Clop
| CVE-2025-55182 suspected | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints. | CVSS 10.0 KEVransomware |
| CVE-2025-11371 suspected | Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files. | KEV |
| CVE-2025-14611 suspected | Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication. | KEV |
| CVE-2025-30406 suspected | Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the way that the application manages keys used for ViewState integrity verification. Successful exploitation allows an attacker to forge ViewState payloads for server-side deserialization, allowing for remote code execution. | KEV |
| CVE-2025-31151 suspected | — | |
| CVE-2025-59287 suspected | Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution. | KEV |
| CVE-2023-22518 suspected | Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data. | KEVransomware |
| CVE-2023-43117 suspected | — | |
| CVE-2023-46604 suspected | Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. | KEVransomware |
| CVE-2025-31161 suspected | CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise. | KEVransomware |
| CVE-2023-34362 suspected | Progress MOVEit Transfer contains a SQL injection vulnerability that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker may be able to infer information about the structure and contents of the database in addition to executing SQL statements that alter or delete database elements. | KEVransomware |
| ip | 146.70.134.50 | — | 2025-12-18 |
| url | http://185.196.11.207:8000/conqueror.exe | — | 2025-12-18 |
| sha256 | e9fa82d92d826c6a1c38165fe6bd610d3b80cd5d53ec65ac3fe94393be64b5a5 | — | 2025-12-18 |
| ip | 185.196.11.207 | — | 2025-12-18 |
| ip | 147.124.216.205 | — | 2025-12-18 |
| Evaluating Mexico’s New Cybersecurity Plan | matched as CL0P | 2026-06-25 |
| Out of the Crypt: The Evolving Cyber Extortion Economy | matched as CLOP | 2026-05-27 |
| Gladinet CentreStack/Triofox: Cryptography Vulnerability | Huntress | matched as cl0p | 2025-12-18 |
| Know Thy Enemy: unraveling the “Hi-Tech Crime Trends 2022/2023” report | matched as Clop | 2025-09-10 |
| Ten Years of Resilience, Innovation & Community-Driven Defense | Huntress | matched as cl0p | 2025-08-25 |
| MFT Exploitation and Adversary Operations | Huntress | matched as cl0p | 2023-11-29 |
| Uncover the Hidden Story of Ransomware Victims – They’re Not Who You Think | matched as Clop | 2023-07-31 |
| Move It on Over: Reflecting on the MOVEit Exploitation | Huntress | matched as cl0p | 2023-07-07 |
| Critical Vulnerabilities in PaperCut Print Management Software | Huntress | matched as Clop | 2023-04-21 |