Lead · Ransomware
Ten ransomware crews peaked on the same day, and the vulnerability feed picked that day to go quiet
On 6 October, ten unaffiliated groups produced 193 of 389 event-timed items in our window, while NVD stopped publishing and Atlassian disclosed a critical unauthenticated file-access flaw across eight self-hosted products.
Qilin, SafePay, Everest, Akira, The Gentlemen, SilentRansomGroup, WallStreet, Incransom, Panzer and Storm all hit their maximum observed activity on the same calendar day: 19, 19, 13, 10, 39, 6, 5, 5, 4 and 7 items respectively, 193 of the 389 event-timed items in a four-day window, against 51 on 5 October and 88 on 7 October. Seven of the ten had a median of zero on every other day, which is to say they did not exist in these feeds until Tuesday and then existed quite a lot. We cannot tell you yet whether that is a coordinated dump-day on a forum nobody has shown us, or a pipeline catching its breath and exhaling four days of posts at once. Both hypotheses are in the hidden section with the tests that would kill them.
The timing is the part worth your coffee. NVD published 102 items into this window and then went silent through the two busiest days in it, which is when Atlassian warned that CVE-2026-21589 lets an attacker with no login read specific files in eight Data Center products, Jira, Confluence, Bitbucket, Bamboo and Crowd among them. If your patch triage is a pipe with a national feed at one end of it, Tuesday was a day you spent reading Monday.
This is the uncomfortable true version: your vulnerability management programme is not a process, it is a supply chain, and yesterday one of its suppliers took the afternoon off without telling you. The attackers did not need to know that. They just needed it to be Tuesday.
Why it mattersIf a feed outage can silently remove a critical unauthenticated flaw from your triage queue, your queue is not a control, it is a rumour with SLAs.