Skip to content

other

Qilin

Qilin is a ransomware-as-a-service operation, also linked to "Korean Leaks" extortion, that breaches networks to steal and encrypt data for ransom.

Known aliases

  • Korean Leaks
  • Qilin ransomware

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

Qilin ransomware affiliate logged into Cisco firewall management with a credential scored 5.3

Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.

Publishers:dev.to

Reality

Evidence58
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence55
security3 publishers

Rapid7 counted 8,539 high-severity CVEs and 40 exploited ones. Patch coverage is now a vanity metric

Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.

Perspective Coverage

3 publishers
Builder
Builder 12%
Operator
Operator 76%
Investor
Investor 12%

Reality

Evidence62
Adoption
Insufficient
Hype gap+30
Incentives70
Confidence60
security17 publishers

AFP sizes the Shai-Hulud syndicate's take at more than 500,000 credentials

Two men arrested in Australia this week are alleged TeamPCP members. The AFP estimate filed alongside the case puts the worm's take at more than 500,000 credentials and 300GB of data, and that scale makes token lifetime the live question.

Perspective Coverage

17 publishers
Builder
Builder 33%
Operator
Operator 50%
Investor
Investor 17%

Reality

Evidence68
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence62
security6 publishers

Cisco's own July 23 log indicator predates its August date for FMC exploitation

CVE-2026-20079 hands unauthenticated attackers root on Secure Firewall Management Center. CISA wants federal boxes fixed by September 12. The hot fix closes the path but does not evict anyone who already walked it.

Perspective Coverage

6 publishers
Builder
Builder 23%
Operator
Operator 65%
Investor
Investor 12%

Reality

Evidence80
Adoption
Insufficient
Hype gap+15
Incentives60
Confidence74