Skip to main content

Malware & Ransomware

Blurred computer screen amidst ordinary office equipment and decor suggests disruption.

Ransomware Attacks Exploited Compromised Identities in 79% of Incidents

Ransomware attacks are often sparked by something surprisingly simple: 79% of incidents start with compromised identities, highlighting the vulnerability of legitimate user logins and credentials. This means that in nearly 8 out of 10 cases, attackers gain a foothold using stolen or hijacked identities rather than complex hacking techniques.

Analyst 207
City street with busy storefronts and office buildings, hinting at disruption.

Ransomware Landscape Fractures as New Groups Proliferate

The ransomware landscape is shattering into more factions than ever, with over one new group emerging every week in 2026, according to the Black Kite Ransomware Report. This explosion of new players has led to a surge in attacks, with 61 new groups appearing in just one year alone.

Analyst 207
IT staff work in a network operations room with rows of equipment and technology.

Qilin Ransomware Gang Exploits Palo Alto VPN Bug in Ongoing Attacks

The Qilin ransomware gang is actively exploiting a critical vulnerability in Palo Alto Networks' VPN software, CVE-2026-0257, to breach security and launch attacks, despite a patch being released on May 13. This alarming development follows reports of multiple intrusions by Qilin in June, highlighting the urgent need for updates.

Analyst 207
Laptop screen displays a website's content management system dashboard on a plain surface with blurred code in the…

WordPress Exploitation Surges as Public Exploit Fuels Remote Code Execution

A surge in WordPress exploitations is underway as hackers leverage a public exploit to enable remote code execution on vulnerable sites, posing a threat to organizations of all sizes and industries. The flaw, dubbed "wp2shell," allows unauthenticated attacks on default WordPress installations, sparking widespread scanning and compromise.

Analyst 207
Cluttered tech lab with AI equipment, laptop screen shows AI model file access.

ENCFORGE Ransomware Targets AI Model Files in Langflow Attack

A new ransomware called ENCFORGE is targeting AI model files, exploiting a high-severity flaw in Langflow to deploy a custom-built payload that threatens machine learning systems. This highly specialized attack focuses on encrypting critical AI data, including PyTorch, TensorFlow, and Hugging Face files.

Analyst 207
Rack-mounted SonicWall SMA1000 appliance in a network operations setting.

SonicWall VPN flaws exploited to install custom malware

A threat actor known as UTA0533 has been exploiting two zero-day vulnerabilities in SonicWall SMA1000 Secure Mobile Access appliances to install custom malware, starting as early as June 22, 2026. This attack uses a critical server-side request forgery and a high-severity command injection vulnerability to gain unauthorized access.

Analyst 207
WordPress dashboard on a laptop screen in a modern office setting with a blurred cityscape background.

WordPress Exploits Spread as Attackers Chain Critical Vulnerabilities

Within hours of public disclosure, hackers leveraged AI models to exploit two critical WordPress vulnerabilities, CVE-2026-60137 and CVE-2026-63030, that when combined enable unauthenticated remote code execution. This potent pairing allows attackers to wreak havoc on websites, highlighting the urgent need for updates.

Analyst 207
Rows of servers and storage units in a brightly-lit data center with cables and network equipment.

JadePuffer Targets AI Model Data with Custom Ransomware

Meet JadePuffer, a threat actor with a targeted vendetta against AI model data, deploying custom ransomware to hold machine learning infrastructure hostage. Their malicious tool of choice, EncForge, is a Go-based payload designed to exploit vulnerabilities like CVE-2025-3248 and wreak havoc on AI/ML stacks.

Analyst 207
US government cybersecurity team gathered around screens discussing strategies in operations center.

AI Models Expose Gaps in US Cyber Defense Strategy

The pressing question is no longer if cybersecurity matters, but how we'll manage AI-driven risks before they overwhelm our defenses - and who will lead the charge. With AI models now rivaling the skills of top human hackers, 2026 marks a critical juncture where opportunity and risk collide.

Analyst 207
Industrial computer servers and monitoring equipment in a power grid control room with generic computer screens and control…

Malicious Cloud Tenants Target Power Grid with GPU Workloads

Researchers have discovered a new cyber-physical attack, dubbed Bit2Watt, where malicious cloud tenants can harness GPU workloads to modulate power grid frequencies, reaching a staggering 6,000 Hz - far surpassing the mere few hertz of typical household appliances. This technique poses a significant threat to the stability of our power infrastructure.

Analyst 207
Cluttered software development workspace with laptop showing blurred GitHub page.

GitHub Repositories Targeted in FakeGit Malware Campaign

A massive FakeGit malware campaign has infected nearly 7,600 GitHub repositories, cleverly disguising itself as legitimate projects and even tricking AI agents with convincing READMEs and fake developer profiles. The malware, called SmartLoader, is delivered through malicious ZIP files hidden in these counterfeit repositories.

Analyst 207
Rows of computer servers and storage systems in a brightly-lit clean-room setting.

AI Agents Exploit Hugging Face Infrastructure, Evade Commercial LLM Guardrails

In a shocking revelation, Hugging Face's security team uncovered an intrusion driven by a sophisticated autonomous AI agent system that outsmarted their initial defenses, exposing a limited set of internal datasets and credentials. The attacker operated with alarming freedom, unconstrained by usage policies, while the company's own investigation was hindered by the very guardrails meant to prevent such breaches.

Analyst 207
Dimly lit server room with exposed directory structure on open workstation screen.

AI-Assisted Phishing Toolkit Exposed in WebDAV Malware Campaign

Meet the AI-assisted phishing toolkit that was left wide open, complete with 1,048 files, including testing notes and live delivery logs - a rare glimpse into a hacker's playbook. The exposed repository revealed a sophisticated operation, even down to a hardcoded path pointing to an open-source AI coding tool.

Analyst 207
Brightly-lit office setting with computer workstation and calendar showing May 13, 2050 date.

HollowGraph Malware Exploits Microsoft Graph for Stealthy C2 Comms

Meet HollowGraph, a sneaky malware that hijacks Microsoft 365 calendars to secretly receive commands and steal data, using a clever dead-drop technique to stay under the radar. It creates seemingly innocuous calendar events with cryptic titles and attachments to covertly communicate with its masters.

Analyst 207
Empty office with laptop on desk, blurred screen, in front of cityscape window and subtle calendar display.

HollowGraph Malware Exploits Microsoft 365 Calendar for Covert C2 Channel

Meet HollowGraph, a sneaky espionage implant that hijacks Microsoft 365 calendars to secretly communicate with its operators, never even touching an attacker-controlled server. By masquerading as a harmless calendar event, HollowGraph quietly receives instructions and sends stolen data under the radar.

Analyst 207
Server room with rows of computer servers and a lone laptop with a blank screen.

JadePuffer Unleashes AI-Targeted Ransomware with Data Wiping Capabilities

In a chilling display of cyber sophistication, JadePuffer unleashed a devastating ransomware attack that not only locked up data but also boasted data-wiping capabilities, leaving a trail of destruction in its wake. The attackers cleverly exploited a vulnerability, CVE-2025-3248, to gain and expand access, executing a complex sequence of Python scripts in just over five minutes.

Analyst 207
Dimly lit computer workstation with laptop, empty screens, and a glowing USB drive.

Cruciferra Crypter Evades Detection With Advanced Obfuscation Tactics

Meet Cruciferra, the notorious crypter dubbed the underground's most lethal tool, and learn how its creators are using advanced obfuscation tactics to evade detection across dozens of malware campaigns. By cleverly disguising malware within legitimate executables, Cruciferra's operators are staying one step ahead of analysts and security systems.

Analyst 207
Laptop on office desk shows Microsoft 365 calendar with blurred cityscape in background.

Malware Hides in Microsoft 365 Calendars via HOLLOWGRAPH Campaign

Meet HOLLOWGRAPH, a sneaky malware that's hiding in plain sight - using Microsoft 365 calendars to pull off a highly targeted espionage threat. This compact implant is reading and writing secret messages, all while masquerading as a harmless calendar event.

Analyst 207
Quiet university setting with laptop and papers on a clean desk near a window.

AI Model Crafts Complex WordPress Exploit Chain in Hours

In just a few hours, a cutting-edge AI model crafted a complex exploit chain for WordPress, leveraging two recently disclosed core vulnerabilities without needing any preconditions or plugins. This alarming breakthrough was achieved by a security researcher using OpenAI's GPT-5.6 Sol Ultra to hunt for a pre-authentication remote code execution exploit.

Analyst 207
Military logistics area under surveillance by IP cameras in Ukraine.

Russian Hackers Exploit IP Cameras to Spy on NATO, Ukraine Military Logistics

Russian hackers are exploiting internet-connected security cameras to spy on NATO and Ukraine's military logistics, with over 87,000 cameras across the EU and Ukraine vulnerable to a known exploit. This alarming operation, revealed by Dutch intelligence, has left sensitive sites exposed to Russian surveillance.

Analyst 207
Laptop screen displays blurred Microsoft 365 calendar in office setting with notebook and pen nearby.

HollowGraph Malware Exploits Microsoft 365 Calendars for Covert C2 Communications

Meet HollowGraph, a sneaky new Windows malware that's exploiting Microsoft 365 calendars to secretly communicate with hackers, using trusted services to hide in plain sight. This highly targeted threat can turn a compromised calendar into a covert channel for stolen data and malicious instructions.

Analyst 207
Modern tech facility with a lone computer workstation in the foreground.

Russian Hacker Exploits Google AI to Control Botnet

A solo Russian hacker, going by the name "bandcampro", cleverly exploited Google's AI tool to build a sneaky botnet operation that was incredibly lightweight, consisting of just three plaintext files totaling 5 KB. This made it easy to replicate and dispose of, allowing the hacker to stay one step ahead.

Analyst 207
Formal law enforcement setting with a professional person in front of a government building interior backdrop.

UK Police Chiefs Push for Cybercrime Risk Orders After TfL Hack

The UK's National Crime Agency has hailed a major cybercrime case as its most complex investigation to date, after two men were jailed for their role in the massive TfL hack, and is now calling for new powers to tackle the growing threat of cybercrime. The case has sparked renewed demands for Cybercrime Risk Orders to help manage and mitigate cyber risk.

Analyst 207
Network device with multiple cables on a rack in a brightly-lit operations room.

SonicWall SMA Zero-Days Exploited to Gain Root Access

A newly identified threat actor, UTA0533, has been caught exploiting zero-day vulnerabilities in SonicWall SMA VPN appliances to gain root access, using custom malware and other sophisticated tactics. This alarming attack was uncovered during an incident response in July, with two compromised appliances detected in a single environment.

Analyst 207