New BlackFile extortion group linked to surge of vishing attacks

2026-04-24T19:23:32Zf82cd8f68c27a4f222a38d3334e4e719810ea0280c897890bfae456c000db7dd
DORAbreeze-cachecisacompliancecopilotcredential-theft','bitwarden'critical-vulnerabilitydata-theftextortionfile-uploadlinuxlocal-privilege-escalationmicrosoftmicrosoft-entranpmpack2therootpackagekitpasskeyspasswordlesssupply-chain-compromisevishingweb-applicationwordpressxsszimbra

What happened

The collection highlights a surge of active and emerging threats across multiple vectors: a new financially motivated extortion group (BlackFile) using vishing and data theft; active exploitation of critical vulnerabilities including a Breeze Cache WordPress arbitrary file upload bug and a widespread Zimbra XSS affecting over 10,000 instances; a local privilege escalation flaw dubbed Pack2TheRoot impacting PackageKit that allows local users to gain root; supply-chain compromises (Bitwarden CLI npm package and Checkmarx KICS artifacts) used to harvest developer credentials; Trigona ransomware’s

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
f82cd8f68c27a4f222a38d3334e4e719810ea0280c897890bfae456c000db7dd
Enrichment time
2026-04-24T19:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.