Critical
moneymessage425 ev
Money Message Ransomware Group Targets 27 Organizations
Threat-cluster summary for moneymessage — derived from 100 correlated evidence items. Named victims include First Baptist Medical Center, Pharmerica.com & BrightSpring Health Services, Tri-Way Manufacturing Technologies, Maxco Supply, Goldenbear.com & mjhallandcompany.com, Guess who!
Critical
abyss376 ev
Abyss Locker Ransomware Operation Lists 87 Victims
The Abyss Locker ransomware operation, first identified in March 2023 and derived from the Babuk source code, has been inactive for 76 days as of the latest observed data-leak site check on 2026-05-13 . The operation's Tor-hosted data-leak site at 3ev4metjirohtdpshsqlkrqcmxq6zu3d7obrdhglpy5jpbr7whmlfgqd.onion remains accessible and lists 87 victims, with the last discovered victim dated 2026-02-26 .
Critical
anubis369 ev
Anubis Ransomware Group Targets Organizations Across 14 Sectors
The Anubis ransomware group, operating as a Ransomware-as-a-Service (RaaS) model, is actively posting victims on its Tor-hosted data leak site (om6q4a6cyipxvt7ioudxt24cw4oqu4yodmqzl25mqd2hgllymrgu4aqd.onion) and has been observed targeting organizations across at least 14 sectors including Manufacturing, Financial Services, Healthcare, Energy, Technology, Public Sector, Education, and others . The group's leak site lists numerous named victims such as Micaforce Technology, Ladue Family Dental, Publishers Clearing House, AkzoNobel, Marnell Financial Services, IFL Group, Copec S.A., ViaQuest, Tesla Systems, and many others spanning geographies including the United States, Canada, France, the United Kingdom, and Australia .
Critical
the_gentlemen314 ev
The Gentlemen Ransomware Group Claims Multiple New Victims
The Gentlemen ransomware group has been observed posting multiple new victim entries on the Ransomlook platform, including Dodson & Horrell, Shajarpak Securities, Oriental Diamond, Amstel Securities, Setcar, Focus Design Partners, Value Exchange International, Getece, Electroban Sae, and Qatar National Broadband . These postings were disseminated via the @Ransomlook Mastodon account, which aggregates ransomware leak-site data, and are linked to the Ransomlook.io group page for The Gentlemen .
Critical
open_webui223 ev
Open WebUI Discloses 23 Vulnerabilities, Including Critical Auth Bypass
Open WebUI, a self-hosted artificial intelligence platform, has disclosed a batch of 23 vulnerabilities affecting versions prior to 0.9.0. The vulnerabilities span authentication bypass, authorization failures, privilege escalation, information disclosure, and server-side request forgery (SSRF).
Critical
model_context32 ev
Critical Vulnerabilities Found in Model Context Protocol Server Implementations
This correlated threat activity (unattributed) indicates exploitation of vulnerabilities in Model Context Protocol (MCP) servers, including path-traversal and remote-code-execution weaknesses . The vulnerabilities have been publicly disclosed and are being actively exploited .
Critical
apache_openmeetings22 ev
Apache OpenMeetings Discloses 16 Vulnerabilities, Including Critical RCE
Analysis of NVD and tier4_replay sources reveals a significant body of disclosed vulnerabilities affecting Apache OpenMeetings across versions from 1.0.0 to 3.2.1. A total of 16 distinct CVEs were identified, spanning severity levels from medium to critical.
Critical
nvidia_triton20 ev
NVIDIA Triton Inference Server Discloses Critical Authentication Bypass Vulnerability
NVIDIA published advisories addressing a batch of vulnerabilities in the Triton Inference Server, disclosed via NVD entries and echoed by the EUVD Mastodon bot and internal replay sources. The most severe is CVE-2026-24207, a critical authentication bypass (CVSS 9.8) that could enable code execution, privilege escalation, data tampering, denial of service, or information disclosure .