Ransomware
Ransomware attacks, extortion crews, and the intrusions that end in encryption. What happened, who is behind it, and how to cut off the path before the payload runs.
ShinyHunters beat MFA at ReliaQuest. Device trust stopped it.
ShinyHunters vished a ReliaQuest employee and got the MFA push approved, but device-trust rules blocked the theft.
A ransomware crew hijacked about 2,000 WordPress sites to spread its malware. Your site could be one of them.
Check Point unmasked StopAndProtect, a ransomware operation running on about 2,000 hacked WordPress sites.
CISA: Medusa ransomware has hit 500+ critical infrastructure orgs and weaponizes new bugs within a day
CISA and the FBI updated their Medusa ransomware advisory: 500+ critical infrastructure victims, and affiliates now weaponize new bugs within 24 hours.
Windows Task Host flaw CVE-2025-60710 gives a local user SYSTEM, and ransomware gangs now exploit it
CISA confirms ransomware crews are exploiting CVE-2025-60710, a Windows Task Host flaw that elevates a local user to SYSTEM on Windows 11 and Server 2025.
Akira ransomware reboots Windows into Safe Mode to shut off security tools
An Akira ransomware affiliate rebooted a Windows host into Safe Mode to disable EDR, stole the data, then fumbled the encryption.
Gunra ransomware beats MFA by backdooring the login server, not the user. Patching Fortinet won't evict it.
Gunra ransomware beats MFA by rewriting the login server so one chosen code always passes, after entering through Fortinet flaws.
Critical Commvault flaw lets attackers run blocked commands on the backup control server
Commvault patched CVE-2026-13737, a critical CVSS 9.2 allowlist bypass in CommServe that lets attackers run commands the backup control server should block.
China-linked Storm-1175 turns N-able N-central into a ransomware launchpad with new StormEncryptor
Microsoft ties China-linked Storm-1175 to StormEncryptor ransomware deployed through the N-able N-central auth bypass (CVE-2026-18577). Patch, then hunt.
A Palo Alto VPN auth bypass is now a Qilin ransomware front door
CVE-2026-0257 lets attackers open a Palo Alto GlobalProtect VPN session with no login, and the Qilin ransomware crew is using it for initial access.
Inc ransomware used the SonicWall SMA zero-days to steal MFA seeds. Resetting passwords will not evict it.
Rapid7 ties the SonicWall SMA 1000 zero-days to an Inc ransomware actor that stole credentials, sessions, and TOTP seeds. A password reset won't evict it.
GigaWiper fakes a ransomware hit to cover a disk wipe, and the only early warning is on the host
GigaWiper encrypts files to .candy with no key and no ransom note, because the ransomware is a decoy for a disk wipe. Here are the host signals that catch it.
Three ransomware responders secretly worked for BlackCat. Trust is the attack surface.
Three incident-response insiders at DigitalMint and Sygnia were sentenced for helping run BlackCat ransomware, one leaking victims' insurance limits.
GodDamn ransomware blinds EDR with a signed kernel driver. Detect the load, not the file.
GodDamn ransomware uses PoisonX, a kernel driver carrying a valid Microsoft signature, to disable EDR.
A low-privilege user could overreach on Dell's Data Domain backup appliances. The fix is out.
CVE-2026-56086 lets a low-privileged remote user gain unauthorized access on Dell PowerProtect Data Domain backup appliances. CVSS 8.8. Patched builds are out.
Kairos stole 2TB, encrypted nothing, and still got $1M. Watch the login, not the file locker.
Kairos stole 2TB from a US county, encrypted nothing, and was paid $1M. Encryptionless extortion breaks file-locker alarms. Detect the login and egress.
We said a password reset wouldn't stop FortiBleed. Now it is deploying ransomware.
FortiBleed harvested 110 million Fortinet credentials. SOCRadar links that access to INC and Lynx ransomware, with 12 encryptions and a Nextcloud zero-day.
A poisoned security scanner ran on your build server and walked out with your cloud keys
The FBI's TeamPCP FLASH alert shows why a trojanized scanner steals from your servers, not the registry, and why pinning packages will not save you.
Scattered Spider keeps winning because your help desk, not a CVE, is the way in
An extradited Scattered Spider suspect breached a retailer in under three hours through a help-desk password reset. Here is the identity control that stops it.
The first AI-run ransomware locked a database with a key it never saved
The first ransomware attack run end to end by an AI agent broke in through a year-old Langflow flaw and encrypted a database with a key it never saved.
Ransomware that runs inside your browser tab, where antivirus cannot see it
Check Point built browser-only ransomware from a DeepSeek AI output: a web page encrypts your files through a legitimate browser API, with no binary for
Mistic backdoor writes nothing to disk and quietly sells your network to ransomware crews
Mistic is an in-memory backdoor that access broker KongTuke uses to hold footholds and sell them to Qilin and other ransomware crews. Here is where to catch it.
Police seized the malware that stole 27 million passwords. The passwords still work.
Operation Endgame seized the servers behind the Amadey and StealC malware, but the 27 million credentials they already stole stay valid until you rotate them.
Prinz Eugen ransomware hits your newest files first and never leaves a note
Prinz Eugen ransomware encrypts your most recently changed files first and drops no ransom note, defeating canary traps and note-based SOC alerts. What to do.
EDR evasion is now a shipped product. Your agent's silence is the only alarm left.
The Gentlemen ransomware gang ships a standardized EDR killer to affiliates using BYOVD. Here is why driver-name hunting fails and what to detect instead.
DragonForce hides its C2 inside Microsoft Teams relays. Your network sensors see a clean call.
DragonForce's Backdoor.Turn routes C2 through Microsoft Teams TURN relays, so network sensors see only Microsoft.
INC ransomware never used a zero-day. It used your patch backlog.
INC reached top-tier RaaS in 2026 with no zero-days. Every edge-device flaw it exploits was patched months earlier. Here is what to actually fix.
PeopleSoft's PSEMHUB zero-day turns the patch service into the breach
CVE-2026-35273 sits in PeopleSoft's Updates Environment Management module. Mandiant ties active exploitation to ShinyHunters, with 100+ orgs already breached.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.