Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ransomware Attack Exploits SmarterMail Vulnerability

Ransomware Attack Exploits SmarterMail Vulnerability

Posted on February 9, 2026 By CWS

An unpatched vulnerability in its own SmarterMail email server has led to a ransomware attack against IT management software company, SmarterTools. The breach occurred on January 29, significantly impacting the company’s office network and a data center responsible for quality control testing systems, the SmarterTools portal, and its Hosted SmarterTrack network.

Extent of the Security Breach

The attack did not extend to the company’s website, shopping cart, or My Account portal, as these services were hosted on a separate network. According to SmarterTools Chief Commercial Officer Derek Curtis, the hackers gained entry through a virtual machine running an outdated instance of SmarterMail. This allowed them to access Windows servers within the data center, ultimately compromising 12 servers.

In response to the breach, SmarterTools immediately powered down all servers at the affected locations and disabled internet access to thoroughly assess the situation. The company took swift actions, including removing as many Windows systems as possible and deactivating Active Directory services. Network-wide password resets were also implemented to bolster security.

Identifying the Attackers

The perpetrators of this cyber assault have been linked to the ransomware group known as Warlock, which surfaced in June 2025 and is suspected to operate from China. It is believed that the attackers exploited CVE-2026-24423, a critical remote code execution vulnerability with a CVSS score of 9.3. This flaw, along with two others—CVE-2026-23760 and CVE-2025-52691—was addressed in a security patch released on January 15.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) had recently issued a warning about CVE-2026-24423 being leveraged in ransomware attacks, which likely referenced the incident involving SmarterTools and possibly other compromised customers.

Recommendations and Precautions

To mitigate further risk, SmarterTools strongly advises its customers to update to the latest SmarterMail version without delay. Curtis highlighted the importance of installing build 9526, released on January 22, which provides enhancements to the previous security fixes. Ensuring installations are up-to-date is challenging but crucial, as even minor updates can prevent significant issues like denial-of-service attacks that can overburden server resources.

This incident underscores the need for robust cybersecurity practices and timely updates to safeguard systems against ever-evolving threats. It also serves as a reminder for organizations to regularly review and enhance their security measures to protect against potential vulnerabilities.

Related stories include recent attacks exploiting vulnerabilities in various software, emphasizing the persistent threat of cyberattacks in the IT landscape.

Security Week News Tags:CISA warning, CVE-2026-24423, Cybersecurity, IT security, network security, Ransomware, SmarterMail, SmarterTools, Vulnerability, Warlock group, Windows systems

Post navigation

Previous Post: SolarWinds WHD Exploited in Complex Multi-Stage Cyber Attacks
Next Post: Criminal IP Boosts IBM QRadar with Real-Time Threat Data

Related Posts

Webinar Today: AI and the Trust Dilemma: Balancing Innovation and Risk Webinar Today: AI and the Trust Dilemma: Balancing Innovation and Risk Security Week News
In Other News: HashJack AI Browser Attack, Charming Kitten Leak, Hacker Unmasked In Other News: HashJack AI Browser Attack, Charming Kitten Leak, Hacker Unmasked Security Week News
EU Sets February Deadline for Verdict on Google’s B Wiz Acquisition EU Sets February Deadline for Verdict on Google’s $32B Wiz Acquisition Security Week News
Honoring Our Veteran Readers: Thank You for Your Service Honoring Our Veteran Readers: Thank You for Your Service Security Week News
NPM Infrastructure Abused in Phishing Campaign Aimed at Industrial and Electronics Firms NPM Infrastructure Abused in Phishing Campaign Aimed at Industrial and Electronics Firms Security Week News
Critical Vulnerability Patched in Citrix NetScaler Critical Vulnerability Patched in Citrix NetScaler Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News