Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ransomware Attack Exploits SmarterMail Vulnerability

Ransomware Attack Exploits SmarterMail Vulnerability

Posted on February 9, 2026 By CWS

An unpatched vulnerability in its own SmarterMail email server has led to a ransomware attack against IT management software company, SmarterTools. The breach occurred on January 29, significantly impacting the company’s office network and a data center responsible for quality control testing systems, the SmarterTools portal, and its Hosted SmarterTrack network.

Extent of the Security Breach

The attack did not extend to the company’s website, shopping cart, or My Account portal, as these services were hosted on a separate network. According to SmarterTools Chief Commercial Officer Derek Curtis, the hackers gained entry through a virtual machine running an outdated instance of SmarterMail. This allowed them to access Windows servers within the data center, ultimately compromising 12 servers.

In response to the breach, SmarterTools immediately powered down all servers at the affected locations and disabled internet access to thoroughly assess the situation. The company took swift actions, including removing as many Windows systems as possible and deactivating Active Directory services. Network-wide password resets were also implemented to bolster security.

Identifying the Attackers

The perpetrators of this cyber assault have been linked to the ransomware group known as Warlock, which surfaced in June 2025 and is suspected to operate from China. It is believed that the attackers exploited CVE-2026-24423, a critical remote code execution vulnerability with a CVSS score of 9.3. This flaw, along with two others—CVE-2026-23760 and CVE-2025-52691—was addressed in a security patch released on January 15.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) had recently issued a warning about CVE-2026-24423 being leveraged in ransomware attacks, which likely referenced the incident involving SmarterTools and possibly other compromised customers.

Recommendations and Precautions

To mitigate further risk, SmarterTools strongly advises its customers to update to the latest SmarterMail version without delay. Curtis highlighted the importance of installing build 9526, released on January 22, which provides enhancements to the previous security fixes. Ensuring installations are up-to-date is challenging but crucial, as even minor updates can prevent significant issues like denial-of-service attacks that can overburden server resources.

This incident underscores the need for robust cybersecurity practices and timely updates to safeguard systems against ever-evolving threats. It also serves as a reminder for organizations to regularly review and enhance their security measures to protect against potential vulnerabilities.

Related stories include recent attacks exploiting vulnerabilities in various software, emphasizing the persistent threat of cyberattacks in the IT landscape.

Security Week News Tags:CISA warning, CVE-2026-24423, Cybersecurity, IT security, network security, Ransomware, SmarterMail, SmarterTools, Vulnerability, Warlock group, Windows systems

Post navigation

Previous Post: SolarWinds WHD Exploited in Complex Multi-Stage Cyber Attacks
Next Post: Criminal IP Boosts IBM QRadar with Real-Time Threat Data

Related Posts

Rethinking Security for Agentic AI Rethinking Security for Agentic AI Security Week News
 Million Worth of Bitcoin Seized in Cryptomixer Takedown $29 Million Worth of Bitcoin Seized in Cryptomixer Takedown Security Week News
Critical Apache Tika Vulnerability Leads to XXE Injection Critical Apache Tika Vulnerability Leads to XXE Injection Security Week News
LLMs Hijacked, Monetized in ‘Operation Bizarre Bazaar’ LLMs Hijacked, Monetized in ‘Operation Bizarre Bazaar’ Security Week News
Rowhammer Attack Demonstrated Against Nvidia GPU Rowhammer Attack Demonstrated Against Nvidia GPU Security Week News
Flickr Alerts Users to Data Exposure via Email Service Flickr Alerts Users to Data Exposure via Email Service Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Target Ivanti EPMM Devices with Hidden Backdoors
  • China-Linked Group Targets Singapore Telecom in Cyber Attack
  • Critical Roundcube Flaw Allows Email Tracking
  • Lema AI Secures $24M to Revolutionize Third-Party Risk
  • Criminal IP Boosts IBM QRadar with Real-Time Threat Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Target Ivanti EPMM Devices with Hidden Backdoors
  • China-Linked Group Targets Singapore Telecom in Cyber Attack
  • Critical Roundcube Flaw Allows Email Tracking
  • Lema AI Secures $24M to Revolutionize Third-Party Risk
  • Criminal IP Boosts IBM QRadar with Real-Time Threat Data

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark