The Attack: Legitimate Tools, Malicious Intent A phishing operation spanning 46 countries is using fake tax documents, invoices, and DocuSign lures to trick victims into installing legitimate remote monitoring and management software. ANY.RUN researchers tracked 425 phishing-kit URLs across 240 hosts between February and July 2026, with 94% of those hosts appearing for only one […]
CRPx0 went from fewer than 10 victims in June 2026 to 48 organizations by late August, according to a recent report from The Register. The ransomware crew offers two products: a full-service hacking operation promising “complete database extraction” and network compromise, and a white-label ransomware-as-a-service platform that lets criminals with “no technical background” run their […]
894 Attacks. One Mechanism They All Depend On. July 2026 saw ransomware attacks hit 894 incidents — the highest monthly total of the year, according to NCC Group’s Threat Intelligence Report. The Gentlemen ransomware group alone claimed over 300 victims in twelve months. A new player called CRPxO emerged with 36 attacks in July. And […]
Two Campaigns, Same Dependency: Writing Payloads to Disk Gen Digital and Expel recently flagged two new malware families making the rounds. WordlistLoader delivers Amatera stealer via fake CAPTCHA prompts on compromised websites, and SynkLoader arrives via Microsoft Teams phishing disguised as IT support. Both campaigns are well-executed social engineering, and both are being used to […]
A new Windows backdoor called Sleepwalker has security researchers paying attention. Unlike typical malware that phones home to a command-and-control server, Sleepwalker sits silently in memory, waiting for a single specially-crafted network packet to wake it up. Once activated, it uses its own 23-instruction command language to exfiltrate data, run code directly in memory, and […]
Another healthcare practice announces a data theft and extortion incident. Another round of patient notifications, regulatory scrutiny, and reputational damage. The details aren’t fully public yet, but the pattern is familiar: attackers gained access to patient health information and either encrypted it, exfiltrated it, or both. Here’s the uncomfortable truth about these breaches: they succeed […]
Microsoft announced this week that Windows 11 is finally removing WMIC (Windows Management Instrumentation Command-line) entirely, completing a five-year deprecation process that started in 2021. The reason? Malware and ransomware groups have been abusing it for years. WMIC is what security researchers call a LOLBIN — a “living-off-the-land binary.” It’s a legitimate Microsoft-signed Windows tool […]
Texas Hearing Institute recently disclosed a ransomware attack that compromised the protected health information of nearly 30,000 patients. The organization now faces HIPAA breach notification requirements, potential OCR investigation, remediation costs, and reputational damage. This attack followed the same pattern as nearly every other ransomware incident: an executable payload was delivered to the organization’s Windows […]
What Happened Betelgeuse is a ransomware variant discovered in August 2026 targeting company networks. Like most modern ransomware, it follows a predictable pattern: gain access to a Windows system, encrypt files, append a distinctive extension (.betelgeuse followed by a numeric suffix), and drop a ransom note demanding payment within 72 hours. The attackers claim to […]
Managers Are the New Bullseye Zscaler’s ThreatLabz just published research on a single ransomware campaign that hit 351 victims across 334 organizations in one month. The detail that matters: 62% of the victims held manager-level titles or higher. The attackers weren’t picking names at random. They targeted people in accounting, finance, HR, operations, and sales […]