< ciso
brief />
Tag Banner

All news with #ransomware tag

514 articles · page 2 of 26

Talos Threat Source: Q2 IR Trends and Insights

🧭 This edition of the Threat Source newsletter ties a challenging Old Rag hike to cybersecurity resilience and introduces the Talos Q2 2026 Incident Response Trends report. The report highlights spikes in authentication abuse and advanced phishing techniques, including QR-based lures and ARToken platforms, while noting ransomware groups abusing legitimate remote management tools. It recommends phishing-resistant MFA, behavior-based monitoring, centralized logging, and prioritized patching.
read more →

ThreatsDay: AI-Driven Attacks and Widespread Malware

🛡️ This week’s ThreatsDay Bulletin surveys a wide set of active campaigns and vulnerabilities, from phishing that delivers XWorm and LunaSpy to custom ransomware (GenieLocker) and crypto-focused stealers. Reports detail fileless WebDAV execution, supply-chain hardening by GitHub, a My Eicher fleet takeover flaw, and AI-agent-driven autonomous exploitation across multiple CVEs. Enterprise and consumer impacts include large data exposures and targeted SaaS account takeovers.
read more →

Ransomware report: VPNs targeted, AI agent observed

🔒 Ransomware activity rose year over year in June and remained elevated in Q2 2026, with VPNs and other network edge devices increasingly used as initial access vectors. Threat actors like Qilin and The Gentlemen led observed incidents, while emerging groups such as KryBit drew attention for ransomware-as-a-service operations. Researchers also documented an autonomous AI agent, JadePuffer, that completed an intrusion chain and delivered a ransom demand.
read more →

Talos IR Q2 2026 Incident Response Trends

📊 Q2 2026 Talos Incident Response (IR) engagements showed phishing as the primary initial access vector, with attackers increasingly using QR code PDFs and cloud-hosted links to bypass defenses. Authentication abuse spiked to 65% of engagements, with adversaries employing AitM proxies, session-token theft, and MFA fatigue. Ransomware activity remained significant, with Sinobi, Nitrogen, and Warlock observed leveraging trojanized RMM tools like MeshAgent and Zoho Assist. Talos recommends phishing-resistant MFA, strict control of administrative binaries, robust centralized logging, and behavior-based monitoring to detect misuse of legitimate management tools.
read more →

MCBS network breach exposes over 1.26M records

🔒 Medical billing firm Medical Computer Business Services (MCBS) disclosed a 2025 network breach that exposed data for 1,261,464 individuals. The intrusion, occurring between September 22–26, 2025, potentially exposed sensitive information including Social Security numbers, dates of birth, medical histories, and insurance identifiers. MCBS identified seven covered entities whose patient records it processed and urges affected individuals to consider fraud alerts or credit freezes. The PEAR ransomware group claims responsibility and says 3.3 TB of data was exfiltrated and leaked.
read more →

Coca‑Cola confirms data theft in Fairlife ransomware attack

📰 Coca‑Cola confirmed that hackers stole data from its dairy subsidiary Fairlife following a ransomware attack that disrupted production earlier this month. The company said most U.S. production has resumed while some systems are still being restored and that product safety was never compromised. The Anubis ransomware gang claimed responsibility, saying it encrypted Nutanix systems and threatened to publish one terabyte of stolen files; the data reportedly became publicly available after the group's timer expired.
read more →

Ransomware Q2 2026: EDR-Kill Becomes Standard

🔍 Halcyon’s Q2 2026 Ransomware Evolution Report warns that shutting down endpoint detection and response (EDR) tools—known as EDR-kill—has become routine among leading ransomware groups, reducing defenders’ time to react. The Gentlemen, a prolific emerging group, incorporates reversed techniques from other gangs and explicitly includes EDR/antivirus shutdowns in attack chains. The report also notes a decline in claimed attacks but a marked rise in sophistication, faster operations, AI-assisted tactics, and the use of ransomware for state-aligned objectives.
read more →

The containment paradox in ransomware response

🔒 This article examines a recurring operational gap in ransomware incident response: SOC analysts often have the authority to isolate systems, but business owners hold accountability for service availability. It argues that isolation can itself become the damage when applied to business-critical systems and proposes a governance-based remedy: a no-touch register tied to a RACI model and time‑boxed escalation with pre-agreed safe-state fallbacks. The piece rebuts the objection that operational vetoes slow response by showing how narrow, timed vetoes protect crown-jewel services without paralyzing detection and containment.
read more →

DevMan RaaS Portal Centralizes Payloads and Management

🛡️ Swiss firm PRODAFT reports that the DevMan ransomware-as-a-service operation runs a centralized affiliate portal enabling payload builds, victim management, finance tracking, and team coordination. The platform evolved to v3 in January 2026 with structured victim records, deadlines, and shared access, while affiliates follow strict rules and an 80-20 revenue split. The locker targets Windows, ESXi, and Linux and uses ChaCha20-Poly1305 encryption.
read more →

Ransomware Attacks Rise Against Universities in H1 2026

🔍 Analysis shows ransomware attacks against higher education rose in H1 2026, driven largely by The Gentlemen operation. Comparitech’s report records 104 attacks on the education sector, 36 confirmed as ransomware, with US institutions the most affected. The median ransom demand jumped to $420,620 and the largest demand reached $1.9m after the Mount Royal University incident.
read more →

AI Empowers More Convincing Ransomware Attacks

📈 A Proofpoint survey shows AI has materially increased ransomware effectiveness by enabling more convincing phishing, impersonation and credential-theft campaigns. The 2026 AI-Era Ransomware Report found AI involvement common across incidents and identified human interaction—malicious links, attachments and credential harvesting—as frequent entry points. Respondents cited legitimate-looking lures and control failures as key reasons attacks bypassed defences.
read more →

Stadler Refuses 10M CHF Ransom After Data Breach

🚆 Swiss rail manufacturer Stadler Rail says the Everest ransomware gang demanded 10 million Swiss francs (~$12.3M) after breaching a shared data exchange platform with a supplier. Stadler declared it will not pay the ransom, filed a criminal complaint with Thurgau cantonal police, and stated that its IT and production operations were unaffected. The company says only non-security-relevant technical supplier data was taken and no personal data or rail systems were compromised.
read more →

How enterprise GenAI can amplify ransomware risk

🛡️ Generative AI is increasingly embedded in business workflows as assistants and agents that access documents, apps, and identities. While AI promises productivity gains, it can amplify existing ransomware tactics by accelerating reconnaissance, credential abuse, and data theft when compromised. The article outlines two threat models—attackers using AI and organizations deploying AI—and recommends governance, least privilege, monitoring, and human approval for high-risk actions.
read more →

Anubis Claims Responsibility for Fairlife Cyberattack

🛡️ The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola's Fairlife dairy subsidiary, alleging it stole approximately 1 TB of corporate data and encrypted Nutanix systems. Coca-Cola disclosed the incident on July 16 after production at U.S. facilities was suspended; the company said product safety was unaffected and declined to comment on Anubis' claims. Anubis, a RaaS group active since December 2024, has combined data theft, encryption, and destructive wiping in prior attacks.
read more →

Ransomware Landscape Expands with New Groups Weekly

🛡️ The Black Kite Ransomware Report 2026 finds 146 active ransomware groups as of June 2026, up from 105 a year earlier, with 61 new groups emerging in 2026 alone. The study highlights a fragmented ecosystem where groups often have short lifespans—averaging 4.9 months—and a small number of operators still account for a large share of disclosed victims. Black Kite urges organizations to prioritize rapid patching of critical vulnerabilities and strengthen identity and vendor controls to mitigate attacks.
read more →

Critical GlobalProtect VPN Bug Now Used in Ransomware

🔒 Palo Alto Networks patched a critical PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) on May 13 after Rapid7 observed active exploitation from May 17. Arctic Wolf reports the Qilin ransomware gang is leveraging the flaw to gain unauthorized VPN access and deploy ransomware, with incidents in June resulting in domain-wide encryption. CISA added the vulnerability to its Known Exploited Vulnerability catalog and ordered federal agencies to remediate within three days.
read more →

Ransomware Now Disrupts a Government Every Day

🔒 Analysis from Comparitech finds ransomware attacks on government agencies rose in early 2026, averaging one incident per day. The study recorded 187 attacks from January to June 2026, a 13% increase from late 2025, with just over half publicly confirmed. The US was the most targeted country (31%), mean demands were around $100,000, and groups like The Gentlemen, Qilin and LockBit were prominent. Experts stress timely patching, backups and staff training to reduce risk.
read more →

The Gentlemen Tops Ransomware Incidents in Q2

🛡️ ReliaQuest's July analysis shows The Gentlemen ransomware gang conducted 300 attacks in the three-month period, surpassing Qilin's 289 incidents. Researchers tracked 1,368 victim claims across 99 countries from 11 ransomware groups, with DragonForce, Akira and LockBit also active. ReliaQuest attributes The Gentlemen's rise to aggressive affiliate recruitment, pre-packaged intrusion kits and AI-accelerated tooling.
read more →

Coca‑Cola reports Fairlife ransomware halts US production

📰 Coca‑Cola disclosed a ransomware incident affecting its Fairlife dairy subsidiary that led to temporary suspension of U.S. production. The company reported unauthorized access to production-related systems, activated incident response and engaged outside cybersecurity advisors while notifying law enforcement. Product safety remains unaffected and Canadian operations are not impacted. An investigation is ongoing and no claim of data theft or extortion has been confirmed.
read more →

Weekly roundup: emerging cyber threats and takedowns

🛡️ This week’s roundup highlights a wave of opportunistic attacks where familiar software and weak defaults are abused to escalate damage quickly. Reports include malicious NuGet packages that deliver spyware via game cheats, trojanized installers distributing sophisticated RATs, and a fast-spreading Rust ransomware incident that encrypted a network within 24 hours. Additional items cover actively exploited CVEs added to CISA’s KEV, guidance for coordinated vulnerability disclosure, large-scale fraud and money‑laundering disruptions in Europe, evasive Windows bind-link techniques, fake GitHub repos spreading an infostealer, and misuse of Chrome Sync for covert surveillance.
read more →