Skip to content
Signals
NVD · CVE-2026-7726 · 6.5 · The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::template_sync(NVD · CVE-2026-7693 · 7.2 · The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization oNVD · CVE-2026-7520 · 8.1 · The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` anNVD · CVE-2026-7444 · 8.1 · The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missinCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-7726 · 6.5 · The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::template_sync(NVD · CVE-2026-7693 · 7.2 · The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization oNVD · CVE-2026-7520 · 8.1 · The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` anNVD · CVE-2026-7444 · 8.1 · The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missinCISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07CISA KEV · CVE-2026-34486 · 7.5 · Apache Tomcat Missing Encryption of Sensitive Data Vulnerability · Added 2026-08-04 · Due 2026-08-07
← Campaigns
ActiveTLP:AMBERConfidence: High

Operation BlackHarvest

First seen January 15, 2026 · Last seen May 20, 2026

Public preview

Summary and targeting visible. Pro adds TTP and actor context, Pro+ adds IOC exports and enrichment.

Plans →

Summary

Double-extortion ransomware campaign targeting healthcare and manufacturing organizations through initial access broker partnerships. Uses phishing and VPN credential abuse for entry.

Target Sectors

HealthcareManufacturing

Target Regions

North America

Safety Note

Fictional campaign. No real victim identifiers, ransom amounts or leak site data included.

Related CVEs

MITRE ATT&CK Techniques

T1566.001Spearphishing Attachment

Initial Access

Train users to identify phishing. Deploy email gateway filtering. Enable attachment sandboxing. Block macro execution by default.

T1486Data Encrypted for Impact

Impact

Maintain offline backups. Monitor for mass file modification events. Restrict execution of unknown binaries. Implement endpoint detection for encryption behavior.

T1078Valid Accounts

Persistence

Enforce MFA on all accounts. Monitor for impossible travel and unusual login patterns. Implement privileged access management. Review service account usage.

T1133External Remote Services

Initial Access

Enforce MFA on all remote access. Restrict VPN/RDP to allowlisted networks where possible. Monitor remote access logs for anomalies. Patch remote access infrastructure promptly.