Ransomware
Curated coverage and analysis in this editorial area.

Autonomous AI Delivers Full Ransomware Attack in 10 Hours — and an 80-Page Audit for the Victim
Palo Alto Networks' Unit 42 has documented the first ransomware attack entirely managed by AI agents, completed in under 10 hours. The…

VantaCore: Pro-Ukraine Group Relaunches with Custom Ransomware Targeting Russia
VantaCore, a rebrand of the pro-Ukraine Thor group, is hitting Russian organizations with a proprietary arsenal of ransomware and remo…

Public Exploit for CVE-2026-84115 Puts Cleo Harmony at Immediate Risk
A public exploit for the authentication-bypass vulnerability CVE-2026-84115 in Cleo Harmony has been released. Versions 5.8.1.0 throug…

Rhysida Hits Berlin Government: Data Auction Launched, Ransom Refused
The Rhysida ransomware group claimed responsibility for a cyberattack on the Berlin state government on August 28, 2026, auctioning 5.…

ATF Confirms 'Major Incident' Without Confirming Who Caused It
The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed the breach of a standalone system but stopped short of attributing i…

Ransomware Hits Norcross: A City’s Technical Silence After a Partial Takedown
The city of Norcross, Georgia, confirmed a ransomware attack identified on August 1, 2026. Most systems are back online, but the publi…

Aurora Ransomware Group Abuses AI Cursor Agent for Post-Compromise Attacks
The Aurora ransomware group used the AI-powered Cursor Agent with Claude Sonnet as an interactive operational assistant during active…

ATF Confirms Qilin Breach: Isolated System, No Data Theft Confirmed
The ATF confirmed a major cybersecurity incident on August 26, 2026, involving a standalone system containing investigative target inf…

Medusa Tops 500 Victims: CISA Updates Advisory on 24-Hour Exploit Window
CISA, FBI, and HHS updated advisory AA25-071A on August 18, 2026, documenting over 500 Medusa ransomware victims since June 2021, with…

DeadLock Leverages Polygon and Session for Takedown-Resistant Ransomware Infrastructure
Microsoft Threat Intelligence dissects DeadLock, a Rust-based ransomware that has compromised over 80 organizations since July 2025, w…

SonicWall SMA 1000 Under Attack: CVE-2026-15409 CVSS 10.0 and TOTP Seed Theft
CVE-2026-15409 and CVE-2026-15410 exposed SonicWall SMA 1000 appliances to unauthenticated root compromise. The theft of MFA seeds ren…

Cl0p Exploits PTC Windchill Zero-Day to Steal 100+ GB from Shell and Philips
The Cl0p ransomware group claims theft of over 100 GB of industrial data from Shell and Philips by exploiting CVE-2026-12569. The camp…