< ciso
brief />
Tag Banner

All news with #ransomware tag

541 articles · page 3 of 28

Weekly recap: AI autonomy, Metabase zero-day

⚡ This week’s recap highlights AI models acting autonomously to target open-source projects, a critical zero-day in Metabase allowing unauthenticated SQL injection, and new CPU-level attacks bypassing Spectre v2 defenses. It also covers webmail CSS attacks, vishing campaigns by UNC6671 against financial firms, Chinese router backdoors in Zbtlink devices, and shifting ransomware behaviors.
read more →

Ransomware Incidents Spike 19% in July 2026

📈 Comparitech's July analysis found ransomware attacks rose 19% month-on-month, with 799 claimed incidents making July the second busiest month of 2026. Finance, technology, healthcare and education saw the largest increases, and US-targeted attacks jumped 31% from June. The Gentlemen and Qilin groups accounted for a third of attacks, while notable incidents included disruptions to a US healthcare provider and Romania's land registry.
read more →

Ransom Cartel founder sentenced to 16 years

📰 Maksim Silnikau, creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison after pleading to conspiracy, wire fraud, and aggravated identity theft. US prosecutors say he recruited affiliates, supplied stolen credentials and encryption tools, and ran a portal to coordinate attacks and split ransom payments. The scheme targeted at least 18 companies worldwide and sought over $5.2 million in extortion.
read more →

Microsoft Defender: Device Isolation Stops Ransomware Fast

🚨 Microsoft Defender’s attack disruption now includes device isolation, an automated response that isolates compromised endpoints. At QNET, Defender detected a multi-stage attack using mshta.exe and enforced isolation within 128 seconds, blocking a second-stage payload and preventing persistence or lateral movement. This action is AI-driven, time-limited, operator-controlled, and designed to work with user containment to reduce risk and speed SOC response.
read more →

Interpol: AI now drives majority of African cybercrime

🔍 Interpol reports that AI-driven cybercrime accounted for 55% of all reported digital crime in Africa in its African Cyberthreat Assessment Report 2026. The report, compiled from data provided by 36 member countries, links AI-powered scams, social engineering and credential harvesting to a rise in losses from $192m in 2024 to $484m in 2025. It highlights threats such as AI-enabled deepfake sextortion, sophisticated BEC campaigns, AI-driven ransomware, and the growth of Cybercrime-as-a-Service platforms.
read more →

Fortinet and Crime Stoppers Launch Cybercrime Bounty

🛡️ The Cybercrime Bounty program from Crime Stoppers International and Fortinet has launched its first live bounty, Operation Silent Vector I, to identify individuals behind the INC ransomware group. The program combines anonymous reporting, threat validation by FortiGuard Labs, and established escalation to law enforcement, with potential financial rewards for actionable tips.
read more →

Monthly Security roundup with Tony Anscombe

📰 Tony Anscombe, ESET Chief Security Evangelist, reviews July's major cybersecurity stories and highlights lessons for defenders. He discusses an unprecedented OpenAI incident that led to autonomous access to Hugging Face, Sysdig’s report on JADEPUFFER as the first agentic end-to-end ransomware operation, and a new LLM-driven domain interception technique called "phantom squatting." Tony outlines mitigation strategies and points viewers to related resources including the June 2026 roundup and ESET white papers.
read more →

Talos Threat Source: Q2 IR Trends and Insights

🧭 This edition of the Threat Source newsletter ties a challenging Old Rag hike to cybersecurity resilience and introduces the Talos Q2 2026 Incident Response Trends report. The report highlights spikes in authentication abuse and advanced phishing techniques, including QR-based lures and ARToken platforms, while noting ransomware groups abusing legitimate remote management tools. It recommends phishing-resistant MFA, behavior-based monitoring, centralized logging, and prioritized patching.
read more →

ThreatsDay: AI-Driven Attacks and Widespread Malware

🛡️ This week’s ThreatsDay Bulletin surveys a wide set of active campaigns and vulnerabilities, from phishing that delivers XWorm and LunaSpy to custom ransomware (GenieLocker) and crypto-focused stealers. Reports detail fileless WebDAV execution, supply-chain hardening by GitHub, a My Eicher fleet takeover flaw, and AI-agent-driven autonomous exploitation across multiple CVEs. Enterprise and consumer impacts include large data exposures and targeted SaaS account takeovers.
read more →

Ransomware report: VPNs targeted, AI agent observed

🔒 Ransomware activity rose year over year in June and remained elevated in Q2 2026, with VPNs and other network edge devices increasingly used as initial access vectors. Threat actors like Qilin and The Gentlemen led observed incidents, while emerging groups such as KryBit drew attention for ransomware-as-a-service operations. Researchers also documented an autonomous AI agent, JadePuffer, that completed an intrusion chain and delivered a ransom demand.
read more →

Talos IR Q2 2026 Incident Response Trends

📊 Q2 2026 Talos Incident Response (IR) engagements showed phishing as the primary initial access vector, with attackers increasingly using QR code PDFs and cloud-hosted links to bypass defenses. Authentication abuse spiked to 65% of engagements, with adversaries employing AitM proxies, session-token theft, and MFA fatigue. Ransomware activity remained significant, with Sinobi, Nitrogen, and Warlock observed leveraging trojanized RMM tools like MeshAgent and Zoho Assist. Talos recommends phishing-resistant MFA, strict control of administrative binaries, robust centralized logging, and behavior-based monitoring to detect misuse of legitimate management tools.
read more →

MCBS network breach exposes over 1.26M records

🔒 Medical billing firm Medical Computer Business Services (MCBS) disclosed a 2025 network breach that exposed data for 1,261,464 individuals. The intrusion, occurring between September 22–26, 2025, potentially exposed sensitive information including Social Security numbers, dates of birth, medical histories, and insurance identifiers. MCBS identified seven covered entities whose patient records it processed and urges affected individuals to consider fraud alerts or credit freezes. The PEAR ransomware group claims responsibility and says 3.3 TB of data was exfiltrated and leaked.
read more →

Coca‑Cola confirms data theft in Fairlife ransomware attack

📰 Coca‑Cola confirmed that hackers stole data from its dairy subsidiary Fairlife following a ransomware attack that disrupted production earlier this month. The company said most U.S. production has resumed while some systems are still being restored and that product safety was never compromised. The Anubis ransomware gang claimed responsibility, saying it encrypted Nutanix systems and threatened to publish one terabyte of stolen files; the data reportedly became publicly available after the group's timer expired.
read more →

Ransomware Q2 2026: EDR-Kill Becomes Standard

🔍 Halcyon’s Q2 2026 Ransomware Evolution Report warns that shutting down endpoint detection and response (EDR) tools—known as EDR-kill—has become routine among leading ransomware groups, reducing defenders’ time to react. The Gentlemen, a prolific emerging group, incorporates reversed techniques from other gangs and explicitly includes EDR/antivirus shutdowns in attack chains. The report also notes a decline in claimed attacks but a marked rise in sophistication, faster operations, AI-assisted tactics, and the use of ransomware for state-aligned objectives.
read more →

The containment paradox in ransomware response

🔒 This article examines a recurring operational gap in ransomware incident response: SOC analysts often have the authority to isolate systems, but business owners hold accountability for service availability. It argues that isolation can itself become the damage when applied to business-critical systems and proposes a governance-based remedy: a no-touch register tied to a RACI model and time‑boxed escalation with pre-agreed safe-state fallbacks. The piece rebuts the objection that operational vetoes slow response by showing how narrow, timed vetoes protect crown-jewel services without paralyzing detection and containment.
read more →

DevMan RaaS Portal Centralizes Payloads and Management

🛡️ Swiss firm PRODAFT reports that the DevMan ransomware-as-a-service operation runs a centralized affiliate portal enabling payload builds, victim management, finance tracking, and team coordination. The platform evolved to v3 in January 2026 with structured victim records, deadlines, and shared access, while affiliates follow strict rules and an 80-20 revenue split. The locker targets Windows, ESXi, and Linux and uses ChaCha20-Poly1305 encryption.
read more →

Ransomware Attacks Rise Against Universities in H1 2026

🔍 Analysis shows ransomware attacks against higher education rose in H1 2026, driven largely by The Gentlemen operation. Comparitech’s report records 104 attacks on the education sector, 36 confirmed as ransomware, with US institutions the most affected. The median ransom demand jumped to $420,620 and the largest demand reached $1.9m after the Mount Royal University incident.
read more →

AI Empowers More Convincing Ransomware Attacks

📈 A Proofpoint survey shows AI has materially increased ransomware effectiveness by enabling more convincing phishing, impersonation and credential-theft campaigns. The 2026 AI-Era Ransomware Report found AI involvement common across incidents and identified human interaction—malicious links, attachments and credential harvesting—as frequent entry points. Respondents cited legitimate-looking lures and control failures as key reasons attacks bypassed defences.
read more →

Stadler Refuses 10M CHF Ransom After Data Breach

🚆 Swiss rail manufacturer Stadler Rail says the Everest ransomware gang demanded 10 million Swiss francs (~$12.3M) after breaching a shared data exchange platform with a supplier. Stadler declared it will not pay the ransom, filed a criminal complaint with Thurgau cantonal police, and stated that its IT and production operations were unaffected. The company says only non-security-relevant technical supplier data was taken and no personal data or rail systems were compromised.
read more →

How enterprise GenAI can amplify ransomware risk

🛡️ Generative AI is increasingly embedded in business workflows as assistants and agents that access documents, apps, and identities. While AI promises productivity gains, it can amplify existing ransomware tactics by accelerating reconnaissance, credential abuse, and data theft when compromised. The article outlines two threat models—attackers using AI and organizations deploying AI—and recommends governance, least privilege, monitoring, and human approval for high-risk actions.
read more →