LIVE · cybersecurity feed
Live wire
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensCVE-2023-38646 · Metabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationCVE-2026-18577 · N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and PersistCVE-2026-8037 · Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsLiving off the coding agent: Two tales of tunnels and LaunchAgents
ransomwarehigh

Ransom Cartel Creator Sentenced to 16 Years for Extortion Scheme

The creator of the Ransom Cartel ransomware, Maksim Silnikau, has been sentenced to 16 years in prison for his role in a scheme that targeted at least 18 companies. Silnikau recruited participants, provided tools, and managed operations, attempting to extort over $5.2 million from victims including businesses, law firms, and educational institutions. His arrest in Poland led to the cessation of Ransom Cartel's activities.

zeroday.news ·

A Belarusian national, Maksim Silnikau, has been sentenced to 16 years in prison for his role in creating and operating the Ransom Cartel ransomware scheme. The 40-year-old, also known by the aliases J.P. Morgan, xxx, and lansky, was found to have participated in cybercrime activities since at least 2005, including membership in the cybercrime forum Direct Connection from 2011 to 2016.

Silnikau initiated the Ransom Cartel operation in 2021, actively recruiting participants from various cybercrime forums. The group is linked to attacks on at least 18 organizations between 2021 and 2023, attempting to extort a total of at least $5.2 million from its victims.

The targets of these attacks were diverse, encompassing law firms, medium-sized businesses, a small medical technology startup, educational institutions, and large multinational corporations located in states such as California, New York, and Nebraska. Some victims experienced operational disruptions lasting several months due to the attacks.

As the architect of Ransom Cartel, Silnikau provided his co-conspirators with essential tools and information for their attacks. This included stolen credentials and mechanisms designed to encrypt compromised computer systems. He also developed and maintained a dedicated website that served as a central hub for monitoring and controlling ongoing attacks, facilitating communication between co-conspirators and victims, negotiating ransom demands, and managing the distribution of illicit funds among the participants.

Silnikau pleaded guilty to charges of conspiracy to commit wire fraud and aggravated identity theft. His activities with Ransom Cartel ceased following his arrest.

Prior to his capture, Silnikau fled from Spain while awaiting extradition to the United States. He was subsequently apprehended in Poland in July 2023 as he attempted to return to Belarus and was extradited to the United States in August 2023. Authorities noted that while Ransom Cartel did not achieve the scale of some larger ransomware operations, Silnikau's capture effectively dismantled the group.

ransomwarecybercrimeextortionsentencing
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hackers breach TrueConf to trojanize client installers with backdoors

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]

cybersecurity

China Launches Cybersecurity Review of Palo Alto Networks Products

China's Cyberspace Administration has initiated a cybersecurity review of Palo Alto Networks' products sold within the country, citing national security concerns. The review, based on national security and cybersecurity laws, lacks specific details regarding the reasons or potential impact. Palo Alto Networks has stated that its operations and product delivery in the region remain unaffected for now.

ai

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

Researchers scour social media to measure developer concerns about AI coding tools

vulnerabilityhigh

Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own […]

breachcritical

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.

CVE-2026-8037critical

CISA Adds Progress LoadMaster Command Injection Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Progress LoadMaster products to its Known Exploited Vulnerabilities catalog. This OS command injection flaw, tracked as CVE-2026-8037, allows unauthenticated attackers to execute arbitrary commands remotely. Exploitation attempts were observed as early as June 29, 2026, shortly after a proof-of-concept exploit became available.