The Attack: Credential Stuffing, Data Theft, and a Self-Defeating Encryptor In early August 2026, an Akira ransomware affiliate compromised a victim organization through a SonicWall SSL VPN account that wasn’t protected by multi-factor authentication. After seven minutes of failed credential spraying, one valid username-password pair worked. Once inside, the attacker moved to the domain controller […]
CISA advisory AA26-222A documents a ransomware operation that should make every Windows administrator uncomfortable. Gunra, built on leaked Conti source code, breached 51 organizations by exploiting unpatched Fortinet firewall vulnerabilities, then executed a playbook that’s become depressingly familiar: lateral movement via SMB, credential harvesting, backup deletion, and mass encryption of up to 9 terabytes per […]
DeadLock ransomware made headlines for moving its command-and-control infrastructure onto the Polygon blockchain — a technique that makes law enforcement takedowns nearly impossible. Microsoft Threat Intelligence published a detailed technical breakdown on August 10, 2026, describing the group’s Rust-based encryptor, its mathematically sound per-file ephemeral key design, and the decentralized ecosystem it built around smart […]
The Attack: Disguise, Deploy, Encrypt The Play ransomware group has adopted a clever evasion tactic: they use a custom binary named PSexesvc.exe that mimics Microsoft’s legitimate PsExec administration tool. This masquerading technique (MITRE ATT&CK T1036) allows them to blend malicious activity into normal Windows administration workflows, making detection difficult for signature-based security tools. Picus Security’s […]
The AV-TEST Institute logs over 450,000 new malware variants every single day. Most of them arrive the same way they have for two decades: through email. Malicious attachments. Links to weaponized sites. Password-protected archives that bypass scanning. HTML smuggling. QR codes. AI-generated social engineering that references real projects and actual colleagues. The delivery methods evolve. […]
DARK PROJECT ransomware affiliates posted three new victims on August 4, 2026: Reid Electric Service (energy sector), TSC Logistics (transportation), and Long-Lewis Automotive Group. The attack pattern is textbook mid-market opportunistic targeting — unpatched edge devices, exploited remote access tools, and a 5–14 day dwell time from initial access to encryption. Security Arsenal’s analysis identifies […]
799 Attacks in One Month — And the Same Vulnerability Ransomware attacks jumped nearly 20 percent in July 2026, with 799 incidents recorded by Comparitech. The most-hit sectors were finance (up 71%), tech (up 62%), pharma and medical billing (up 46%), and education (up 44%). The United States saw 322 of those attacks. Two gangs […]
Kaspersky recently documented a series of ransomware attacks targeting companies in Colombia and Mexico where attackers skipped the custom malware entirely and just weaponized BitLocker — Microsoft Windows’ legitimate disk encryption feature. The attacks succeeded because the evildoers understood something important: if you can get inside a network and activate BitLocker with your own recovery […]
The Signature Update Problem Kaspersky’s 2025 detection systems identified an average of 500,000 new malicious files per day—a 7% increase over the previous year. The same report documented a 59% surge in password-stealer detections and a 51% spike in spyware. Every one of those half-million daily files represents a new piece of code that antivirus […]
Microsoft issued a warning last week about CaptiveCrunch, a Russian campaign targeting corporate travelers on hotel and conference WiFi networks. The attack, attributed to Storm-2945 (a sub-cluster of Russia’s Midnight Blizzard), delivers a remote access trojan called CornFlake by compromising guest network captive portals and presenting fake Windows update prompts to unsuspecting users. CornFlake is […]