The Signature Update Problem Kaspersky’s 2025 detection systems identified an average of 500,000 new malicious files per day—a 7% increase over the previous year. The same report documented a 59% surge in password-stealer detections and a 51% spike in spyware. Every one of those half-million daily files represents a new piece of code that antivirus […]
Microsoft issued a warning last week about CaptiveCrunch, a Russian campaign targeting corporate travelers on hotel and conference WiFi networks. The attack, attributed to Storm-2945 (a sub-cluster of Russia’s Midnight Blizzard), delivers a remote access trojan called CornFlake by compromising guest network captive portals and presenting fake Windows update prompts to unsuspecting users. CornFlake is […]
The Attack: Ransomware Plus Data Theft On June 16, 2026, attackers compromised River Financial Corporation’s network, deployed ransomware across their server environment, and exfiltrated an unknown amount of data. The company took systems offline, disabled compromised admin accounts, and brought in forensic investigators. Weeks later, they’re still trying to determine what data was stolen. They’ve […]
The Attack That Triggered Federal Investigation In 2021, the Xing Team ransomware gang struck OSF Healthcare System, encrypting protected health information and exposing systemic security failures. The HHS Office for Civil Rights opened an investigation that culminated in a 2026 settlement — not just for the ransomware attack itself, but for the underlying HIPAA Security […]
What Happened at MCBS MCBS, LLC, a Georgia-based healthcare management and revenue cycle management company, just disclosed a cybersecurity incident affecting 1.26 million individuals. While the full details are still emerging, this is the nightmare scenario for any organization handling protected health information: over a million patient records potentially compromised, HIPAA breach notification requirements triggered, […]
Cisco Talos recently disclosed msaRAT, a remote access trojan attributed to the Chaos ransomware group. The malware is notable for its evasion technique: it uses headless Chrome or Edge browser processes to communicate with command-and-control servers via the Chrome DevTools Protocol, disguising its traffic as legitimate browser activity. Traditional network monitoring tools and antivirus software […]
AnMed Health, a nonprofit health system serving upstate South Carolina and Northeast Georgia, was forced to close nearly 80 facilities following a cyberattack. While the organization hasn’t disclosed specifics, the scale of disruption — shutting down dozens of care locations — points to ransomware that encrypted critical systems across the network. This is what happens […]
The Attack: Sophisticated Evasion Assumes the Payload Already Landed Proofpoint recently documented Cruciferra, a crypter-as-a-service used by multiple cybercrime groups to deliver RATs and info-stealers to financial services, healthcare, government, and education targets. The campaigns use phishing emails with malicious attachments or links to ZIP files hosting the payload. What makes Cruciferra interesting is the […]
The Attack: Malware Assembly Inside the Browser The SourTrade malvertising campaign, documented by Confiant in July 2026, represents a new level of effort in evading signature-based detection. Instead of serving a complete malicious executable from a fixed URL, the attack has the victim’s browser build the payload itself. The landing page registers a ServiceWorker and […]
The Problem: Ransomware No Longer Breaks In. It Logs In. Sophos’ seventh annual State of Ransomware report, released in July 2026, documents a fundamental shift in how ransomware attacks begin. For the first time in years, exploited software vulnerabilities are no longer the leading cause. Instead, 79% of ransomware attacks now start with a compromised […]