Tag: ransomware
-
Ransomware Is Accelerating, But It’s Not Because of AI
Researchers pointed to fragmentation of the ransomware ecosystem, the emergence of new attackers, and expansion of attacks on less defended organizations. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ransomware-is-accelerating-not-ai
-
Services Firm ApolloMD Settles Hack Lawsuit for $4M
Settlement With Revenue Cycle Vendor Stems From Qilin Gang Attack Affecting 627,000. Revenue cycle management services firm ApolloMD Business Services has agreed to pay just over $4 million to settle proposed class action litigation stemming from a 2025 data theft claimed by ransomware gang Qilin that affected nearly a dozen physician practices and 627,000 of…
-
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola’s Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak/
-
Ransomware victims fail to fix flaws that exposed them
Many organizations still aren’t securing their email or patching vulnerabilities after recovering from attacks, a new report found. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ransomware-lingering-weaknesses-black-kite/825791/
-
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and…
-
JadePuffer returns with ransomware built to target AI models and infrastructure
JadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/21/jadepuffer-encforge-ransomware/
-
Forescout Report Reveals Surge in AI-Driven Cyber Threats
The Forescout 2026 H1 Threat Review found that more than 37,000 vulnerabilities were published during the first six months of the year, representing a 51% increase year on year. More than half were classified as high or critical severity, while ransomware attack claims rose by 25% to 4,544 incidents, averaging 25 attacks every day. The…
-
A New Ransomware Threat Actor Emerges Every Week, Warns Report
Analysis by Black Kite warns that ransomware ecosystem is becoming bigger and more fragmented First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/new-ransomware-weekly/
-
2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge
Ransomware volumes hit a new peak in 2026, with Black Kite tracking 7,551 publicly disclosed victims, 146 active groups, and a 443% year”‘over”‘year surge in Qilin activity that reshapes the threat landscape. The data points to a structurally higher operating tempo, a middle”‘market pivot, and attacker visibility that often outpaces defenders’ own understanding of their…
-
JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data
JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe high”‘value AI and ML artifacts across an entire stack. A missing”‘authentication bug in the /api/v1/validate/code endpoint that enables unauthenticated arbitrary Python execution on the host. That initial operation chained reconnaissance, credential…
-
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims’ networks, according to cybersecurity company Arctic Wolf. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/
-
Ransomware trifft die Produktion über IT- und OT-nahe Systeme
Wenn von Cyberangriffen auf Industrieunternehmen die Rede ist, denken viele zunächst an manipulierte Maschinen oder kompromittierte Steuerungssysteme. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ransomware-produktion-ot-systeme
-
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month.The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem.The…
-
Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware
Tags: access, attack, authentication, corporate, cve, cyber, encryption, exploit, flaw, hacker, network, ransomware, vpn, vulnerabilityHackers are exploiting a high-severity vulnerability in Palo Alto Networks’ PAN-OS to gain initial access to corporate networks and deploy Qilin ransomware. Multiple intrusions investigated in June 2026 began with the exploitation of CVE-2026-0257, an authentication bypass flaw affecting GlobalProtect portal and gateway deployments. The attacks evolved from external VPN compromises to domain-wide encryption, with…
-
JadePuffer agentic attacks now target AI model data with ransomware
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware/
-
Cosmetics giant Estée Lauder victim of mass Oracle breach
Employee data at US-based cosmetics firm Estée Lauder was compromised through a vulnerability in Oracle’s software, likely orchestrated by the Cl0p ransomware gang. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645849/Cosmetics-giant-Estee-Lauder-victim-of-mass-Oracle-breach
-
Pay up or not? Ransomware surge has victims facing tough choices.
Governments look at banning ransom payments in face of increasingly sophisticated threats. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/pay-up-or-not-ransomware-surge-has-victims-facing-tough-choices/
-
Researchers trace SonicWall SMA1000 exploitation to late June
Multiple threat actors, including INC ransomware, have targeted vulnerable firewall systems. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/researchers-sonicwall-sma1000-exploitation-june/825654/
-
Pay up or not? Ransomware surge has victims facing tough choices
Governments look at banning ransom payments in face of increasingly sophisticated threats. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/pay-up-or-not-ransomware-surge-has-victims-facing-tough-choices/
-
JadePuffer Returns With Ransomware Designed to Wipe AI Models
JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/jadepuffer-ai-model-ransomware/
-
182 Ransomware-Opfer in Deutschland bis Mai 2026 – Infostealer-Malware wird zum Einfallstor für Ransomware
First seen on security-insider.de Jump to article: www.security-insider.de/ransomware-2026-deutschland-opferzahlen-qilin-a-1bdee414e150bd5596d138cb26edb042/
-
Lawyers say Russian tourist detained in Armenia over mistaken identity in ransomware case
First seen on scworld.com Jump to article: www.scworld.com/brief/russian-tourist-detained-in-armenia-over-mistaken-identity-in-us-extradition-request
-
Inc Ransomware Exploits SonicWall SMA Zero-Days
When chained together, the two vulnerabilities allow threat actors to gain root-level capabilities on SonicWall’s mobile access appliances. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days
-
Ransomware attack forces Coca-Cola to suspend US production at dairy unit
The beverage company is still working to determine the full scope of the breach at its Fairlife business. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ransomware-attack-coca-cola-suspend-production-dairy/825540/
-
Government Agencies Falling Victim to Ransomware Daily, Warns Study
Government organizations are targeted by attackers who know agencies cannot afford disruption to public services First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/government-ransomware-daily/
-
Spirals ransomware locks down victim systems in under 24 hours
A previously unknown ransomware strain called Spirals was used last month in an attack against an IT services company in South Asia, where attackers went from initial access … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/17/spirals-ransomware-south-asia/
-
Hackers Breached an IIS Server and Deployed Ransomware Across the Network the Next Day
Hackers leveraged a compromised Microsoft IIS server to gain initial access and deploy a previously unseen ransomware payload across an enterprise network within 24 hours, highlighting a highly coordinated and operationally mature intrusion chain observed in June 2026. The campaign reflects a fast-paced, hands-on-keyboard intrusion combined with automated lateral movement, signaling a threat actor capable…
-
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
Armenia has held a Russian tourist named Aleksandr Ermakov in a detention center since June 28, on a U.S. extradition request for a REvil ransomware suspect named Aleksandr Ermakov.His wife, Maria Yurova, told REN TV that border officers pulled him out of the departure hall at Yerevan’s Zvartnots airport, held up a phone with a…
-
The Gentlemen Overtakes Qilin as Most Prolific Ransomware Threat
Analysis of ransomware incidents by ReliaQuest indicates a shift in the ransomware landscape First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/the-gentlemen-most-prolific/

