Ransomware
Curated coverage and analysis in this editorial area.

MySQL Exposed at 26%: The 2026 Top 10 Attack Surface Exposures
Intruder's 2026 ASM Index reveals exposed databases and admin panels as primary vectors. Time-to-exploit has collapsed to a single day…

Lorem Ipsum Pivots to ClickFix After Fox Tempest Takedown
BlueVoyant reports the Lorem Ipsum malware abandoned signed Microsoft Teams installers for ClickFix tactics on compromised WordPress s…

DragonForce Weaponizes Microsoft Teams TURN Relays for Stealth C2
The DragonForce ransomware group deployed Backdoor.Turn, the first documented in-the-wild malware to abuse Microsoft Teams' legitimate…

iRhythm: Patient Health Data Stolen via Social Engineering
iRhythm Holdings disclosed a data breach in which attackers exfiltrated PHI and PII from third-party business applications through soc…

Conti Developer Sentenced: Why Loaders Are the RaaS Achilles' Heel
Ukrainian Conti ransomware developer Oleksii Lytvynenko pleaded guilty in U.S. federal court after extradition from Ireland. The case…

The Gentlemen: LLMs Accelerate the Ransomware Attack Cycle
CERT-AGID reveals that The Gentlemen ransomware group uses LLMs to build platforms in three days and customize extortion. Technical cl…

The Gentlemen: LLMs Cut Ransomware Development to Three Days
CERT-AGID reports the ransomware group The Gentlemen uses LLMs to build platforms in three days, personalize extortion, and replicate…

ShinyHunters Hits 100+ Universities with Oracle Zero-Day
CVE-2026-35273 in PeopleSoft EMHub: unauthenticated RCE, CVSS 9.8, 68% of victims in higher education. CISA mandates patch by June 15.

AudiA6 Takedown: Global Strike Dismantles $900M Crypto-Laundering Pipeline
On June 11, 2026, international authorities arrested two administrators in Georgia and seized infrastructure across four countries, di…

Europol and DOJ Dismantle AudiA6: A Critical Hub for Ransomware Money Laundering Smashed
In a major operation on June 10, 2026, authorities arrested two administrators in Georgia and seized 25 domains and 30+ servers. The A…

CVE-2026-50751: Check Point VPN Zero-Day Exploited by Qilin Affiliate; Patch Released June 8
A Qilin ransomware affiliate exploited a critical zero-day in Check Point VPN’s IKEv1 protocol for over a month. The flaw (CVSS 9.3) a…

World Cup 2026: A Cyber-Physical Attack Surface Spanning Three Nations
Unit 42 maps the sprawling perimeter of the USA-Mexico-Canada World Cup, identifying critical OT/IT interdependencies across 16 host c…