Scattered Spider’s Structure More Like a Cybercrime Collective Than a Unified Gang
2026-07-07T14:52:19Z•05fbb83410f8cd52c49278242231268a84a4054688c2fd08fbb5b7846dfc46dd
adobe-coldfusionai-securitycavern-manticorefileless-malwarejadepuffermacos-xpcmillenium-ratmirainetnutopera-gxoracle-peoplesoftousabanpopa-botnetprompt-injectionpurelog-stealerqilinransomwareransomware-as-a-servicermm-exploitscattered-spidersimplehelpsupply-chain-attackstinyRCTveil#dropzero-day
What happened
A cluster of high-impact cyber incidents and research findings: multiple zero-day vulnerabilities are being actively exploited (notably an Adobe ColdFusion flaw rated CVSS 10.0 and Oracle PeopleSoft zero-day tied to several breaches), a critical SimpleHelp RMM bug has been weaponised to deliver malware, and destructive/strategic ransomware activity (including agentic ‘JadePuffer’ and market-dominant Qilin RaaS) is escalating. Additional notable developments include new nation-linked threat actors (Cavern Manticore, TinyRCT), large-scale botnet/RAT campaigns (Millenium RAT, NetNut/Popa/Mirai),
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 05fbb83410f8cd52c49278242231268a84a4054688c2fd08fbb5b7846dfc46dd
- Enrichment time
- 2026-07-07T14:52:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.