Backups Are the Bullseye: Linux Ransomware and Management Plane Bugs

Charm · September 29, 2026 · 2 min read · 6 sources

News

CISA Puts Ivanti EPMM on the Spot with KEV Addition

CISA officially added an Ivanti Endpoint Manager Mobile (EPMM) vulnerability to its Known Exploited Vulnerabilities catalog. If you're running Ivanti in your stack, this is now a mandatory patch under CISA's directive; non-compliance is a liability.

Aviatrix Controller's Critical Cloud Network Flaw Revealed

Aviatrix's controller had a critical flaw that could have allowed attackers to compromise your entire cloud network fabric. This is a prime example of why compromising the management plane is the endgame for cloud attackers today.

FBI Flags Luna Moth’s Low-Tech Callback Phishing Strategy

Luna Moth is skipping the malware and hitting companies with callback phishing to get remote access directly. It's a low-tech, high-yield attack that completely blows past your EDR if your users are trained to call 'support' on their own.

Tactics

Ransomware Gangs Now Targeting Cloud Backup Deletion

Ransomware gangs are now hitting cloud backups, meaning your disaster recovery plan might get deleted first. You need immutable, air-gapped backups, or you're just betting that your S3 bucket permissions are perfect.

Tools

Nuclei Templates Updated for New AI SSRF Flaw

Nuclei just shipped new templates for finding that AI SSRF flaw researchers discovered last week. For builders, this is a direct way to pipeline the proof-of-concept into your scanning workflow without waiting for vendor patches.

Threat Intel

Qilin Ransomware Expands to Linux Attack Vectors

The Qilin ransomware group is shipping a dedicated Linux encryptor, specifically aiming at ESXi and other hypervisors. This confirms that the 'Linux as a soft spot' thesis is the standard operating procedure for top-tier gangs now.

Stay Ahead

Delivered each morning.