// 3 CRITICAL · 2 ZERO-DAY · 3 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H
ai

Autonomous AI Delivers Full Ransomware Attack in 10 Hours — and an 80-Page Audit for the Victim

Palo Alto Networks' Unit 42 has documented the first ransomware attack entirely managed by AI agents, completed in under 10 hours. The…

Sep 02, 2026views - 1.2k

ransomware

VantaCore: Pro-Ukraine Group Relaunches with Custom Ransomware Targeting Russia

VantaCore, a rebrand of the pro-Ukraine Thor group, is hitting Russian organizations with a proprietary arsenal of ransomware and remo…

Sep 02, 2026views - 1.2k

CYBERSECEXPLOIT

Public Exploit for CVE-2026-84115 Puts Cleo Harmony at Immediate Risk

A public exploit for the authentication-bypass vulnerability CVE-2026-84115 in Cleo Harmony has been released. Versions 5.8.1.0 throug…

Sep 02, 2026views - 997

ransomware

Rhysida Hits Berlin Government: Data Auction Launched, Ransom Refused

The Rhysida ransomware group claimed responsibility for a cyberattack on the Berlin state government on August 28, 2026, auctioning 5.…

Aug 30, 2026views - 1.1k

ransomware

ATF Confirms 'Major Incident' Without Confirming Who Caused It

The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed the breach of a standalone system but stopped short of attributing i…

Aug 30, 2026views - 1.1k

ransomware

Ransomware Hits Norcross: A City’s Technical Silence After a Partial Takedown

The city of Norcross, Georgia, confirmed a ransomware attack identified on August 1, 2026. Most systems are back online, but the publi…

Aug 30, 2026views - 1.1k

ransomware

Aurora Ransomware Group Abuses AI Cursor Agent for Post-Compromise Attacks

The Aurora ransomware group used the AI-powered Cursor Agent with Claude Sonnet as an interactive operational assistant during active…

Aug 28, 2026views - 1.2k

CYBERSEC

ATF Confirms Qilin Breach: Isolated System, No Data Theft Confirmed

The ATF confirmed a major cybersecurity incident on August 26, 2026, involving a standalone system containing investigative target inf…

Aug 27, 2026views - 1.1k

ransomwareADVISORY

Medusa Tops 500 Victims: CISA Updates Advisory on 24-Hour Exploit Window

CISA, FBI, and HHS updated advisory AA25-071A on August 18, 2026, documenting over 500 Medusa ransomware victims since June 2021, with…

Aug 24, 2026views - 1.2k

ransomware

DeadLock Leverages Polygon and Session for Takedown-Resistant Ransomware Infrastructure

Microsoft Threat Intelligence dissects DeadLock, a Rust-based ransomware that has compromised over 80 organizations since July 2025, w…

Aug 22, 2026views - 1.1k

CYBERSECCVE

SonicWall SMA 1000 Under Attack: CVE-2026-15409 CVSS 10.0 and TOTP Seed Theft

CVE-2026-15409 and CVE-2026-15410 exposed SonicWall SMA 1000 appliances to unauthenticated root compromise. The theft of MFA seeds ren…

Aug 20, 2026views - 1.2k

CYBERSECZERO-DAY

Cl0p Exploits PTC Windchill Zero-Day to Steal 100+ GB from Shell and Philips

The Cl0p ransomware group claims theft of over 100 GB of industrial data from Shell and Philips by exploiting CVE-2026-12569. The camp…

Aug 20, 2026views - 1.2k