Threats Affecting Russia
View all threats affecting or targeting Russia. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Russia
Click on any threat for detailed analysis and mitigation recommendations
Toy Ghouls’ new toy: the GenieLocker ransomware 0 GenieLocker is a new ransomware family active since March 2026, targeting organizations in the Russian Federation, primarily in manufacturing. Attributed to the financially motivated Toy Ghouls group (also known as Bearlyfy, Labubu, and Laboo.boo), this custom-designed ransomware marks a shift from their previous reliance on third-party encryption tools like RedAlert, LockBit, and Babuk. GenieLocker exists in two variants: PE builds for Windows and ELF builds for Linux and ESXi. The Windows version features sophisticated capabilities including process termination, service shutdown, anti-debugging techniques, and advanced encryption using the libsodium library with XChaCha20-Poly1305 algorithm. Initial access typically occurs through compromised VPN credentials from trusted partners, followed by deployment of tools like Mimikatz, SoftPerfect Network Scanner, and SSH utilities for lateral movement before deploying ransomware using PsExec and PAExec. Join the discussion | AlienVault OTX General | 07/30/2026, 09:41:18 UTC Added: 07/31/2026, 06:22:12 UTC |
ZDI-26-456: GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityCVE-2026-18303 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18303. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
ZDI-26-458: GIMP TIF File Parsing Integer Overflow Remote Code Execution VulnerabilityCVE-2026-18305 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18305. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
ZDI-26-459: GIMP SGI File Parsing Integer Overflow Remote Code Execution VulnerabilityCVE-2026-18306 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18306. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
ZDI-26-460: GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution VulnerabilityCVE-2026-18307 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18307. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:04 UTC |
ZDI-26-461: GIMP TIF File Parsing Integer Overflow Remote Code Execution VulnerabilityCVE-2026-18308 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18308. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:03 UTC |
ZDI-26-462: GIMP APNG File Parsing Integer Overflow Remote Code Execution VulnerabilityCVE-2026-18309 0 This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-18309. Join the discussion | Zero Day Initiative | 07/29/2026, 05:00:00 UTC Added: 07/30/2026, 15:59:02 UTC |
vBulletin fixes critical pre-auth RCE flaw with public exploit 0 A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...] Join the discussion | Bleeping Computer | 07/28/2026, 18:08:50 UTC Added: 07/28/2026, 18:22:07 UTC |
Unpatched Fastjson Vulnerability Exploited in Attacks 0 The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on SecurityWeek . Join the discussion | SecurityWeek | 07/28/2026, 07:27:55 UTC Added: 07/28/2026, 07:37:06 UTC |
Hackers target US firms in FastJson RCE zero-day attacks 0 Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...] Join the discussion | Bleeping Computer | 07/27/2026, 23:49:44 UTC Added: 07/27/2026, 23:52:09 UTC |
Showing 1 to 10 of 13 results