Active Threat Alerts
Real-time cybersecurity threats targeting your industry. Updated continuously by Sentry's SOC team.
Black Basta Ransomware Targeting SMB Healthcare & Legal Sectors
Black Basta ransomware group has launched a new campaign specifically targeting healthcare providers and law firms under 200 employees using malicious Word macros in fake invoice emails.
Critical RCE Vulnerability in Fortinet FortiOS (CVE-2024-21762)
Fortinet has released an emergency patch for a critical out-of-bounds write vulnerability in FortiOS SSL-VPN. Active exploitation detected in the wild targeting enterprises.
DocuSign Impersonation Campaign Targeting Professional Firms
Threat actors are sending highly convincing DocuSign-branded phishing emails to professional service firms, attorneys, and CPAs requesting "urgent contract review."
MOVEit-Style Vulnerability in Popular File Transfer Platform
A new SQL injection vulnerability discovered in a widely-used managed file transfer solution affects thousands of healthcare and financial organizations. Active scanning observed.
AI-Generated Voice Cloning BEC Attacks Targeting CFOs
A sophisticated threat group is using AI voice cloning to impersonate executives in phone calls to finance staff, authorizing fraudulent wire transfers averaging $340,000.
Microsoft 365 Default Settings Exposing Thousands of Firms to Email Spoofing
Security researchers have identified that 43% of small business Microsoft 365 tenants do not have DMARC enforcement enabled, allowing attackers to send emails that appear to be from the firm's own domain.
LockBit 3.0 Variant Resurfaces Targeting Manufacturing OT Networks
A new LockBit 3.0 variant has been observed specifically targeting operational technology networks in manufacturing, including SCADA and HMI systems previously considered isolated.
Windows Print Spooler Vulnerability Affecting Legacy Systems (CVE-2024-38199)
Microsoft patched a remote code execution vulnerability in the Windows Print Spooler service. While patched in current Windows versions, legacy systems (Windows 10 pre-22H2, Server 2016) remain vulnerable.