Cloud Backup Wipers, Linux Ransomware, and Management Plane Exploits

Charm · September 30, 2026 · 2 min read · 6 sources

News

CISA adds actively exploited Ivanti EPMM vulnerability to its catalog

CISA has officially added a known Ivanti EPMM flaw to its catalog of actively exploited vulnerabilities. This is a formal signal that threat actors are using this bug in real attacks right now, raising the urgency for patching.

Critical flaw in Aviatrix Controller could let attackers compromise cloud networks

A critical flaw in Aviatrix Controller, a popular cloud networking platform, has been disclosed. Attackers could use it to gain control over cloud infrastructure, making this a high-priority patch for multi-cloud environments.

Threat Intelligence

Ransomware actors are now actively erasing cloud backups

Ransomware groups are evolving their playbooks to include the systematic destruction of cloud-based backups. This forces defenders to reconsider backup architecture, pushing toward immutable or offline copies that can survive an attack.

FBI warns of a new callback phishing campaign by Luna Moth

The FBI is warning about a sophisticated callback phishing campaign operated by Luna Moth. This social engineering tactic bypasses traditional email filters by tricking victims into calling a fake support number, leading to data theft.

Qilin ransomware adds a Linux encryptor to its toolkit

The Qilin ransomware group has expanded its arsenal with a new encryptor that specifically targets Linux systems, including ESXi hypervisors. This is a clear signal that attackers are following the enterprise shift to virtualization and cloud.

Tools

New Nuclei template published for the Aviatrix Controller vulnerability

A new Nuclei template has been submitted to detect the critical Aviatrix Controller vulnerability. This gives defenders an immediate, automated way to scan their cloud environments for exposure, a huge leverage point for security teams using the ProjectDiscovery stack.

Stay Ahead

Delivered each morning.