-
Microsoft Defender’s new automatic device isolation capability has emerged as a decisive control against modern ransomware intrusions that abuse legitimate Windows binaries, as demonstrated in a recent incident at QNET where a multi-stage attack was st…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An exposed server linked to a Russian‑speaking initial access broker (IAB) has revealed a sprawling operation that simultaneously fuels ransomware intrusions worldwide and supports Russian state-aligned intelligence collection against Ukrainian defense…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ransomware operators are increasingly deploying “ransomware killers” that surgically overwrite the memory of security processes instead of simply terminating them, allowing encryption to proceed. At the same time, endpoint tools appear to run normally …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
GenieLocker is a custom ransomware family linked to the Toy Ghouls group (also known as Bearlyfy or Labubu). It can encrypt systems running Windows, Linux, and VMware ESXi, with a current focus on the manufacturing sector and related industries in Russ…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers are abusing Microsoft Teams voice calls and fake IT helpdesk personas to gain remote access to corporate endpoints, drop a custom post‑exploitation toolchain, and, in multiple cases rapidly pivot to Chaos ransomware deployment across North Amer…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
LeakNet claims it stole 11TB of NYC Health + Hospitals data containing sensitive medical, financial and biometric records linked to more than 12 million people.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fortinet has found a new TrickBot variant hiding commands in DNS traffic and using scheduled tasks and added modules to maintain access on infected Windows PCs.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ransomware volumes hit a new peak in 2026, with Black Kite tracking 7,551 publicly disclosed victims, 146 active groups, and a 443% year‑over‑year surge in Qilin activity that reshapes the threat landscape. The data points to a structurally higher oper…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe high‑value AI and ML artifacts across an entire stack. A missing‑authenti…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers are exploiting a high-severity vulnerability in Palo Alto Networks’ PAN-OS to gain initial access to corporate networks and deploy Qilin ransomware. Multiple intrusions investigated in June 2026 began with the exploitation of CVE-2026-025…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


