Ransomware
Curated coverage and analysis in this editorial area.

Lazarus Shares Zero-Day and C2 With Gunra: South Korea Raises Alarm
Four South Korean agencies confirm the Lazarus Group shared tools, infrastructure, and a zero-day vulnerability with the Gunra ransomw…

ExfilSquad Exfiltrates Data on 100,000 UK Police Officers: Debut Without Encryption
The emerging ransomware group ExfilSquad has exfiltrated contact data for over 100,000 officers from the UK Police National Legal Data…

Kodak Confirms 'Limited' Breach, but ShinyHunters Claims 2.2 Million Records
Kodak acknowledged unauthorized access to a 'limited amount' of corporate data on June 18, 2026, but did not verify the 2.2 million re…

Orova Strikes Hong Kong on Day of SFC's First Ransomware Fine
The Orova ransomware group listed five Hong Kong victims on August 4, 2026, bringing its confirmed tally to 24 in three months. The ne…

Analog Devices Separates Real Breach from ExfilSquad Claim: The Lesson
Analog Devices confirmed file exfiltration in its July 29 SEC 8-K filing but distances the ExfilSquad claim of 570,000 records as a se…

INC Ransomware Chains Two SonicWall Zero-Days for Root Access via VPN Appliance
Two zero-days in SonicWall SMA 1000 let INC Ransomware gain remote root access. Pre-disclosure exploitation began June 22, three weeks…

CRPx0 Lists Hyundai Turkey: The Credibility Gap in Dark Web Claims
Ransomware group CRPx0 has listed Hyundai Turkey on its dark web leak site. With no official confirmation and no independent verificat…

Data-Theft Campaign Targets Windchill and FlexPLM via CVE-2026-12569 RCE
A data-theft extortion campaign is exploiting CVE-2026-12569, a critical unauthenticated RCE in PTC Windchill and FlexPLM, to deploy h…

INC Ransomware Dominates SonicWall Zero-Day Chain: When the VPN Appliance Becomes an Unmonitored Bridge
INC Ransomware has emerged as the dominant threat actor actively weaponizing a chain of two zero-day vulnerabilities in SonicWall SMA…

Phishing Tops 50% of IR Cases: Cisco Talos Flags Perimeter Collapse
In Q2 2026, phishing became the leading initial access vector in over half of Cisco Talos Incident Response engagements, up from rough…

Estée Lauder's 10-Month Oracle EBS Breach: The Suspected Patch Gap That Let Clop In
Estée Lauder disclosed a 10-month breach of its Oracle E-Business Suite HR system. The Clop ransomware group exploited CVE-2025-61882,…

AnMed Ransomware: 72-Hour Criminal Deadline Collides With 72-Hour CIRCIA Mandate
AnMed Health suffered a ransomware attack starting July 26, 2026, with a patient reporting a 72-hour ransom demand. The health system…