Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen.
The data theft extortion group likely compromised a critical vulnerability affecting PTC’s product lifecycle management software in June, a month before it sent threatening emails to victims.
INC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data…
The OpenAI logo is displayed on a smartphone screen placed on a reflective surface, photographed using a slow exposure with a motion blur effect, in Creteil, France, on May 12, 2026. Daybreak is an AI-powered cybersecurity service designed to detect, analyze, and remediate software vulnerabilities more quickly. (Photo by Samuel Boivin/NurPhoto via Getty Images)
We almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying…
Laundry Bear exploited a zero-day vulnerability for five months before it was patched in November 2025, and the group is still actively exploiting vulnerable environments.
Researchers said the vulnerabilities, which attackers are chaining together, were first exploited three weeks before the vendor disclosed and patched the defects.