Tomiris
Reports per quarter
CVEs named in reports
- CVE-2017-11882 KEV ransomware
- CVE-2018-0171 KEV
- CVE-2020-5902 KEV ransomware
- CVE-2021-1675 KEV ransomware
- CVE-2021-26605
- CVE-2021-34527 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2023-28252 KEV ransomware
- CVE-2025-29824 KEV ransomware
- CVE-2025-32433 KEV
- CVE-2025-49704 KEV ransomware
- CVE-2025-49706 KEV ransomware
Show all 16 CVEs Show fewer
- CVE-2025-53770 KEV ransomware
- CVE-2025-53771
- CVE-2025-6218 KEV
- CVE-2025-8088 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Tomiris called, they want their Turla malware back
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tomiris called, they want their Turla malware back
-
APT_trends_report_Q2_2022_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2022_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q3 2021
Show all 11 reports Show fewer
-
DarkHalo after SolarWinds- the Tomiris connection (UNC2849)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DarkHalo after SolarWinds- the Tomiris connection (UNC2849)
Newest first. Details opens the report in Explore.