy each recorded 4 victims, contributing 1.98% individually.
Lower levels of ransomware activity were observed in Electronics, Architecture, and Real Estate, each with 2 victims, accounting for 0.99% individually.
The least affected sectors were Law Firms, Telecommunications, and Organisations, each recording 1 victim, representing 0.50% of the total ransomware activity.
Overall, the data shows that ransomware activity was primarily concentrated in Manufacturing, IT, Business Services, Retail, Healthcare, and Finance sectors. These industries accounted for the majority of reported victims, highlighting continued attacker's focus on sectors with critical operations, valuable information assets, and a higher potential for operational disruption.

Ransomware Group in Focus
N0n Ransomware
Executive Summary
The verified public record for N0n now includes a threat-tracking identity, publication activity on 18 September 2026, one Tor onion service, and two downloadable data archives released after their deadlines expired. RansomLook recorded nine N0n posts first observed between 16:01 and 16:07 UTC. WatchGuard lists N0n as active, first seen in September 2026, with the type Data Broker. Examination of the two released archives confirmed organisation-specific CRM and database content. [1][2][3]
No independently verified malware sample, malware hash, ransom note, encrypted-file extension, decryptor, wallet, negotiation identity, command-and-control host, clearnet domain, IP address, organisation incident statement, regulator notice, law-enforcement confirmation, or incident-response report was identified by the research cutoff. The released data supports a verified data-exposure finding, but it does not establish ransomware execution, encryption, service disruption, initial access, persistence, lateral movement, collection method, or exfiltration method. [4][7]
The sole retained N0n-specific infrastructure observable is the Tor service listed independently by RansomLook and in reporting that reproduces a ThreatMon alert. Its 56-character service identifier decodes as a version 3 onion address and passes the checksum procedure defined in the Tor specification. This validates the address format; it does not prove a malware infection or a successful compromise. [1][4][5]
Published Data Evidence
The evidence below was examined locally and summarised without reproducing personal records or credential values. The portal capture showed both entries under the leaked category with expired deadlines and download and torrent controls.
|
Evidence
|
Verified finding
|
Boundary
|
|
Vietnamese education organisation
|
The archive contained a 152,044-row CRM export. Aggregate analysis identified 128,447 populated names, 128,658 phone-number fields, 44,649 email addresses, and 21,014 rows containing all three. Every parsed row contained organisation-specific education labels, and 981 records referenced official education domains. The file included cities, study interests, enrollment, and engagement fields. Record timestamps primarily covered January through November 2025.
|
The records were not matched to individuals. The precise source system, acquisition method, and record-level authenticity were not independently established. The CSV also contained 175 irregular-width rows.
|
|
Brazilian legal-services platform
|
The archive contained 18 files. Six organisation-labelled business tables covered users, chart-of-accounts structures, income, outflow, account types, and subtypes. Three user rows contained email addresses and bcrypt password hashes. The archive also contained Neon and PostgreSQL platform-state and performance data.
|
The organisation did not acknowledge the incident. The small application dataset and absence of an external forensic report prevent conclusive authentication of the archive's origin.
|
Assessment. N0n's public distribution of the two archives is verified, and the contents provide strong evidence of data exposure associated with the two anonymised organisations. The files do not independently prove that N0n performed the original intrusion, deployed ransomware, encrypted systems, or obtained the data directly from the named environments. No public acknowledgement by either organisation was located by the research cutoff.
Vietnamese Education Organisation
Brazilian legal-services platform
Verified Infrastructure Observable
|
Type
|
Defanged value
|
Validation
|
Use |
|
Tor v3 service
|
nongzecboljwv3yfndkggsybsglfrkf
fw7bvk2zemuteoxe6etpusnad[.]onion |
Exact value in two public sources; RansomLook displayed Up; 56-character v3 format and checksum validated. [1][4][5]
|
Threat-intelligence correlation only; not proof of endpoint infection.
|
|
www
|
n0n[.]to
|
ASSOCIATED; HIGH confidence in observed N0n-branded portal association. Referenced in the supplied README and directly observed. Suitable for contextual domain/HTTP-host correlation, with analyst-access exceptions.
|
No additional N0n infrastructure IOC or malware IOC met the verification standard. In particular, no malware hash, ransom-note name, encrypted extension, wallet, email address, qTox identity, clearnet domain, IP address, TLS certificate, or confirmed negotiation endpoint is included. The released-archive hashes are retained separately as evidence identifiers, not as indicators of endpoint infection. [7][8][9][10][8][9][10]
Excluded Claims and Techniques
The following material remains excluded because no independent primary evidence was located:
- Organisation names and claimed victim counts. This report uses anonymised organisation details only.
- Operator claims about service interruption, network blackout, source-system locking, or data categories not confirmed in the released files.
- Encryption capability, ransomware binary behaviour, operating system targets, or recovery impact.
- initial access, credential source, phishing, exploitation, persistence, privilege escalation, discovery, lateral movement, collection method, staging method, or exfiltration method.
- Ransom demand, cryptocurrency wallet, payment, negotiation, or settlement.
- Attribution to an operator, affiliate, country, predecessor, rebrand, malware family, or other threat groups.
- Actor-specific technique mappings, signatures, YARA rules, Sigma rules, or hash blocklists.
Defensive Actions
The actions below are general ransomware and data-extortion safeguards from the CISA StopRansomware Guide. They are not presented as N0n-specific countermeasures. [6]
- Require phishing-resistant multifactor authentication for email, VPN, remote access, and privileged accounts. [6]
- Segment critical systems and restrict administrative access to approved management paths. [6]
- Maintain offline or logically isolated backups and test restoration procedures. [6]
- Preserve centralised identity, endpoint, network, cloud, and security-control logs outside the systems they monitor. [6]
- If a compromise is suspected, isolate affected systems, disable compromised accounts, preserve evidence, and follow the approved incident-response plan. [6]
- Preserve the released archives in restricted evidence storage, record SHA-256 values, restrict access to personnel with a documented need, and do not upload personal or credential-bearing data to public malware-analysis services.
- Use the Tor observable for intelligence correlation and monitoring; do not treat a match by itself as proof that an endpoint is infected. [1][6]
Mitigation Using Red Piranha Crystal Eye 6.0
- Block and monitor: Add n0n[.]to to Web Filter policies and verify HTTPS enforcement.
- Detect and contain: Update IDPS rules, validate inline prevention, and isolate suspected hosts using Advanced Firewall rules.
- Reduce exposure: Segment databases and backups, enforce MFA, and apply CEASR application controls.
- Respond and recover: Review CE alerts, preserve evidence, rotate compromised credentials, and restore verified backups.
Source References
[1] RansomLook, "N0n group profile," Accessed Sep. 20, 2026. [Online]. Available: https://www.ransomlook.io/group/n0n
[2] RansomLook, "Recent posts for 18 September 2026," Accessed Sep. 20, 2026. [Online]. Available: https://www.ransomlook.io/recent?window=3
[3] WatchGuard Threat Lab, "Ransomware Tracker," Accessed Sep. 20, 2026. [Online]. Available: https://www.watchguard.com/wgrd-security-hub/ransomware-tracker
[4] Undercode News, "New ransomware group N0n emerges," Sep. 19, 2026. [Online]. Available: https://undercodenews.com/new-ransomware-group-n0n-emerges-adding-another-threat-to-the-2026-cybercrime-landscape/
[5] Tor Project, "Encoding onion addresses," Accessed Sep. 20, 2026. [Online]. Available: https://spec.torproject.org/rend-spec/encoding-onion-addresses.html
[6] Cybersecurity and Infrastructure Security Agency, "StopRansomware Guide," Accessed Sep. 20, 2026. [Online]. Available: https://www.cisa.gov/stopransomware/ransomware-guide
[7] No More Ransom, "Decryption tools catalogue," Accessed Sep. 20, 2026. [Online]. Available: https://www.nomoreransom.org/en/decryption-tools.html
[8] AlienVault OTX, "Threat intelligence pulse search," Checked Sep. 20, 2026. [Online]. Available: https://otx.alienvault.com/browse/global/pulses
[9] VirusTotal, "Threat intelligence search," Checked Sep. 20, 2026. [Online]. Available: https://www.virustotal.com/gui/domain/n0n.to/details https://www.virustotal.com/gui/domain/n0n.to/relations
[10] Triage, "Public malware analyses," Checked Sep. 20, 2026. [Online]. Available: https://tria.ge/reports https://dns.google/resolve?name=n0n.to&type=A