Ransomware
Curated coverage and analysis in this editorial area.

AnMed Ransomware: 72-Hour Criminal Deadline Collides With 72-Hour CIRCIA Mandate
AnMed Health suffered a ransomware attack starting July 26, 2026, with a patient reporting a 72-hour ransom demand. The health system…

The Great Patching Isn't Enough Anymore: When Attackers Weaponize Your Own Tools
Cisco Talos IR's Q2 2026 report marks a turning point: phishing now drives over 50% of engagements, while authentication abuse surged…

Ransomware in Vietnam: A 2.56% Drop Masks a More Insidious Threat
Kaspersky's Q1 2026 report shows fewer Vietnamese SMEs hit by ransomware, but experts warn the threat has shifted to earlier intrusion…

Prinz Eugen: The Ransomware That Encrypts Recent Files and Vanishes Without a Trace
Prinz Eugen sorts files by modification date, verifies decryptability, then wipes its key and binary. A model targeting the data least…

Spirals: New Rust Ransomware Deployed Across Enterprise Network in Under 24 Hours
The Symantec Threat Hunter Team has documented Spirals, a Rust-based ransomware using ECDH+AES hybrid encryption. An attack in South A…

Anubis Hits Fairlife-Coca-Cola: Production Halted, 1 TB of Data Threatened
The Anubis ransomware group claims responsibility for an attack on Fairlife, a Coca-Cola subsidiary specializing in premium dairy prod…

Infostealers Overtake Phishing and Exploits as Top Enterprise Cloud Access Vector
Infostealer malware logs have surpassed phishing and vulnerability exploits as the primary initial access vector for enterprise cloud…

Qilin Exploits CVE-2026-0257: From VPN Bypass to Ransomware in 4 Days
Arctic Wolf confirms Qilin ransomware is exploiting CVE-2026-0257 in Palo Alto GlobalProtect. The window between patch availability an…

Stadler Rejects $12.3M Ransom: Everest Fails to Leak Data
Swiss rail manufacturer Stadler Rail publicly refused a 10 million Swiss franc ($12.3 million) ransom demand from the Everest ransomwa…

Cl0p Hits PTC Windchill: Zero-Day RCE Exploited for Industrial IP Theft
The Cl0p ransomware group exploits CVE-2026-12569 in PTC Windchill and FlexPLM for unauthenticated remote code execution. CISA confirm…

Microsoft Dismantles StealC C2 Network, But Stolen Logs Keep Fueling Breaches
On June 24, 2026, Microsoft and Europol took down over 200 StealC and Amadey C2 domains. Yet years-old credential logs still circulate…

EncForge: JadePuffer Hits Irrecoverable AI Models With Agentic Ransomware
The agentic threat actor JadePuffer has deployed EncForge, ransomware purpose-built for AI/ML assets. Encrypted models cannot be recov…