Trusted Platforms, Malicious Payloads Between July and September 2026, attackers hijacked a verified HBO Max Reddit account and ran 108 malicious advertisements over 48 hours. The ads promoted fake HBO Max software, AI tools, and developer utilities. Users who clicked were redirected to websites using the ClickFix social engineering technique — fake error pages or […]
The Groups You Haven’t Heard Of Are Still Encrypting Files Monti, Vice Society, Royal (rebranded as BlackSuit), Cuba, Nokoyawa, Yanluowang, and Lorenz aren’t household names like LockBit or Qilin, but they’re actively compromising businesses in 2026. They target mid-size organizations, school districts, hospitals, and municipal systems — victims that pay quietly and attract less law […]
Security Arsenal’s monitoring of the MEDUSALOCKER leak site identified four new victim postings on September 12, 2026: two manufacturing firms (one in China, one in the UAE), a US construction company, and an Indian hospitality property. The affiliates likely compromised these organizations weeks earlier via perimeter exploitation — VMware vCenter path traversal (CVE-2026-59310), Cisco FMC […]
On September 3, 2026, ConnectWise issued an emergency advisory telling ScreenConnect administrators to disable file transfers immediately. Huntress had discovered attackers weaponizing ScreenConnect’s file transfer capability to spread malware across managed environments — turning a legitimate remote access tool into a worm delivery mechanism. The attack worked because ScreenConnect, like most remote management tools, has […]
The Attack: From a Teams Chat to Domain Controller Access An operator impersonating internal IT support contacts an employee through Microsoft Teams from an external tenant. A little social pressure gets the target to approve a remote assistance session—either through Teams screen-share “request control” or by reading back a Quick Assist code. Once the session […]
What Happened Midwest Spine and Brain Institute disclosed a ransomware attack that originated through a vendor compromise. The attack impacted patient data systems — exactly the kind of critical healthcare infrastructure that organizations struggle to protect, especially when the threat comes through a trusted business relationship rather than a direct perimeter breach. Vendor compromises are […]
Five healthcare providers just reported ransomware-related data breaches to HHS. Alta Orthopaedics in California, Cornerstone Behavioral Healthcare in Maine, Cameron Regional Medical Center, and two others — all hit by ransomware that encrypted patient records and disrupted operations. Same attack pattern. Same result. Same preventable problem. Ransomware Requires Writing Files to Disk Every ransomware attack […]
KELA’s September 2026 threat intelligence report describes what they’re calling “Ransomware 5.0″—AI-powered, highly automated attacks with breakout times under 30 minutes, targeting Windows, Linux, ESXi hypervisors, and cloud infrastructure. The quadruple extortion model combines file encryption, data theft, DDoS attacks, and direct harassment of customers and partners. The report notes that 83% of cyberattacks now […]
DaVita, one of the largest kidney dialysis providers in the United States, agreed to pay $15 million to settle litigation stemming from a 2025 ransomware attack. The attack resulted in the theft of sensitive patient data — protected health information (PHI) covered under HIPAA. Operations were disrupted. Patients were notified. Lawyers were paid. This is […]
The Attack: Multi-Stage Delivery, BYOVD, and Persistence A recent campaign targeting individuals and organizations in Cambodia demonstrates the multi-stage complexity of modern malware delivery. Researchers at Acronis identified attacks using phishing emails with diverse lures — Cambodian government notices, public health announcements, dental records, real estate documents, and promotional offers — to distribute compressed archives […]