Caramel Tsunami
Also reported as SOURGUM, Candiru and DEV-0236. Linked to Israel by one source.
Reports per quarter
CVEs named in reports
- CVE-2012-5687
- CVE-2013-3900 KEV
- CVE-2013-5947
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4404 KEV
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-1130 KEV
- CVE-2015-1635 KEV
Show all 77 CVEs Show fewer
- CVE-2015-2051 KEV
- CVE-2015-7248
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-5638 KEV ransomware
- CVE-2018-10562 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-3568 KEV
- CVE-2019-6225
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-1472 KEV ransomware
- CVE-2020-1472122
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-21166 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-28310 KEV
- CVE-2021-30551 KEV
- CVE-2021-30860 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-31979 KEV
- CVE-2021-3197961
- CVE-2021-33742 KEV
- CVE-2021-33771 KEV
- CVE-2021-3377162
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-35247 KEV
- CVE-2021-36934 KEV
- CVE-2021-38647 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-4104
- CVE-2021-44228 KEV ransomware
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-0609 KEV
- CVE-2022-1040 KEV
- CVE-2022-20821 KEV
- CVE-2022-2294 KEV ransomware
- CVE-2022-26766
- CVE-2022-26871 KEV
- CVE-2022-27518 KEV
- CVE-2022-28810 KEV
- CVE-2022-29499 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-3236 KEV
- CVE-2022-40139 KEV
- CVE-2022-41040 KEV ransomware
- CVE-2022-41128 KEV
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-44698 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-41991 KEV
- CVE-2023-41992 KEV
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Chrysaor (Malware Family)
-
Move, Patch, Get Out the Way- 2022 Zero-Day Exploitation Continues at an Elevated Pace
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Move, Patch, Get Out the Way- 2022 Zero-Day Exploitation Continues at an Elevated Pace
-
The Return of Candiru- Zero-days in the Middle East
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Return of Candiru- Zero-days in the Middle East
Show all 36 reports Show fewer
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
yir-cyber-threats-report-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-report-download.pdf
-
CatalanGate Extensive Mercenary Spyware Operation against Catalans Using Pegasus and Candiru
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor CatalanGate Extensive Mercenary Spyware Operation against Catalans Using Pegasus and Candiru
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t32021
-
Pegasus vs. Predator- Dissident's Doubly-Infected iPhone Reveals Cytrox Mercenary Spyware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Pegasus vs. Predator- Dissident's Doubly-Infected iPhone Reveals Cytrox Mercenary Spyware
-
Strategic web compromises in the Middle East with a pinch of Candiru _ WeLiveSecurity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Strategic web compromises in the Middle East with a pinch of Candiru _ WeLiveSecurity
-
Strategic web compromises in the Middle East with a pinch of Candiru
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Strategic web compromises in the Middle East with a pinch of Candiru
-
Mercenary APTs – An Exploration
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Mercenary APTs – An Exploration
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t22021
-
Microsoft Digital Defense Report OCTOBER 2021
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Digital Defense Report OCTOBER 2021
-
How Data Brokers Sell Access to the Backbone of the Internet
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How Data Brokers Sell Access to the Backbone of the Internet
-
iPhones running latest iOS hacked to deploy NSO Group spyware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor iPhones running latest iOS hacked to deploy NSO Group spyware
-
Candiru's Spyware- How It Works And Attacking Journalists, Activists And Many More
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Candiru's Spyware- How It Works And Attacking Journalists, Activists And Many More
-
Fighting cyberweapons built by private businesses
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Fighting cyberweapons built by private businesses
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Protecting customers from a private-sector offensive actor using 0-day exploits and DevilsTongue malware
-
Hooking Candiru Another Mercenary Spyware Vendor Comes into Focus
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hooking Candiru Another Mercenary Spyware Vendor Comes into Focus
-
Researchers Say They Uncovered Uzbekistan Hacking Operations Due to Spectacularly Bad OPSEC
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Researchers Say They Uncovered Uzbekistan Hacking Operations Due to Spectacularly Bad OPSEC
Newest first. Details opens the report in Explore.