Two threat actors chained unpatched SonicWall zero-days for root access on enterprise VPNs before disclosure — then INC Ransomware weaponized the same flaws at scale. Plus Microsoft's record 570-fix Patch Tuesday, the Craneware healthcare supply chain breach, and 23M Paidwork records on cybercrime forums.
Audio is available on Spreaker — see link below.
Two threat actors. Two unpatched flaws.
What makes this more concerning is what came next. Rapid7 identified INC Ransomware as an active exploiter of the same vulnerability chain.
Elsewhere, Microsoft shipped a record five hundred and seventy fixes in this month's Patch Tuesday update, KB5101650. Two of those are zero-days under active exploitation.
The Craneware breach adds to what's becoming a clear pattern in 2026. The UK-based company provides billing software to thousands of US hospitals and pharmacies.
Two more items to track. Paidwork, a microtask platform, had twenty-three point three million user records exposed from a March intrusion.
The two watchpoints that matter most right now: whether additional SonicWall victims emerge as incident response investigations widen, and how quickly healthcare sector organizations assess their exposure through billing software providers like Craneware. Both situations are actively developing with significant gaps in confirmed information.
Chapter summary auto-generated from the verified script. Listen to the full episode for the complete content.