2D ago
2 sources
Europol says it flagged 4,340 URLs for removal during a June-July 2026 operation targeting online content linked to The Com, a decentralized extremist network that recruits and abuses young people online. The action was run by Europol's EU Internet Referral Unit and Spain's CITCO with investigators from nine countries, and focused on content tied to self-harm, child sexual abuse material, violent attacks, grooming, doxing, swatting, and attack manuals; Europol says The Com includes subgroups involved in cyber intrusions and ransomware.
— This matters because The Com blends violent extremism with cyber-enabled abuse such as sextortion, doxing, swatting, and ransomware, often targeting minors through mainstream online platforms. Platforms, investigators, schools, and families should watch for coded recruitment content and coercion tactics, while defenders should note the group’s overlap with cybercrime activity.
Sources: Europol flags 4,340 URLs for removal in 'The Com' crackdown, Europol flags 4,340 'horrific' URLs linked to The Com
2D ago
4 sources
Swiss rail manufacturer Stadler says the Everest extortion group breached a data exchange platform shared with one of its suppliers and demanded about $12.3 million not to leak stolen data. Stadler says the incident happened in mid-July 2026, that its own IT systems and production were not disrupted, and that the attackers took technical information from the supplier side rather than security-relevant or personal data. The company filed a criminal complaint and says it will not pay.
— This is a real supply-chain-linked extortion event affecting a major transportation manufacturer, even though Stadler says operations and rail vehicles were not impacted. Organizations that share files or platforms with suppliers should review third-party access, data exchange security, and exposure of technical documents.
Sources: Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack, Swiss train maker Stadler refuses Everest $12 million ransomware demand, Swiss train maker tells ransomware crooks to get off at the next stop (+1 more)
2D ago
4 sources
Attackers are actively breaking into organizations that use PTC Windchill and FlexPLM, a product lifecycle management platform used by many industrial companies. The flaw, CVE-2026-12569, is an improper input validation bug that lets a remote unauthenticated attacker run arbitrary code through crafted requests. PTC began releasing patches and mitigations on June 17 and said attackers have used the bug to install persistent JSP web shells for remote command execution and data theft; CISA has added it to the Known Exploited Vulnerabilities catalog.
— This is urgent for manufacturers and other firms that rely on Windchill or FlexPLM, because attackers can break in over the network without valid credentials and keep long-term access. Organizations should apply PTC's patches or mitigations immediately, check for the published indicators of compromise, and treat exposed servers as potentially compromised.
Sources: First-Ever Exploitation of PTC Windchill Vulnerability Discovered in the Wild, CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue, CISA sets urgent deadline to fix Cisco flaw exploited in attacks (+1 more)
3D ago
1 sources
Cisco Talos says the Chaos ransomware group is deploying a new Rust-based backdoor called msaRAT that hides its command traffic by sending it through Google Chrome or Microsoft Edge instead of connecting directly to attacker servers. The malware is loaded in memory from an MSI installer posing as a Windows update, then uses the Chrome DevTools Protocol to control a headless browser, reach a Cloudflare Workers endpoint, and relay encrypted WebRTC traffic through Twilio TURN servers to obscure the attackers’ infrastructure.
— This gives attackers a stealthier way to stay in networks and evade security tools because the malware blends into normal browser traffic. Organizations should hunt for the reported indicators, watch for suspicious headless browser activity and remote debugging use, and harden defenses against the email, voice-phishing, and fake IT/software-update lures used to start these intrusions.
Sources: New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
4D ago
4 sources
A cyberattack on Japanese cold-chain and frozen-food company Nichirei disrupted deliveries to KFC Japan and may force some stores to limit menus, shorten hours, or close. Nichirei said unauthorized access caused system failures that stopped shipment and warehouse operations, and later confirmed attackers accessed a server storing personal information. No ransomware family, malware, or CVE has been identified publicly, and the company said it is withholding details to prevent further damage.
— This shows how an attack on a logistics supplier can quickly spill into consumer-facing disruptions and possible data exposure. Organizations that depend on Nichirei or similar third parties should review contingency plans and watch for breach notifications, while affected users should monitor for updates about any exposed personal data.
Sources: Cyberattack threatens utterly critical infrastructure in Japan: KFC, Cyberattack on Japan's largest cold-chain operator disrupts KFC, supermarket supplies, Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei (+1 more)
4D ago
5 sources
Coca-Cola said a ransomware attack at its Fairlife dairy subsidiary temporarily stopped production of Fairlife products at U.S. facilities. In an SEC Form 8-K, the company said attackers gained unauthorized access to some systems, including production-related systems, and that it activated incident response and business continuity measures; Canadian production was not affected, and no ransomware group or data theft has yet been confirmed.
— This is an operationally significant ransomware disruption affecting food production, not just office systems. Organizations with manufacturing or industrial operations should review segmentation, backup recovery, and business continuity plans, while customers and partners should watch for supply disruptions and any later breach notifications.
Sources: Coca-Cola says Fairlife ransomware attack halts US dairy production, Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack, Dairy company Fairlife suspends production in US after cyber incident (+2 more)
10D ago
5 sources
French and Dutch authorities, with Europol and partners from 16 countries, seized 33 servers and multiple domains tied to the 'First VPN' service, which investigators say was widely used in ransomware, fraud, and data-theft attacks. Authorities arrested or questioned a Ukrainian administrator, infiltrated the service, and said intelligence from the takedown identified thousands of users, with 506 users and 83 intelligence packages shared internationally.
— The takedown targets a criminal privacy service that allegedly supported major cybercrime operations and may generate follow-on investigations into ransomware and data-theft cases. Defenders and incident responders should watch for new attribution and victim-notification leads emerging from the seized data.
Sources: Police seize “First VPN” service used in ransomware, data theft attacks, Europe dismantles VPN service used by cybercriminals to hide ransomware attacks, ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested (+2 more)
10D ago
1 sources
A newly identified ransomware actor called Spirals broke into a South Asian IT services company and went from initial access to data theft and encryption in less than a day. Symantec says the attackers entered through an internet-exposed Microsoft IIS server, uploaded an ASP.NET web shell, enabled Remote Desktop, dumped credentials from the SAM and LSASS, moved laterally with Windows Management Instrumentation (WMI) and PsExec, and used revsocks, Chisel, and Cloudflare Tunnel for persistence. The Rust-based ransomware used intermittent encryption to speed up locking files and dropped a ransom note named RECOVERY_SECTION.log.
— This is a fast-moving ransomware playbook that can leave defenders very little time to respond once attackers get in. Organizations with exposed IIS servers should urgently review exposure, hunt for the listed tools and indicators, and verify that endpoint protection, backups, and lateral-movement controls are working.
Sources: New Spirals ransomware encrypts victim network in under 24 hours
11D ago
14 sources
A researcher’s public release of six Windows zero-days has already led attackers to exploit three of them, and Microsoft says more unpatched flaws remain. Microsoft named the bugs as RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma; it said BlueHammer, RedSun, and UnDefend saw attacks after proof-of-concept exploit code was posted, while YellowKey is tracked as CVE-2026-45585 and, along with GreenPlasma and MiniPlasma, still lacks a fix.
— Windows defenders may have little time between public disclosure and real-world attacks, especially when proof-of-concept exploit code is available. Organizations should review Microsoft mitigations immediately, monitor for compromise tied to these bug names and CVE-2026-45585, and prioritize hardening or temporary workarounds where patches do not yet exist.
Sources: Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops, Microsoft calls zero-day releases ‘never justifiable’ as researcher threatens to drop more, Microsoft says it will not pursue security researchers after zero-day backlash (+11 more)
11D ago
3 sources
The U.S. unsealed an indictment against three Russians accused of running Media Land and ML Cloud, hosting services that allegedly helped cybercriminals carry out attacks against victims in the United States and elsewhere. Prosecutors say Aleksandr Volosovik, Yulia Pankova, and Kirill Zatolokin provided infrastructure and technical support designed to shield criminal customers from law enforcement, enabling ransomware groups including LockBit, BlackSuit, and Play as well as stolen-card marketplaces such as Briansclub and Bidencash; the indictment cites 44 victims and about $62 million in losses.
— Bulletproof hosting is a key enabler for ransomware, fraud, and stolen-data markets, so this case matters beyond the named defendants. Defenders should note the specific infrastructure and actor links, while affected organizations and the public should expect continued law-enforcement disruption efforts rather than an immediate end to related threats.
Sources: US unseals indictment against alleged operators of Russian bulletproof hosting service, US charges alleged operators of Russian bulletproof hosting service, US Charges Russian Individuals and Firms for Running Cybercrime Services
12D ago
3 sources
Canada’s signals intelligence agency says it carried out state-authorized hacks in 2025 against a ransomware-as-a-service gang, foreign fentanyl-chemical traffickers, and a violent extremist group. In its annual report, the Communications Security Establishment said one operation made the ransomware gang’s infrastructure inoperable and deleted stolen data being advertised on the dark web, and that it also conducted 10 additional technical disruptions against major ransomware gangs last year. The specific groups, malware, and infrastructure were not named.
— This is a rare public acknowledgment that a government agency directly disrupted criminal cyber infrastructure rather than only warning about it. Defenders should watch for follow-on disclosures about which ransomware groups were hit, because that could affect threat tracking, infrastructure blocklists, and victim-notification efforts.
Sources: Canadian spy agency reports hacking three criminal groups in 2025, In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops, Canada’s Electronic Spy Agency Conducted Cyberattacks on Criminals Brokering Fentanyl Ingredients, Report Says
16D ago
2 sources
A man accused of helping deploy Ryuk ransomware against U.S. victims has pleaded guilty in federal court after being extradited from Ukraine. U.S. prosecutors say Karen Serobovich Vardanyan provided initial access to corporate networks and helped deploy Ryuk between November 2019 and April 2020, encrypting hundreds of servers and workstations. Court records cited attacks including a Michigan company, a technology company in Oregon, and a school in Texas, with the conspirators allegedly receiving about 1,610 bitcoin in ransom payments.
— This matters because it ties a named individual to one of the most damaging ransomware operations and shows continued prosecution years after the attacks. Defenders and affected sectors should treat it as a reminder that initial-access brokers and old Ryuk tradecraft still shape current ransomware threats descended from Ryuk and Conti.
Sources: Ryuk ransomware member pleads guilty in the US, faces 15 years in prison, Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence
16D ago
2 sources
Microsoft says a threat actor has used a destructive Windows backdoor called GigaWiper for more than eight months to maintain access and sabotage infected systems. First seen in October 2025, the Go-based malware combines older wiping components with backdoor functions, supports command-and-control through RabbitMQ and Redis, and can run PowerShell, upload files, take screenshots, record screens, trigger a Blue Screen of Death, encrypt files in both reversible and destructive modes, and wipe disks at the physical-drive level.
— This is not just another infostealer or ransomware sample: it gives attackers a single tool for stealthy access and for crippling machines on demand. Defenders should hunt for the malware’s persistence and command-and-control activity, especially RabbitMQ, Redis, MinIO Client, and destructive commands, because the impact can range from spying to irreversible data loss.
Sources: GigaWiper Combines Multiple Malware for System-Level Sabotage, Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
16D ago
4 sources
A former ransomware negotiator at DigitalMint was sentenced after prosecutors said he secretly helped BlackCat ransomware attacks against U.S. organizations. Court records say Angelo Martino worked with two other former DigitalMint and Sygnia negotiators as BlackCat affiliates between April 2023 and April 2025, demanded payments, threatened to leak stolen data, and shared victims’ insurance limits and negotiation positions with the gang to maximize ransom demands.
— This matters because it shows attackers can exploit trusted insiders at companies hired to help victims during ransomware crises. Organizations using outside negotiators or incident-response firms should review access, logging, conflict controls, and what sensitive insurance and negotiation data those vendors can see.
Sources: Former ransomware negotiator gets 4 years for BlackCat attacks, Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks, Third US Security Expert Sentenced to Prison for Helping Ransomware Gang (+1 more)
17D ago
1 sources
Latvia's state-owned forestry company LVM is still restoring systems weeks after a ransomware attack knocked customer and contractor services offline. Latvian authorities said the attackers likely spent more than a week in the network and exploited an unpatched vulnerability in software that had not been updated for two years. CERT.LV said about 44 GB of data was leaked, including internal documents, email, code repositories, digital certificates, cryptographic keys, and user credentials.
— This is a significant ransomware and data-theft incident affecting a major state-owned enterprise, with possible downstream risk from leaked credentials and cryptographic material. Organizations in Latvia, especially public-sector and state-linked entities, should review exposure, rotate affected secrets and certificates, and urgently patch internet-facing systems.
Sources: Latvian forestry company still restoring systems weeks after ransomware attack
17D ago
2 sources
Mount Royal University in Calgary says hackers broke into its network, stole files from a shared storage drive used by students and staff, and deleted data from university systems. The university says the June 17 attack disrupted online services, internet access, and internal systems; data was confirmed stolen from certain folders on its H drive, while a separate J drive holding departmental data was wiped, with no current evidence it was copied first. The CMD Organization extortion group claimed the attack, published sample files including passport scans, and demanded 30 bitcoin.
— Students, employees, and former staff may face identity and privacy risks, while the university may lose some data permanently. Affected people should watch for direct breach notices and consider credit and identity monitoring; defenders in education should review file-share access, backup resilience, and extortion response plans.
Sources: Mount Royal University confirms breach as hackers claim attack, Mount Royal University Confirms Data Stolen in Ransomware Attack
19D ago
4 sources
A 19-year-old accused Scattered Spider member was extradited from Finland to the United States to face charges tied to hacking and extortion. The FBI says Peter Stokes helped breach an unnamed luxury jewelry retailer around May 12, 2025 by calling the IT help desk from Google Voice numbers, posing as employees, and getting password and multifactor authentication resets; the attackers allegedly compromised three accounts, including two IT administrator accounts, used ngrok for persistent access, stole data, and demanded $8 million in cryptocurrency.
— This matters because it gives defenders a concrete look at how Scattered Spider is still using help-desk impersonation to break into companies without exploiting software flaws. Organizations, especially those with privileged IT accounts, should harden help-desk identity checks, review MFA reset procedures, and monitor for unauthorized remote-access tools such as ngrok.
Sources: Teen suspect in Scattered Spider hacks is extradited to US, Alleged Scattered Spider hacker extradited to the United States, Alleged Scattered Spider Hacker Extradited to US (+1 more)
22D ago
3 sources
Researchers say an attacker used a large language model to automate a full ransomware and extortion attack against exposed servers, ending with encrypted and deleted data. Sysdig said the intrusion began by exploiting Langflow CVE-2025-3248, an unauthenticated remote-code-execution flaw, then moved to a production server running MySQL and Alibaba Nacos, abused Nacos CVE-2021-29441 and the product's default JWT signing key, added a backdoor admin, and encrypted 1,342 configuration records before dropping database schemas.
— Organizations running internet-exposed Langflow or Nacos instances could face fast, destructive break-ins that do not reliably allow recovery even if a ransom is paid. Defenders should urgently patch or isolate exposed systems, rotate credentials, and check for cron-based persistence, rogue Nacos admins, and database tampering.
Sources: Smooth AI criminal drives 'first' end-to-end agentic ransomware attack, Agentic AI Used to Conduct Ransomware Attack via Langflow, JadePuffer ransomware used AI agent to automate entire attack
24D ago
14 sources
Researchers say more than 30,000 Fortinet firewalls and virtual private network gateways were compromised and can expose the organizations behind them to further hacking. SOCRadar said a campaign it calls FortiBleed systematically tried known passwords against internet-exposed Fortinet devices, harvested working credentials, then monitored traffic and reused newly captured passwords to spread further; victims span companies and government bodies in more than 190 countries.
— Organizations using Fortinet edge devices may already have attackers inside even without a new software flaw. This is urgent for network defenders: audit Fortinet logins, rotate passwords and tokens, review device configurations, and check for signs of credential harvesting or unauthorized access.
Sources: 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs, FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices., Massive password-stealing attack hits 75k Fortinet firewalls (+11 more)
25D ago
1 sources
Check Point says code generated by DeepSeek can be adapted into a working browser-based ransomware attack that encrypts a victim’s local files after they approve a browser permission prompt. The sample, dubbed "InfernoGrabber 9000," is a Python Flask web app targeting Android users and abuses Chrome and Chromium-based browsers’ File System Access API to read and write local files without a traditional malware install, relying on phishing-style social engineering rather than a browser exploit or CVE.
— This lowers the barrier for criminals to build ransomware-like attacks that run in the browser, where users may trust the prompt because it comes from a legitimate browser feature. Defenders should review controls around Chromium-based browsers and file-access permissions, and users should be wary of websites asking for broad local file access.
Sources: Somebody told DeepSeek to build in-browser ransomware and it gleefully complied
25D ago
2 sources
Nidec says a ransomware attack hit part of the server environment at its Taiwanese subsidiary, Nidec Chaun Choung Technology, and the attackers are now demanding $2 million. The company said the June 22, 2026 incident led it to shut down the affected server and network to contain the damage and that it is investigating possible data leakage and any effect on production and shipping. Blackfield claims it stole data and threatened to publish or sell it if Nidec does not negotiate.
— This is a disruption and extortion risk for a large global manufacturer whose products feed automotive, computing, robotics, and other supply chains. Organizations connected to Nidec should watch for follow-on fraud or leaked documents, while manufacturers should review ransomware containment, segmentation, and backup recovery plans.
Sources: Blackfield ransomware asks Nidec Corporation for $2 million ransom, Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches
26D ago
1 sources
Arctic Wolf says multiple 2026 Anubis ransomware attacks began with either stolen VPN credentials or exploitation of CitrixBleed 2, putting organizations with exposed Citrix access at risk. The report ties Anubis intrusions to CVE-2025-5777 in Citrix NetScaler, then details follow-on use of legitimate remote management tools including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment, plus cloudflared, authenticated proxies, and SSH SOCKS tunnels for persistence and lateral movement.
— This matters because attackers are mixing a known edge-device flaw with normal-looking IT tools, making ransomware intrusions harder to spot until systems are already at risk. Organizations using Citrix remote access should patch and review VPN exposure, hunt for these remote admin tools, and closely monitor domain controllers, remote desktop servers, hypervisors, backup systems, and network storage.
Sources: From CitrixBleed 2 to Cloudflared: The Tools and Techniques Behind Anubis Ransomware Attacks
26D ago
2 sources
A former Huntress employee publicly alleged that a current company insider passed information from U.S. law enforcement to a ransomware actor known as DevMan, potentially putting customers at risk. The claims center on an alleged December 2025 insider incident rather than Huntress's separate Klue-related exposure; Huntress said the matter involved an employee who showed poor judgment in communicating with a cybercriminal, and said it took the concerns seriously. The article does not provide technical indicators, affected customer count, or independent confirmation from law enforcement.
— If true, this would be a serious insider-threat case at a security vendor, with possible exposure of investigative information and downstream risk to customers. Defenders should watch for confirmation, assess any Huntress notifications, and treat this as a potential trust and supply-chain concern rather than a proven breach at this stage.
Sources: Ex-Huntress analyst claims company insider fed info to a ransomware crim. Social media drama ensues, Huntress CEO says threat hunter used 'poor judgment' in alerting ransomware crim about law enforcement probe
26D ago
5 sources
CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog on May 20, 2026, citing evidence of active exploitation. The additions include legacy Microsoft Windows, DirectX, Internet Explorer, and Adobe Reader bugs, plus Microsoft Defender flaws CVE-2026-41091 (elevation of privilege) and CVE-2026-45498 (denial of service). Federal agencies must remediate by the deadlines set under BOD 22-01.
— KEV additions indicate real-world exploitation and help defenders prioritize patching and mitigations. Organizations, especially federal agencies, should urgently assess exposure to the newly listed Microsoft Defender and legacy Windows-related vulnerabilities.
Sources: CISA Adds Seven Known Exploited Vulnerabilities to Catalog, Microsoft warns of new Defender zero-days exploited in attacks, Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days (+2 more)
26D ago
1 sources
A Microsoft Defender security flaw was exploited before a patch was available, and U.S. officials now say ransomware attackers used it in real intrusions. The bug, tracked as BlueHammer and CVE-2026-33825, is a local privilege-escalation flaw in Microsoft Defender; it was publicly disclosed on April 2, patched on April 14, added to CISA’s Known Exploited Vulnerabilities catalog on April 22, and CISA has now updated that entry to specify ransomware use. Huntress said it observed zero-day exploitation before Microsoft released fixes.
— Organizations using Windows systems with Microsoft Defender should treat this as a high-priority post-zero-day issue and verify patching immediately. The new ransomware tie raises the urgency because attackers used the flaw to gain higher privileges that can help them take over systems and deploy follow-on malware.
Sources: BlueHammer Vulnerability Exploited in Ransomware Attacks
1M ago
4 sources
Researchers say a newly identified backdoor called Mistic is being used to quietly keep access inside company networks in attacks tied to KongTuke, an initial access broker linked to ransomware groups. Symantec says Mistic has been used since April 2026 against organizations in insurance, education, IT, and professional services, including deployment after ModeloRAT in at least one case. The malware is side-loaded through MpExtMs.exe and a malicious version.dll, can run payloads in memory, steal credentials via a fake login prompt, and receive commands from attacker-controlled servers; Zscaler says it also appeared in a multi-stage ClickFix infection chain and can load Beacon Object Files for in-memory post-exploitation.
— Organizations in the named sectors may be facing a low-visibility foothold used to prepare ransomware attacks, not just one-off malware infections. Defenders should hunt for KongTuke and ClickFix activity, review Symantec and Zscaler indicators, and watch for suspicious DLL side-loading, fake login prompts, and Microsoft Teams-based social engineering.
Sources: Stealthy Mistic backdoor linked to ransomware access broker KongTuke, New ‘Mistic’ RAT Opens Door to Several Ransomware Families, New Mistic Backdoor Linked to KongTuke in ClickFix and ModeloRAT Campaigns (+1 more)
1M ago
1 sources
Attackers used a fake Microsoft Edge update process to trick employees into installing a malicious browser extension that helped deploy malware on their computers. Zscaler says the 'Edgecution' campaign starts with Microsoft Teams messages from fake IT support and uses Chrome Native Messaging in Microsoft Edge to let the extension communicate with a local Python-based backdoor outside the browser sandbox. The activity is linked by tactics and infrastructure patterns to an initial access broker associated with the Payouts Kings ransomware operation.
— This matters because it turns a browser extension into a bridge for full system compromise, not just in-browser abuse, and it is being used in real ransomware-linked intrusions. Organizations should warn users about fake IT support messages, restrict extension installs, and monitor or lock down Native Messaging host configurations on managed endpoints.
Sources: Malicious Edge extension abuses Native Messaging as bridge to malware
1M ago
1 sources
Indian vehicle maker Bajaj Auto disclosed that a ransomware attack hit its operations and also affected Bajaj Auto Technology Limited. In a regulatory filing, the company said it detected the incident on June 24, 2026, took containment steps, and brought in cybersecurity experts; it has not yet named the threat actor, said whether data was stolen, or disclosed any ransom demand.
— This is a live disruption at one of India’s largest manufacturers, so suppliers, employees, and customers may face operational delays while the scope is still unclear. Manufacturers and partners should watch for follow-up notices, be alert for extortion or phishing tied to the incident, and review exposure if they connect systems or data with Bajaj Auto.
Sources: Indian auto giant Bajaj Auto hit by ransomware incident
1M ago
1 sources
Researchers say a new ransomware group called Prinz Eugen is breaking into organizations and encrypting their newest or most recently changed files first to increase pressure to pay. ThreatDown says the operators appear to use stolen Remote Desktop Protocol (RDP) credentials, legitimate remote monitoring and management tools such as RemotePC, and hands-on-keyboard activity. The Go-based encryptor uses ChaCha20-Poly1305, appends a .prinzeugen extension, may delete originals after verifying decryption works, and currently shows at least several known victims, including a reported Standard Bank incident.
— Organizations with exposed or weakly protected remote access are at risk, especially if attackers can reuse stolen credentials and blend in with legitimate admin tools. Defenders should review RDP exposure, audit remote-management tool use, hunt for the listed indicators of compromise, and watch for unusual admin account creation.
Sources: New Prinz Eugen ransomware prioritizes recent files for encryption
1M ago
2 sources
A new report identifies a suspected real-world operator behind The Gentlemen, one of 2026's most active ransomware groups. KrebsOnSecurity, drawing on Check Point, Intel 471, Flashpoint, and Constella data, says the ransomware-as-a-service group has claimed at least 332 victims since mid-2025 and more than 240 in 2026, recruits affiliates with a 90/10 ransom split, and commonly gains entry through internet-facing VPN and firewall devices before rapidly encrypting networks.
— This is a major ransomware actor by victim volume, so the attribution and tradecraft details help defenders prioritize monitoring of exposed remote-access and edge devices. Organizations should review exposure of VPNs and firewalls, harden remote access, and watch for intrusion patterns associated with fast-moving affiliate-led ransomware attacks.
Sources: Who Runs the Ransomware Group ‘The Gentlemen?’, Gentlemen ransomware uses multiple EDR killers to disable defenses
1M ago
4 sources
A cyberattack forced Mackay Sugar, one of Australia's largest sugar producers, to shut down two mills in Queensland and stop sugarcane harvesting in the Mackay region. The company said the incident affected parts of its operations and that cybersecurity experts and authorities are investigating while systems are restored. No ransomware claim, data-theft disclosure, or technical details about the intrusion method have been confirmed yet.
— This is a real-world operational technology and business disruption incident affecting food production and local growers, not just office IT. Organizations in agriculture and other industrial sectors should review incident response plans, segmentation between business and plant systems, and contingency procedures for outages.
Sources: Cyberattack shuts down major Australian sugar mills, disrupting harvest, Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer, Cyberattack sees crops kept in the ground (+1 more)
1M ago
4 sources
DragonForce ransomware operators used Microsoft Teams network relays to disguise malware communications during an attack on a major U.S. services company. Symantec says the attackers deployed a custom Go-based backdoor called Backdoor.Turn that abused Teams' TURN relays (servers that help route traffic when direct connections fail) to mask command-and-control traffic as Microsoft activity. The December 2025 intrusion also used bring-your-own-vulnerable-driver tactics, including HWAuidoOs2Ec.sys, wsftprm.sys (CVE-2023-52271), GameDriverx64.sys (CVE-2025-61155), and K7RKScan.sys (CVE-2025-1055), before data theft and ransomware deployment.
— This matters because defenders may see the malware's traffic as legitimate Microsoft Teams activity, making detection and blocking harder during a ransomware attack. Organizations should review Microsoft Teams-related network trust assumptions, hunt for the listed indicators, and prioritize controls against driver-based security-tool tampering and suspicious use of SQL/MSSQL servers.
Sources: Ransomware gang abuses Microsoft Teams relays to hide malicious traffic, Crooks found a new way to collaborate using Teams – by hiding command-and-control traffic, Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack (+1 more)
1M ago
2 sources
A Ukrainian national has pleaded guilty in the United States for helping carry out Conti ransomware attacks that hit victims in the U.S. and other countries. The Justice Department said Oleksii Lytvynenko admitted joining the Conti conspiracy in 2021, possessing data stolen from 12 victims, and helping code a loader, malware used to install tools needed for ransomware intrusions. Prosecutors say Conti targeted more than 1,000 victims worldwide and collected over $150 million before the group fragmented in 2022.
— This matters because Conti was one of the most damaging ransomware groups of its era, and the case adds concrete attribution and operational detail defenders can use to understand how these attacks were carried out. It also shows continued law-enforcement pressure on the people behind major ransomware campaigns and their successor groups.
Sources: Ukrainian national pleads guilty to role in Conti ransomware operation, Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges
1M ago
2 sources
Authorities say they shut down AudiA6, a cryptocurrency laundering service allegedly used by ransomware groups and other cybercriminals to wash more than $380 million. Europol said the operation was linked to more than 15 ransomware and large-scale crypto-theft investigations, while arrests in Georgia and earlier evidence from a 2025 arrest in Poland helped identify administrators, seize 25 domains, freeze cryptocurrency, and recover about 6,000 know-your-customer identity records tied to mule accounts.
— This matters because ransomware profits only scale when criminals can cash out, and AudiA6 allegedly served as a central laundering hub for that process. Crypto platforms, investigators, and organizations tracking extortion activity should watch for related wallet exposure and mule-account abuse, while victims may gain new leads tying attacks to payment flows.
Sources: Authorities dismantle 'AudiA6' ransomware crypto-laundering service, In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine
1M ago
5 sources
Check Point says attackers used a zero-day flaw to break into some of its VPN systems, and at least one confirmed follow-on intrusion was linked to the Qilin ransomware operation. The main issue, CVE-2026-50751, is an unauthenticated authentication-bypass bug affecting Remote Access VPN, Mobile Access / SSL VPN, and Spark gateways when configured with deprecated IKEv1, legacy clients, and no mandatory machine certificate; Check Point also disclosed CVE-2026-50752, an IKEv1 certificate-validation flaw that could enable man-in-the-middle attacks on site-to-site VPNs. Exploitation began May 7 and has hit a few dozen organizations globally.
— Organizations using affected Check Point VPN setups could be exposed to break-ins without valid credentials, with ransomware risk if attackers get in. This is urgent: apply Check Point's updates immediately or disable IKEv1, require machine certificates, and follow the vendor's mitigations.
Sources: Check Point links VPN zero-day attacks to Qilin ransomware gang, Ransomware crims got a month-long head start on Check Point VPN 0-day that now has a fix, CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day (+2 more)
1M ago
1 sources
Mid and South Essex NHS Foundation Trust says the 2024 Qilin ransomware attack on pathology provider Synnovis exposed about 2,380 records tied to specialist diagnostic testing, and the total may rise as records are matched to individual patients. The incident is the same long-running data theft and service-disruption event that hit NHS pathology services in southeast London on June 3, 2024; patient data was later published after failed extortion, and affected trusts are still identifying who must be notified.
— This shows the fallout from a major healthcare ransomware breach is still growing years later, with more patients and hospitals discovering exposed records. Affected NHS organizations need to keep tracing exposed data and notifying people, while patients contacted about past diagnostic testing should treat breach notices seriously and watch for scams or misuse of their information.
Sources: Qilin NHS breach tally grows as Essex trust confirms stolen records
1M ago
1 sources
A ransomware attack forced Evanston Township High School in Illinois to close for at least two days, canceling summer school, sports camps, and other on-campus activities. The school said phone systems are down and staff have limited access to email, Google accounts, and other network systems including eSchool. External forensics specialists and breach counsel were engaged, and the FBI is involved. No ransomware group has publicly claimed responsibility yet.
— This is a real-world operational disruption affecting students, families, and staff, not just an IT outage. Schools and local governments should review incident response readiness, offline recovery options, and communications plans, while affected families should watch for follow-up notices about any data exposure.
Sources: Ransomware sends Illinois high school on an early summer vacation
1M ago
7 sources
The FBI says Silent Ransom Group is targeting U.S. law firms by pretending to be IT support, then stealing data and extorting victims without encrypting files. In 2026 attacks, the group reportedly used callback phishing emails, phone-based social engineering, remote desktop access, and in some cases sent an operative on site to insert a USB or external drive after a failed remote-access attempt; the attackers then used tools such as WinSCP and Rclone to exfiltrate data.
— Law firms and other organizations should treat unsolicited IT calls, emails, and in-person support visits as potential attack vectors, not just remote phishing. The warning is urgent because the attackers use legitimate admin tools and leave few traces, so organizations should verify IT identities, restrict external-drive use, and harden remote-access workflows now.
Sources: FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data, FBI warns of in-person data theft attacks from extortion gang, FBI warns extortion hackers are visiting US law firms to steal data (+4 more)
1M ago
2 sources
Sophos says it found a ransomware attack toolkit in a customer environment that was built with help from AI coding agents and used to hide from security software and map a victim's Windows network. The framework included Cobalt Strike traffic-masking profiles, Telegram-based command and control, a Cloudflare Worker redirector, and Python tools that generated Rust and Go payloads for evasion and execution. Sophos found operator logs referencing a ransom note and organizations listed on a ransomware leak site, indicating criminal use rather than legitimate red-team testing.
— This shows AI tools are being used to speed up real ransomware tradecraft, especially defense evasion and internal network discovery. Defenders should review detections for Telegram and Cloudflare-backed command channels, unusual payload loaders, and suspicious Active Directory reconnaissance, and treat AI-assisted malware development as an operational threat rather than a theory.
Sources: AI-built ransomware toolkit automates EDR evasion, AD discovery, In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief Eyed for CISA
1M ago
1 sources
The U.S. sanctioned Nobitex, Iran’s largest cryptocurrency exchange, saying it helped process transactions tied to ransomware actors and Iran’s Islamic Revolutionary Guard Corps. The Treasury’s Office of Foreign Assets Control also designated Nobitex executives and targeted other Iranian exchanges including Wallex, Bitpin, and Ramzinex as part of its "Economic Fury" campaign, alleging sanctions evasion and terrorist-financing support rather than a software flaw or CVE-tracked vulnerability.
— This matters because ransomware groups and state-linked actors depend on payment channels to move money, and sanctions can disrupt those routes while raising compliance risk for exchanges, companies, and users who interact with them. Organizations handling crypto exposure should review sanctions screening and watch for links to designated wallets and entities.
Sources: The U.S. sanctions Nobitex crypto exchange used by ransomware
1M ago
1 sources
IMA Diligence Services says attackers stole sensitive personal data from a legacy server managed by a third party, affecting 525,306 people. The company says the intruders accessed the server between December 8 and December 16 and exfiltrated files containing names, addresses, Social Security numbers, driver's license numbers, financial account and credit card data, medical and health insurance information, and in some cases passport and taxpayer ID numbers. SecurityWeek says the Genesis ransomware group previously claimed the attack and said it stole 700 GB of data.
— This is a high-impact breach because it exposed the kinds of data that can be used for identity theft, fraud, and medical or financial scams. Affected people should watch for the company's notice, enroll in credit monitoring, and consider fraud alerts or account monitoring, while defenders should review third-party legacy systems and data-retention exposure.
Sources: IMA Diligence Services Data Breach Impacts 525,000 People
2M ago
1 sources
Play ransomware operators have posted MyPillow to their leak site, claiming they stole sensitive internal data and will publish it if the company does not pay. According to the gang’s dark-web extortion post, the alleged haul includes personal and confidential data, client documents, budgets, payroll records, IDs, tax files, and finance information. The article does not provide technical details on the intrusion method, affected systems, or data volume, and MyPillow had not confirmed the breach at publication time.
— If the claim is accurate, employees, customers, and business partners could face privacy risks, fraud, or follow-on phishing using stolen records. Defenders should watch for confirmation, review for signs of Play ransomware activity, and prepare incident-response, notification, and credential-reset steps if exposure is verified.
Sources: MyPillow must decide whether to be firm or soft as ransomware crims demand pay
2M ago
1 sources
ReliaQuest and SonicWall say attackers exploited CVE-2024-12802 on SonicWall Gen6 SSL-VPN appliances to bypass MFA when admins installed patched firmware but did not complete required LDAP reconfiguration steps. Intrusions observed from February to March involved brute-forced credentials, internal reconnaissance, RDP access, and attempted deployment of Cobalt Strike and a BYOVD tool across multiple sectors and geographies.
— Organizations using SonicWall Gen6 SSL-VPN may still be exposed even if they believe they are patched, because firmware updates alone do not fully mitigate the flaw. Defenders should verify the manual remediation, hunt for listed indicators, and treat exposed Gen6 devices as potentially compromised.
Sources: Hackers bypass SonicWall VPN MFA due to incomplete patching
2M ago
1 sources
Microsoft said it seized domains and hundreds of VMs tied to Fox Tempest, a criminal service that abused Microsoft Artifact Signing using more than 580 fraudulent accounts created with fake identities. The operation allegedly sold code-signing certificates used to sign malware including Oyster, Lumma, Vidar, and Rhysida, and was linked to ransomware actors including Vanilla Tempest as well as INC, Qilin, and Akira affiliates.
— Trusted code-signing helps malware bypass user suspicion and some security controls, so this service likely enabled broader, more effective intrusions. Defenders should review detections and hunting for suspicious signed binaries and malware families named by Microsoft.
Sources: Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware