New BlackFile extortion group linked to surge of vishing attacks
2026-04-24T19:23:32Z•f82cd8f68c27a4f222a38d3334e4e719810ea0280c897890bfae456c000db7dd
DORAbreeze-cachecisacompliancecopilotcredential-theft','bitwarden'critical-vulnerabilitydata-theftextortionfile-uploadlinuxlocal-privilege-escalationmicrosoftmicrosoft-entranpmpack2therootpackagekitpasskeyspasswordlesssupply-chain-compromisevishingweb-applicationwordpressxsszimbra
What happened
The collection highlights a surge of active and emerging threats across multiple vectors: a new financially motivated extortion group (BlackFile) using vishing and data theft; active exploitation of critical vulnerabilities including a Breeze Cache WordPress arbitrary file upload bug and a widespread Zimbra XSS affecting over 10,000 instances; a local privilege escalation flaw dubbed Pack2TheRoot impacting PackageKit that allows local users to gain root; supply-chain compromises (Bitwarden CLI npm package and Checkmarx KICS artifacts) used to harvest developer credentials; Trigona ransomware’s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- f82cd8f68c27a4f222a38d3334e4e719810ea0280c897890bfae456c000db7dd
- Enrichment time
- 2026-04-24T19:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.