August 2026 set a record: 997 ransomware attacks worldwide in a single month, the highest count ever tracked by Comparitech. Inside that spike, a new ransomware-as-a-service operation called Panzer went from nonexistent on August 4 to claiming 16 victims across 11 countries by early September. The group launched with a fully operational affiliate platform, cross-platform […]
GuidePoint Security recently documented a sophisticated malware campaign that uses smart contracts on the Polygon blockchain to maintain command-and-control infrastructure. The technique, called EtherHiding, stores the attacker’s current C2 server address inside a blockchain smart contract instead of hardcoding it into the malware. When defenders block one C2 domain, the attacker updates the smart contract […]
Trusted Platforms, Malicious Payloads Between July and September 2026, attackers hijacked a verified HBO Max Reddit account and ran 108 malicious advertisements over 48 hours. The ads promoted fake HBO Max software, AI tools, and developer utilities. Users who clicked were redirected to websites using the ClickFix social engineering technique — fake error pages or […]
The Groups You Haven’t Heard Of Are Still Encrypting Files Monti, Vice Society, Royal (rebranded as BlackSuit), Cuba, Nokoyawa, Yanluowang, and Lorenz aren’t household names like LockBit or Qilin, but they’re actively compromising businesses in 2026. They target mid-size organizations, school districts, hospitals, and municipal systems — victims that pay quietly and attract less law […]
Security Arsenal’s monitoring of the MEDUSALOCKER leak site identified four new victim postings on September 12, 2026: two manufacturing firms (one in China, one in the UAE), a US construction company, and an Indian hospitality property. The affiliates likely compromised these organizations weeks earlier via perimeter exploitation — VMware vCenter path traversal (CVE-2026-59310), Cisco FMC […]
On September 3, 2026, ConnectWise issued an emergency advisory telling ScreenConnect administrators to disable file transfers immediately. Huntress had discovered attackers weaponizing ScreenConnect’s file transfer capability to spread malware across managed environments — turning a legitimate remote access tool into a worm delivery mechanism. The attack worked because ScreenConnect, like most remote management tools, has […]
The Attack: From a Teams Chat to Domain Controller Access An operator impersonating internal IT support contacts an employee through Microsoft Teams from an external tenant. A little social pressure gets the target to approve a remote assistance session—either through Teams screen-share “request control” or by reading back a Quick Assist code. Once the session […]
What Happened Midwest Spine and Brain Institute disclosed a ransomware attack that originated through a vendor compromise. The attack impacted patient data systems — exactly the kind of critical healthcare infrastructure that organizations struggle to protect, especially when the threat comes through a trusted business relationship rather than a direct perimeter breach. Vendor compromises are […]
Five healthcare providers just reported ransomware-related data breaches to HHS. Alta Orthopaedics in California, Cornerstone Behavioral Healthcare in Maine, Cameron Regional Medical Center, and two others — all hit by ransomware that encrypted patient records and disrupted operations. Same attack pattern. Same result. Same preventable problem. Ransomware Requires Writing Files to Disk Every ransomware attack […]
KELA’s September 2026 threat intelligence report describes what they’re calling “Ransomware 5.0″—AI-powered, highly automated attacks with breakout times under 30 minutes, targeting Windows, Linux, ESXi hypervisors, and cloud infrastructure. The quadruple extortion model combines file encryption, data theft, DDoS attacks, and direct harassment of customers and partners. The report notes that 83% of cyberattacks now […]