| New Threats Detection Added | • GemStone |
| New Threat Protection | 86 |
| Newly Detected Threats | 7 |
Weekly Detected Threats
The following threats were added to Crystal Eye this week:
Threat name: | GemStone | ||||||||||||||||||||||||
GemStone is a malicious Chromium-based browser extension that was initially discovered in August 2026. GemStone is designed to steal sensitive browser data including credentials, cookies, session tokens, and browsing information. GemStone abuses the granted browser permissions to monitor user activity and collect data from visited websites. It is also capable of maintaining surveillance inside the victim's browser by masquerades as an "AI-powered browsing companion by Google Gemini". Once infected, it will communicate to attacker-controlled infrastructure to perform further malicious activities. | |||||||||||||||||||||||||
Threat Protected: | 06 | ||||||||||||||||||||||||
Rule Set Type: |
| ||||||||||||||||||||||||
Class Type: | Command-and-Control | ||||||||||||||||||||||||
Kill Chain: |
| ||||||||||||||||||||||||
Known Exploited Vulnerabilities (Week 2 - September 2026)
For more information, please visit the Red Piranha Forum:
https://forum.redpiranha.net/t/known-exploited-vulnerabilities-catalog-2nd-week-of-september-2026/697.
Vulnerability | CVSS | Description | Affected Version | Fixed Version | |
9.9 | Missing Authorisation - ConnectWise ScreenConnect contains a vulnerability within the ScreenConnect client that can allow an attacker to transfer and execute files through an active remote session without authorisation or host confirmation. | <= 26.6.1.9711 | 26.6.5.9742 | ||
8.1 | Privilege Escalation - JFrog Artifactory (Self Hosted) contains a privilege escalation vulnerability that can allow an attacker with low privileged access to perform elevated actions due to incorrect validation of the scope within the authentication token. | <= 7.133.10 | 7.133.11 | ||
7.5 | Authentication Bypass - JFrog Artifactory contains an improper authentication vulnerability that can allow an unauthenticated attacker to obtain an internal anonymous-user token even if anonymous access is disabled. Exploitation of this vulnerability can allow an attacker to access resources which are available to this internal anonymous identity. | Check vendor advisory for affected versions. | |||
10 | Unauthenticated Path Traversal - GitLab Community and Enterprise Editions contain a path traversal vulnerability that can allow an unauthenticated remote attacker to read arbitrary files without authentication. | 18.7 - 19.1.7 19.2 - 19.2.5 19.3 - 19.3.1 | 19.1.8 19.2.6 19.3.2 | ||
9.8 | Privilege Escalation - MikroTik RouterOS contains a vulnerability within the SSH login path that can allow an attacker with access to an unauthenticated SSH session to elevate privileges and gain access to the device. | 6.0 - 6.49.20 7.0 - 7.23.3 7.24 - 7.24.1 | 6.49.21 7.23.4 7.24.2 | ||
8.3 | Unauthenticated Information Disclosure - MikroTik RouterOS contains a vulnerability that can allow an unauthenticated remote attacker to leak kernel memory from the device, resulting in the disclosure of credentials or other sensitive information stored within memory. Exploitation of this vulnerability can lead to denial of service as a result of a system restart. | 6.0 - 6.49.20 7.0 - 7.23.3 7.24 - 7.24.1 | 6.49.21 7.23.4 7.24.2 | ||
9.8 | Authentication Bypass - Citrix NetScaler ADC and NetScaler Gateway contains an authentication bypass vulnerability that can allow an unauthenticated remote attacker to gain access to the system. Exploitation can occur when the applicance is configured as an AAA virtual server or Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy). | Check vendor advisory for affected products and versions. | |||
7.4 | Unauthenticated RCE - Multiple Fortinet products contain a heap-based buffer overflow vulnerability that can allow an unauthenticated remote attacker to execute code on the system. | Check vendor advisory for affected products and versions. | |||
8.8 | Unauthenticated RCE - Google Chromium V8 contains an out of bounds write vulnerability that can allow an unauthenticated remote attacker to execute arbitrary code within the context of the browsers sandbox when visiting a specially crafted HTML page. This vulnerability may affect additional web browsers that utilise Chromium. | < 153.0.8010.36 | 153.0.8010.36 | ||
10 | Authentication Bypass - Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contains an authentication bypass vulnerability that can allow an unauthenticated remote attacker to gain access to the system. | Check vendor advisory for affected products and versions. | |||
10 | Unauthenticated RCE - Adobe Commerce and Magento Open Source contains a vulnerability that can allow an unauthenticated remote attacker to execute arbitrary code on the system. | Check vendor advisory for affected versions. | |||
7.8 | Privilege Escalation - Microsoft Windows Update Stack contains a privilege escalation vulnerability that can allow an attacker with local access to escalate to SYSTEM level privileges. | Check vendor advisory for affected products and versions. | |||
10 | Unauthenticated RCE - N-able N-central contains a command injection vulnerability that can allow an unauthenticated remote attacker to execute code on the device. | < 2026.3.1.14 | 2026.3.1.14 | ||
7.8 | Privilege Escalation - Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that can allow a local attacker to escalate to SYSTEM level privileges. | Check vendor advisory for affected products and versions. | |||
ICS Advisories
Vulnerability | CVSS | Description | Affected Version | Fixed Version | |
CareCam | Pro IP Cameras CVE-2026-85083 (CVSS 6.8) | Contains a hard-coded credentials vulnerability that can allow an attacker with physical access to the device to gain privileged access to the bootloader. CISA ICS Advisory: ICSA-26-251-01 | Check advisory for affected products and versions. | N/A | |
ST Engineering | iDirect iQ-Series Terminals CVE-2026-38059 (CVSS: 8.7) CVE-2026-38057 (CVSS: 7) CVE-2026-38056 (CVSS: 8.8) CVE-2026-38058 (CVSS: 8.1) | Contains a vulnerability that can allow an unauthenticated attacker to retrieve sensitive device information via REST API Endpoints, perform state changing operations via a Cross-Site Request Forgery vulnerability, and escalate privileges on the system. CISA ICS Advisory: ICSA-26-183-01 | <= 4.5.2.1 | 4.5.3.0 | |
AVENA | Pipeline Integrity Monitor CVE-2026-81821 (CVSS: 8.4) CVE-2026-81822 (CVSS: 8.4) CVE-2026-81823 (CVSS: 5.3) CVE-2026-81824 (CVSS: 4.7) | Contains vulnerabilities that can allow an unauthenticated attacker to view and decrypt sensitive files, information, and execute JavaScript code upon visiting a specially crafted URL. CISA ICS Advisory: ICSA-26-253-01 | <= 2025 SP1 P1 (7.1.9580.8513) | 2025 SP1 P2 | |
NextGen Healthcare | Mirth Connect CVE-2026-82583 (CVSS: 8.3) CVE-2026-78224 (CVSS: 8.2) CVE-2026-82578 (CVSS: 7.5) | Contains vulnerabilities that can allow an authenticated attacker to execute arbitrary SQL queries on the system, and can allow an attacker exfiltrate data via an XML External Entities vulnerability. CISA ICS Advisory: ICSMA-26-253-01 | <= 4.7.1 | 4.7.2 | |
Orthanc | DICOM Server CVE-2026-87020 (CVSS: 8.1) | Contains an integer overflow vulnerability that can allow an attacker to execute code on the system upon supplying a specially crafted PNG file. CISA ICS Advisory: ICSMA-26-253-02 | <= 1.12.11 | 1.13.0 |
Updated Malware Signature (Week 2 - September 2026)
Threat | Description | |
Amatera Stealer CnC | Amatera Stealer CnC is an info stealer sold as a Malware-as-a-Service model. This communicates with its Command-and-Control infrastructure to receive malicious payload to steal information such as browser credentials, cookies, cryptocurrency wallet info, and system details. |
| Ransomware Report | |
The Red Piranha Team conducts continuous surveillance across the dark web and other threat intelligence channels to identify global organisations impacted by ransomware attacks. In the past week, this monitoring revealed multiple ransomware incidents spanning a diverse range of threat groups, underscoring the persistent and widespread nature of today's cyber threat landscape. Presented below is a detailed breakdown of ransomware group activity, victim geographies, and targeted industries observed during this period. Ransomware Hits Last WeekLast week’s ransomware activity shows that Storm was the most active ransomware group, impacting 40 countries, which accounted for 19.70% of the total ransomware hits. This made Storm the leading ransomware actor during the reporting period. The Gentlemen recorded the second-highest activity, affecting 22 countries and contributing 10.84% of the total ransomware activity. Kazu followed with 17 countries impacted, representing 8.37%, while Black Nevas affected 14 countries, accounting for 6.90%. Qilin recorded activity across 12 countries, contributing 5.91% of total ransomware hits. Direwolf and SafePay each impacted 10 countries, representing 4.93% individually. Vexy and Akira each affected 7 countries, accounting for 3.45% individually. Moderate ransomware activity was observed from Emperador and Lockbit5, each impacting 5 countries, contributing 2.46% individually. Chaos, Inc Ransom, Dark Project, Rhysida, and Play each affected 4 countries, representing 1.97% individually. Several ransomware groups showed lower activity levels. Aurora and Everest each impacted 3 countries, accounting for 1.48% individually. Wallstreet also affected 3 countries, contributing 1.48%. Groups including Dysphor1a, Panzer, ShinyHunters, Eclipse, Global Secret Group, and Clop each impacted 2 countries, representing 0.99% individually. The remaining ransomware groups, including Space Bears, Blacklocks, Leaknet, Insomnia, Interlock, Anubis, Ransomhouse, Embargo, Beast, DragonForce, Pear, Fulcrumsec, and Nightspire, each impacted 1 country, accounting for 0.49% individually. Overall, ransomware activity last week was primarily driven by Storm, The Gentlemen, Kazu, Black Nevas, and Qilin, which together accounted for a significant portion of global ransomware activity. The presence of multiple active groups highlights the continued expansion and diversification of the ransomware ecosystem, with both established and emerging operators targeting organisations across different regions. |

Worldwide Ransomware Victims
Worldwide ransomware victim distribution shows that the United States was the most affected country, with 93 victims, accounting for 45.81% of the total ransomware activity. This indicates that nearly half of all reported ransomware victims were located in the United States, making it the primary target region during this period.
Canada recorded the second-highest number of victims, with 13 cases, representing 6.40% of the total. Brazil followed with 9 victims, contributing 4.43%, while Germany recorded 8 victims, accounting for 3.94% of overall ransomware activity.
Other countries with notable ransomware impact included Australia, with 7 victims, representing 3.45%. Argentina and India each reported 6 victims, contributing 2.96% individually. South Africa and Italy each recorded 5 victims, accounting for 2.46% individually.
Moderate ransomware activity was observed in the United Kingdom and Spain, each with 4 victims, representing 1.97% individually. Philippines, Mexico, Sweden, and Türkiye each recorded 3 victims, contributing 1.48% individually.
Several countries reported lower but notable activity, including Myanmar, France, Portugal, Peru, Saudi Arabia, and Colombia, each recording 2 victims, accounting for 0.99% individually.
The remaining countries recorded 1 victim each, representing 0.49% individually. These included South Korea, Ecuador, Chile, United Arab Emirates, Egypt, Ireland, Pakistan, Switzerland, Denmark, Slovakia, Netherlands, Austria, Taiwan, Sri Lanka, Oman, Bosnia and Herzegovina, Serbia, Japan, and Hong Kong.
Overall, the data shows that ransomware activity was heavily concentrated in the United States, which accounted for nearly half of all reported victims. However, significant activity across North America, South America, Europe, Asia-Pacific, the Middle East, and Africa highlights the continued global reach of ransomware operations and the persistent targeting of organizations across diverse regions.

Industry-wide Ransomware Impact
Industry-wide ransomware victim data shows that Manufacturing was the most affected sector, with 37 victims, accounting for 18.23% of total ransomware activity. This makes Manufacturing the primary target industry during this period.
Healthcare recorded the second-highest number of victims, with 32 cases, representing 15.76% of the total. Retail followed with 29 victims, contributing 14.29%, while Business Services accounted for 24 victims, representing 11.82% of overall ransomware activity.
Other sectors with significant ransomware impact included Finance, with 12 victims, accounting for 5.91%, and IT, with 10 victims, contributing 4.93%. Transportation, Education, and Federal each recorded 9 victims, representing 4.43% individually.
Moderate ransomware activity was observed in Agriculture, which reported 6 victims, accounting for 2.96%. Energy and Hospitality each recorded 5 victims, contributing 2.46% individually. Construction recorded 4 victims, representing 1.97% of total activity.
Lower levels of ransomware activity were observed in Electronics, Insurance, and Law Firms, each reporting 3 victims, accounting for 1.48% individually.
The least affected sectors were Real Estate, Media & Internet, and Architecture, each recording 1 victim, representing 0.49% individually.
Overall, the data shows that ransomware activity was primarily concentrated in Manufacturing, Healthcare, Retail, and Business Services sectors. These industries accounted for the majority of reported victims, highlighting continued attacks focus on sectors with critical operations, valuable data assets, and a higher potential for business disruption.
Ransomware Group in Focus
Vexy Ransomware
Executive Summary
Vexy is a newly observed extortion operation with a functioning Tor publication site and an affiliate offer that claims Windows, Linux, and VMware ESXi locker builds. Public monitoring places its emergence in early September 2026. The strongest evidence establishes the actor brand, leak-site activity, one onion service, one qTox identity, and the text of the affiliate offer. It does not establish a deployed encryptor. [1][2][3]
RansomLook captured seven Vexy publication records from 5 through 11 September. No named organization, regulator, law-enforcement body, or published incident-response investigation independently confirmed these six new claims by the research cutoff. [1][4][5][6]
Technical attribution remains low confidence. ANY.RUN searches for the actor name and exact onion site returned no analyses. Public searches for MalwareBazaar, ThreatFox, URLhaus, Hybrid Analysis, Triage, Malpedia, and No More Ransom produced no attributable Vexy sample or decryptor. [7][8][9][10][15]
Ransomware Group Overview
Origin and Public Profile
WatchGuard lists Vexy as active, first seen in September 2026, and categorizes it as a data broker using direct and double extortion. RansomLook recorded 12 total posts through the cutoff, one onion service, one qTox identity, and a last post on 10 September at 23:43 UTC. These platforms largely observe the same actor-controlled artifacts, so their agreement is corroborating publication activity rather than independent proof of intrusions. [1][3]
No confirmed alias, predecessor group, operator nationality, language origin, development team, access broker, or relationship to an established ransomware brand was identified. Attribution beyond the Vexy public persona would be speculative.
Operating Model
RansomLook preserves affiliate rules marked in force from 2 September and is attributed to ReHub. The offer claims a Rust codebase, build configuration, negotiation and ticket functions, analytics, multilingual support, Tor access, and invite-code registration for a one-time USD 200 Bitcoin payment. The qTox identity and Tor blog address in the rules match the group profile. [1][2]
The advertisement supports a moderate-confidence judgment that Vexy sought for affiliates. It does not prove the advertised builders were delivered, functional, or used against any named organisation. No revenue-share terms, affiliate vetting criteria, forbidden target rules, escrow arrangements, or payment-splitting mechanism were visible in the preserved text.
Extortion Behaviour
The operator uses public naming and threatens disclosure to create pressure. Secondary reports repeat alleged data volumes for several posts, but no primary evidence confirms data possession, publication completeness, ransom amount, payment, negotiation outcome, or operational disruption. The public record cannot distinguish a successful intrusion from exaggerated, recycled, or misattributed data. [4][11][12][13]
Infrastructure
One Tor v3 service and one qTox identity are attributable to the Vexy public persona. RansomLook reported a 33% average onion uptime over 30 days and showed the service down at collection time. No clearnet mirror, hosting IP, passive-DNS chain, TLS certificate, cryptocurrency wallet, or confirmed negotiation endpoint was established. [1][2]
Technical Analysis
Observed Evidence Boundary
No public Vexy binary, ransom note, encrypted-file extension, decryptor, configuration extraction, reverse-engineering report, or victim forensic narrative was located. There is therefore no basis for a Vexy-specific hash blocklist, YARA rule, encryption description, process tree, command-line list, registry signature, service name, mutex, or network protocol profile.
Advertised Locker Capabilities
Component | Advertised Function |
Windows | Rust; AES-256 data encryption with RSA wrapping; local and network shares; exclusions; service/process termination; free-space wiping; self-delete; wallpaper/icon/printer notifications. |
Linux | Equivalent encryption; local, SMB, and NFS data; exclusions; critical-service termination; wiping; monitoring; self-delete. |
VMware ESXi | Selective datastore targeting; VMware service termination; event-log clearing; self-delete. |
Affiliate panel | Tor access; build configuration; analytics; negotiation/tickets; earnings; multilingual interface; invite-code registration. |
The affiliate text is direct evidence of what the operator advertised, not evidence that the software performs as described. The cryptographic implementation, key generation, error handling, exclusions, process lists, share enumeration, speed, and recovery behavior remain untested. [2]
Attack Lifecycle
Initial Access through Collection
No Vexy-specific initial-access vector, exploited vulnerability, phishing lure, credential source, persistence mechanism, privilege-escalation method, discovery command, lateral-movement tool, staging method, or exfiltration utility is confirmed. These phases must remain in intelligence gaps. Generic ransomware patterns are useful for coverage planning but cannot be written as Vexy behavior.
Exfiltration and Extortion
Public naming and disclosure pressure are directly observable. Alleged data volumes and claims of stolen internal material originate with the operator or services reproducing the operator's text. Defenders should investigate archive creation and abnormal egress when responding to a suspected case, but the Vexy exfiltration tool and destination are unknown.
Impact
The observable impact is reputational and operational pressure created by public claims. File encryption, service interruption, data destruction, backup impairment, and payment are unverified. A Vexy attribution should require a ransom note, binary, endpoint telemetry, negotiation artifact, or other technical anchor.
Indicators and Observables
Type | Defanged Value |
Tor leak site | http[://]vexytsr3chimdz6siwaqi2lvxxwfkxvffkpwyanr2llequ2hkm56jvqd[.]onion |
qTox identity | C32355C829A3CC4B320D4E78634FB4113B4B2918B383BB7AEAA48BDAAA4A0146E99B45A2A4C9 |
The onion is publication infrastructure, and the qTox value is an actor contact identity. Neither proves infection on an endpoint. The qTox identity is retained for intelligence correlation, not automatic blocking.
Mitigation and Response Recommendations
Identity and Remote Access
Require phishing-resistant multifactor authentication for email, VPN, remote administration, and privileged access. Remove unused internet-facing services, restrict administrative access to managed jump hosts, rotate exposed credentials, and review third-party access. CISA identifies compromised credentials and exposed remote services as recurring ransomware entry paths. [14]
Network and Virtualization
Separate user, server, backup, storage, and virtualization management networks. Permit SMB and NFS only where required. Protect ESXi and vCenter with dedicated administration paths, separate credentials, restricted interfaces, and logging outside the managed environment.
Backups and Recovery
Maintain offline or logically isolated backups, use separate backup-administration identities, enable immutability where supported, and test representative restorations. Document dependencies and recovery priorities before an incident. [14]
Containment and Evidence
If destructive activity is suspected, isolate affected systems, disable compromised accounts, preserve volatile and disk evidence when feasible, and use out-of-band communications. Determine scope from telemetry and forensic evidence rather than from an actor post alone. [14]
Crystal Eye Control Alignment
- CE Advanced Firewall: Enforce segmentation between user, server, backup, storage, and hypervisor networks; restrict east-west administrative traffic.
- CE Intrusion Protection Detection and Local Rules: Correlate remote administration, file sharing, service control, log clearing, recovery impairment, high-volume file change, and sustained outbound transfer; use the onion only as supporting context.
- CE Web Filter Antiphishing Antivirus and Protocol Filter: Block credential-harvesting traffic, apply behavior detection, and restrict unnecessary Tor, qTox, SMB, NFS, and remote administration.
Confidence Assessment
Assessment Area | Confidence | Reason |
Actor-controlled public infrastructure | MEDIUM | Two trackers agree on the onion; both may derive from the same actor artifact. |
Publication dates and names | MEDIUM | Direct tracker record; capture time may differ from incident or discovery time. |
Six new distinct in-window names | MEDIUM | One repeat removed; entity ambiguity remains for Mega Velocity and Sancity. |
Affiliate-program advertisement | MEDIUM | Preserved text is direct evidence of marketing, not delivery or use. |
Advertised malware functions | LOW | No sample or telemetry validates the claims. |
Victim compromise and data theft | UNVERIFIED | No independent primary confirmation was located. |
Encryption and operational disruption | UNVERIFIED | No binary, ransom note, encrypted artifact, or victim report. |
Known Gaps
- No independently confirmed victim statement, regulatory filing, law-enforcement confirmation, or incident-response narrative for an in-window claim.
- No attributable malware binary, ransom note, extension, configuration, process tree, reverse engineering, YARA rule, or decryptor.
- No confirmed initial access, affiliate identity, access broker, credential source, exploited vulnerability, or phishing material.
- No validated persistence, privilege escalation, discovery, lateral movement, staging, exfiltration, encryption, or recovery-inhibition method.
- No confirmed ransom demand, wallet, payment, negotiation transcript, settlement, or data-publication verification.
- No confirmed relationship to another operator, malware family, prior brand, country, or development team.
- VirusTotal authentication/file views and OTX pulse/indicator results were incomplete; MalwareBazaar required a browser verification challenge.
References
[1] RansomLook, "Vexy group profile and post archive," https://www.ransomlook.io/group/vexy
[2] RansomLook, "Vexy affiliate program rules," https://www.ransomlook.io/group/vexy/raas-rules
[3] WatchGuard Threat Lab, "Vexy Ransomware," https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/vexy
[4] Ransomwhere, "Vexy and current ransomware tracking views," https://ransomwhere.org/
[5] SOCRadar, "Logar Network Solutions claimed victim record," https://socradar.io/free-tools/ransomware-intelligence/victims/logar-network-solutions-vexy-ransomware-d119fce2
[6] BorealSec Intel, "Vexy Ransomware victim geography view," https://intel.borealsec.io/ransomware/map/?group=vexy-ransomware&window=30d
[7] ANY.RUN, "Public submissions search," https://app.any.run/submissions/
[8] MalwareBazaar, "Sample database and VexxStealer search results," https://bazaar.abuse.ch/browse/
[9] ThreatFox, "VexxStealer tag records," https://threatfox.abuse.ch/browse/tag/VexxStealer/
[10] URLhaus, "VexxStealer payload records," https://urlhaus.abuse.ch/browse/signature/VexxStealer/
[11] Threadlinqs Intelligence, "Mega Velocity claim and Vexy profile," https://intel.threadlinqs.com/threat/TL-2026-2363
[12] GalaxyWarden, "Sancity unverified claim," https://www.galaxywarden.com/blog/breach/sancity-vexy-ransomware-2026-09
[13] GalaxyWarden, "United Group unverified claim," https://www.galaxywarden.com/blog/breach/united-group-vexy-ransomware-2026-09
[14] Cybersecurity and Infrastructure Security Agency, https://www.cisa.gov/stopransomware/ransomware-guide
[15] No More Ransom, "Decryption tools catalogue," https://www.nomoreransom.org/en/decryption-tools.html