Black Swarm IntelligenceTLP:CLEAR Autonomous CTI · synthesized from live collection

The Daily Threat Briefing

As of 10:00 UTC · 1249 items / 24h · 1559 items / 7d
Lead · Critical

AiLock Ransomware Operation Claims 32 Victims

The AiLock ransomware operation, which emerged in early 2025, has posted 32 victims on its Tor-hosted data leak site.

The AiLock ransomware operation, which emerged in early 2025, is an active RaaS group marketing itself as AI-assisted ransomware using a hybrid ChaCha20/NTRUEncrypt encryption scheme and double-extortion tactics . The operation actively recruits affiliates and threatens regulatory reporting if ransoms are unpaid . As of the latest evidence, AiLock has posted 32 victims on its Tor-hosted data leak site (dhnsppqjaaa22lsqxl2tfhji4ca43743kubltnodvsft3hkvai77p6ad.onion), with the first discovered victim on 2026-03-03 and the last discovered victim on 2026-05-11 . The average delay between attack and claim is 404.4 days .

Across the Pipelines

top story by collection source · 4d

What each collection stream is surfacing most strongly right now — the dark web's leak-site activity, the OSINT feed's vulnerability and reporting signal, and social chatter.

Dark Web Critical

Money Message Ransomware Group Targets 27 Organizations

Threat-cluster summary for moneymessage — derived from 100 correlated evidence items. Named victims include First Baptist Medical Center, Pharmerica.com & BrightSpring Health Services, Tri-Way Manufacturing Technologies, Maxco Supply, Goldenbear.com & mjhallandcompany.com, Guess who!

moneymessage · 422 dark web signals
OSINT Feed Critical

Open WebUI Discloses 23 Vulnerabilities, Including Critical Auth Bypass

Open WebUI, a self-hosted artificial intelligence platform, has disclosed a batch of 23 vulnerabilities affecting versions prior to 0.9.0. The vulnerabilities span authentication bypass, authorization failures, privilege escalation, information disclosure, and server-side request forgery (SSRF).

open_webui · 189 osint feed signals
Social Critical

The Gentlemen Ransomware Group Claims Multiple New Victims

The Gentlemen ransomware group has been observed posting multiple new victim entries on the Ransomlook platform, including Dodson & Horrell, Shajarpak Securities, Oriental Diamond, Amstel Securities, Setcar, Focus Design Partners, Value Exchange International, Getece, Electroban Sae, and Qatar National Broadband . These postings were disseminated via the @Ransomlook Mastodon account, which aggregates ransomware leak-site data, and are linked to the Ransomlook.io group page for The Gentlemen .

the_gentlemen · 130 social signals
11
Critical · 24h
highest-tier clusters
355
High Severity · 24h
▲ 44.4× vs 14d median
1249
Items · 24h
1559 over 7 days
5,121
Evidence · 24h
dark / osint / social
553
Active Actors
last 72 hours
United States
Top Target
26,227 mentions / 7d
01

The Day in Context

14-day correlated-item volume

Each bar is a day of correlated threat items by severity — today against the recent past, so a spike or a lull is visible at a glance.

02

Top Stories

ranked · last 48h
Critical moneymessage425 ev

Money Message Ransomware Group Targets 27 Organizations

Threat-cluster summary for moneymessage — derived from 100 correlated evidence items. Named victims include First Baptist Medical Center, Pharmerica.com & BrightSpring Health Services, Tri-Way Manufacturing Technologies, Maxco Supply, Goldenbear.com & mjhallandcompany.com, Guess who!

Critical abyss376 ev

Abyss Locker Ransomware Operation Lists 87 Victims

The Abyss Locker ransomware operation, first identified in March 2023 and derived from the Babuk source code, has been inactive for 76 days as of the latest observed data-leak site check on 2026-05-13 . The operation's Tor-hosted data-leak site at 3ev4metjirohtdpshsqlkrqcmxq6zu3d7obrdhglpy5jpbr7whmlfgqd.onion remains accessible and lists 87 victims, with the last discovered victim dated 2026-02-26 .

Critical anubis369 ev

Anubis Ransomware Group Targets Organizations Across 14 Sectors

The Anubis ransomware group, operating as a Ransomware-as-a-Service (RaaS) model, is actively posting victims on its Tor-hosted data leak site (om6q4a6cyipxvt7ioudxt24cw4oqu4yodmqzl25mqd2hgllymrgu4aqd.onion) and has been observed targeting organizations across at least 14 sectors including Manufacturing, Financial Services, Healthcare, Energy, Technology, Public Sector, Education, and others . The group's leak site lists numerous named victims such as Micaforce Technology, Ladue Family Dental, Publishers Clearing House, AkzoNobel, Marnell Financial Services, IFL Group, Copec S.A., ViaQuest, Tesla Systems, and many others spanning geographies including the United States, Canada, France, the United Kingdom, and Australia .

Critical the_gentlemen314 ev

The Gentlemen Ransomware Group Claims Multiple New Victims

The Gentlemen ransomware group has been observed posting multiple new victim entries on the Ransomlook platform, including Dodson & Horrell, Shajarpak Securities, Oriental Diamond, Amstel Securities, Setcar, Focus Design Partners, Value Exchange International, Getece, Electroban Sae, and Qatar National Broadband . These postings were disseminated via the @Ransomlook Mastodon account, which aggregates ransomware leak-site data, and are linked to the Ransomlook.io group page for The Gentlemen .

Critical open_webui223 ev

Open WebUI Discloses 23 Vulnerabilities, Including Critical Auth Bypass

Open WebUI, a self-hosted artificial intelligence platform, has disclosed a batch of 23 vulnerabilities affecting versions prior to 0.9.0. The vulnerabilities span authentication bypass, authorization failures, privilege escalation, information disclosure, and server-side request forgery (SSRF).

Critical model_context32 ev

Critical Vulnerabilities Found in Model Context Protocol Server Implementations

This correlated threat activity (unattributed) indicates exploitation of vulnerabilities in Model Context Protocol (MCP) servers, including path-traversal and remote-code-execution weaknesses . The vulnerabilities have been publicly disclosed and are being actively exploited .

Critical apache_openmeetings22 ev

Apache OpenMeetings Discloses 16 Vulnerabilities, Including Critical RCE

Analysis of NVD and tier4_replay sources reveals a significant body of disclosed vulnerabilities affecting Apache OpenMeetings across versions from 1.0.0 to 3.2.1. A total of 16 distinct CVEs were identified, spanning severity levels from medium to critical.

Critical nvidia_triton20 ev

NVIDIA Triton Inference Server Discloses Critical Authentication Bypass Vulnerability

NVIDIA published advisories addressing a batch of vulnerabilities in the Triton Inference Server, disclosed via NVD entries and echoed by the EUVD Mastodon bot and internal replay sources. The most severe is CVE-2026-24207, a critical authentication bypass (CVSS 9.8) that could enable code execution, privilege escalation, data tampering, denial of service, or information disclosure .

03

Threat Posture

today · last 7 days
Severity Mix · last 24h
Most Active Actors · evidence volume, 7d
04

Global Targeting

victim & mention geography · 7d
Top Targeted Countries
    05

    Sector Watch

    evidence mentions · 7d
    07

    Exploitation Watch

    CVEs referenced · 7d

    The most-referenced CVEs across this week's evidence. Persistent high counts on older CVEs usually mean they still work against unpatched perimeters.

    06

    Geopolitical Desk

    conflict-adjacent signal · 5d

    Drone Attack and related conflict signal

    A series of drone attacks have been reported in Ukraine, with multiple incidents occurring in the eastern part of the country . The attacks have been linked to a group known as "drone_attack" . The group has been active in the region for several months, with previous attacks targeting military and civilian infrastructure .

    The pipeline is surfacing additional conflict-adjacent clusters in social and OSINT collection. Treat these as situational-awareness signal rather than fully attributed campaigns.

    drone_attackagriusmalekteamfreeciviliandrone_strikesemantic_ffadb67e
    08

    On the Move

    surfaced in the last 72h

    Clusters posting fresh, high-volume activity in the last three days — the names to watch next.

    Analyst's Note · What to Watch

    A recurring pattern this cycle is extortion without encryption — multiple groups stealing and listing data rather than encrypting it. That shifts the detection window earlier, to exfiltration rather than file activity: watch egress, not just files.

    High-severity output stands at 355 in the last 24 hours with 11 critical clusters; Business Services leads sector exposure this week. The fastest-moving risk remains data-extortion ransomware paired with a quick vulnerability-exploitation cycle.

    Baseline for tomorrow: a drop back toward the 14-day median would signal today was an event, not a trend; sustained elevation suggests an active surge worth standing up watch for.

    — Synthesized by Black Swarm · autonomous correlation across dark web, OSINT and social
    Black Swarm Daily Threat Briefing · generated 2026-06-01 10:00 UTC · TLP:CLEAR
    Synthesized from 1559 correlated threat items (7d) across dark-web, OSINT-feed and social collection. Headlines editorialized by Lorin (self-hosted); severity is evidence-derived; victim and CVE names are as-reported by tracked leak sites and advisories and may contain attribution noise.
    Live Feed →  ·  Threat Actors →  ·  Industry Profiles →