799 Attacks in One Month — And the Same Vulnerability Ransomware attacks jumped nearly 20 percent in July 2026, with 799 incidents recorded by Comparitech. The most-hit sectors were finance (up 71%), tech (up 62%), pharma and medical billing (up 46%), and education (up 44%). The United States saw 322 of those attacks. Two gangs […]
Kaspersky recently documented a series of ransomware attacks targeting companies in Colombia and Mexico where attackers skipped the custom malware entirely and just weaponized BitLocker — Microsoft Windows’ legitimate disk encryption feature. The attacks succeeded because the evildoers understood something important: if you can get inside a network and activate BitLocker with your own recovery […]
The Signature Update Problem Kaspersky’s 2025 detection systems identified an average of 500,000 new malicious files per day—a 7% increase over the previous year. The same report documented a 59% surge in password-stealer detections and a 51% spike in spyware. Every one of those half-million daily files represents a new piece of code that antivirus […]
Microsoft issued a warning last week about CaptiveCrunch, a Russian campaign targeting corporate travelers on hotel and conference WiFi networks. The attack, attributed to Storm-2945 (a sub-cluster of Russia’s Midnight Blizzard), delivers a remote access trojan called CornFlake by compromising guest network captive portals and presenting fake Windows update prompts to unsuspecting users. CornFlake is […]
The Attack: Ransomware Plus Data Theft On June 16, 2026, attackers compromised River Financial Corporation’s network, deployed ransomware across their server environment, and exfiltrated an unknown amount of data. The company took systems offline, disabled compromised admin accounts, and brought in forensic investigators. Weeks later, they’re still trying to determine what data was stolen. They’ve […]
The Attack That Triggered Federal Investigation In 2021, the Xing Team ransomware gang struck OSF Healthcare System, encrypting protected health information and exposing systemic security failures. The HHS Office for Civil Rights opened an investigation that culminated in a 2026 settlement — not just for the ransomware attack itself, but for the underlying HIPAA Security […]
What Happened at MCBS MCBS, LLC, a Georgia-based healthcare management and revenue cycle management company, just disclosed a cybersecurity incident affecting 1.26 million individuals. While the full details are still emerging, this is the nightmare scenario for any organization handling protected health information: over a million patient records potentially compromised, HIPAA breach notification requirements triggered, […]
Cisco Talos recently disclosed msaRAT, a remote access trojan attributed to the Chaos ransomware group. The malware is notable for its evasion technique: it uses headless Chrome or Edge browser processes to communicate with command-and-control servers via the Chrome DevTools Protocol, disguising its traffic as legitimate browser activity. Traditional network monitoring tools and antivirus software […]
AnMed Health, a nonprofit health system serving upstate South Carolina and Northeast Georgia, was forced to close nearly 80 facilities following a cyberattack. While the organization hasn’t disclosed specifics, the scale of disruption — shutting down dozens of care locations — points to ransomware that encrypted critical systems across the network. This is what happens […]
The Attack: Sophisticated Evasion Assumes the Payload Already Landed Proofpoint recently documented Cruciferra, a crypter-as-a-service used by multiple cybercrime groups to deliver RATs and info-stealers to financial services, healthcare, government, and education targets. The campaigns use phishing emails with malicious attachments or links to ZIP files hosting the payload. What makes Cruciferra interesting is the […]