Skip to content

The patch almost always arrives too late.

Six vulnerabilities that turned into real incidents over the past year, placed on one scale: the time between attackers starting to exploit them and anyone publishing an advisory about them. For four of the six, that difference is negative.

4/6

exploited before publication.

The exploitation window

The dashed line is the day the vendor published its advisory. Anything to the left of it was already being exploited before the vulnerability existed on paper. No patching policy, however tight, closes a window that opened before anyone knew it was there.

That is why patching is necessary but not sufficient. What closes the gap is knowing what you have facing the internet, and having somebody look at it the way an attacker would before an attacker does.

From class to incident

None of these incidents rests on a new kind of mistake. They are the vulnerability classes this knowledge base explains, found in software thousands of organisations run. Understand the class and you recognise the next case before it has a name.

The six cases

Who is behind it

Attackers are not an anonymous mass. They are organised groups with a business model or an assignment, and with a recognisable way of getting in. These six shape a large part of the picture.

Cl0p

extortion

Extortion at scale, largely without encryption

Cl0p's signature is the mass campaign: one vulnerability in file transfer or enterprise software that thousands of organisations expose to the internet, used against hundreds of them in a single wave, often before a patch exists. Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo, Oracle E-Business Suite and, in 2026, very probably PTC Windchill. In these campaigns hardly anything gets encrypted: the data is stolen and the threat to publish it is the leverage.

also known asTA505, FIN11, Lace Tempest

AttributedCVE-2026-12569

LockBit

extortion

Ransomware as a service

LockBit supplied the ransomware and the extortion platform; separate affiliates did the break-in and shared the proceeds. Those affiliates were rarely creative about entry: unpatched edge appliances and stolen credentials, Citrix Bleed among them. In February 2024 police forces took over LockBit's infrastructure in Operation Cronos. The brand has tried to come back since, but the model it stood for now runs under other names.

also known asBitwise Spider

Akira

extortion

Ransomware through the VPN

Akira has been active since 2023 and almost always comes in through the VPN: a login without a second factor, or a known vulnerability in the VPN appliance itself, in Cisco and SonicWall equipment among others. Rarely anything new, mostly a door that should have been closed already. That makes the group a good gauge of how sound your remote access really is.

also known asStorm-1567

Scattered Spider

extortion

Social engineering of the service desk

Scattered Spider rarely needs a vulnerability. The group calls the service desk, poses as an employee and has a password or an MFA token reset, then steals data to extort and in some cases deploys ransomware. Alongside that: SIM swapping and wearing users down with endless MFA prompts. What stops this is a service desk that verifies identity properly, and MFA that cannot be phished or reset over the phone.

also known asUNC3944, Octo Tempest, 0ktapus

Volt Typhoon

state-linked

State-linked pre-positioning in critical sectors

Western agencies link Volt Typhoon to China, and the group stands out for what it does not do: no ransomware, no visible loot, hardly any malware on the networks it enters. It comes in through edge equipment, hides its traffic behind hijacked end-of-life office routers, and then works with the administrative tooling already present, in order to stay inside critical infrastructure for years.

also known asVanguard Panda, BRONZE SILHOUETTE

Sandworm

state-linked

Destructive state operations

Sandworm is attributed to Russian military intelligence and sits behind a series of destructive attacks, from NotPetya to repeated strikes on the Ukrainian power grid. The objective is not money but outage, which makes the group a different class of risk from an extortion gang.

also known asAPT44, Seashell Blizzard

Press / to search · Esc