nightspire
| CVE-2024-55591 suspected | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module. | CVSS 9.8 KEVransomware |
| CVE-2023-27532 suspected | Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within the backup infrastructure network perimeter to obtain encrypted credentials stored in the configuration database. This may lead to an attacker gaining access to the backup infrastructure hosts. | KEVransomware |
| CVE-2024-37085 suspected | VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management by re-creating the configured AD group ('ESXi Admins' by default) after it was deleted from AD. | KEVransomware |
| CVE-2025-32463 suspected | Sudo contains an inclusion of functionality from untrusted control sphere vulnerability. This vulnerability could allow local attacker to leverage sudo’s -R (--chroot) option to run arbitrary commands as root, even if they are not listed in the sudoers file. | KEV |
| md5 | efd5366eb7473d6f7fb97ec7ac59f09d | — | 2026-06-02 |
| md5 | 42c062d6299ca9f76554441a29429404 | — | 2026-06-02 |
| md5 | d65c293efb5e6d033c83b2ac472bf0cb | — | 2026-06-02 |
| ip | 194.87.31.69 | — | 2026-06-02 |
| md5 | 8901ce810f999f79c51c4d4f6c93fe6b | — | 2026-06-02 |
| sha256 | 51b9f246d6da85631131fcd1fabf0a67937d4bdde33625a44f7ee6a3a7baebd2 | — | 2026-06-02 |
| sha256 | 2834114ff7e487c4ca3f50ca39f7d652dea1be98f885c388f01b6ff35309307b | — | 2026-06-02 |
| sha256 | 3ab9575225e00a83a4ac2b534da5a710bdcf6eb72884944c437b5fbe5c5c9235 | — | 2026-06-02 |
| sha256 | bde50a42efc079edde1a314243ad339db2d42e343fbbcd39117803b0f5960355 | — | 2026-04-07 |
| sha256 | ad67031e2ca68764fe1a7d6632c02b02a299d59efb920710011a9a2ccf4399b7 | — | 2026-04-07 |
| How Hastalamuerte Operates: Group-IB's Analysis of The Gentlemen's Attack Methods | matched as Nightspire | 2026-06-02 |
| Decoding NightSpire: Ransomware IOCs Aren't Set in Stone | Huntress | matched as NightSpire | 2026-04-07 |