INC ransomware's Rust rewrite powers a surge to 830+ victims as FortiBleed compromises 30,000 firewalls across 194 countries. Plus: a fourth Defender zero-day from the same researcher and Oracle's 245-vulnerability Critical Patch Update.
Audio is available on Spreaker — see link below.
INC ransomware has rewritten its encryptors in Rust, and the numbers behind that decision tell you exactly how serious this group has become. Over eight hundred thirty victims since August twenty twenty-three.
There's a detail in INC's updated toolkit that deserves specific attention. Their credential dumper has been updated to target newer Veeam backup deployments.
Separately, Microsoft has confirmed a new zero-day in the Malware Protection Engine. It's tracked as CVE-2026-50656, carries a CVSS score of seven point eight, and allows privilege escalation.
On the Fortinet front, two separate threats are running simultaneously, and the combination is what makes this week's picture difficult. The FortiBleed campaign has compromised thirty thousand seven hundred ninety-one Fortinet firewalls across a hundred and ninety-four countries.
Compounding that, three separate Fortinet FortiSandbox vulnerabilities are being actively exploited right now. All three carry CVSS scores of nine point one.
Oracle released its June Critical Patch Update, covering two hundred forty-five vulnerabilities. Oracle Fusion Middleware alone received a hundred and six patches, fifty-three of which address flaws exploitable over a network without any credentials required.
Chapter summary auto-generated from the verified script. Listen to the full episode for the complete content.