ransomware Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials The Anubis ransomware group, a rebranded version of Sphinx, is actively exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to gain initial access to victim networks. They leverage legitimate RMM tools like Scree… The Hacker News · Jul 2, 2026 High CVE-2025-5777USUKAUcitrixbleedransomware-as-a-servicecredential theft
ransomware Ransomware Thugs Masquerade as Interpol to Entice Small Biz A new ransomware campaign is targeting small businesses globally, impersonating Interpol to lure victims into downloading malware. The campaign utilizes basic social engineering techniques, delivering a rudimentary ranso… Dark Reading · Jul 2, 2026 Medium USEUSAsocial engineeringphishingsmall business
ransomware The Gentlemen ransomware: what you need to know The Gentlemen ransomware group is a sophisticated and aggressive cybercriminal operation, despite its seemingly formal name. They are known for deploying double extortion tactics, stealing data and threatening to leak it… Graham Cluley · Jul 2, 2026 High ransomwaredouble extortioncybercrime
ransomware FortiBleed Campaign Linked to INC, Lynx Ransomware Attacks Researchers say credentials harvested from hundreds of thousands of FortiGate firewalls are being used to facilitate ransomware attacks by the INC and Lynx operations. The post FortiBleed Campaign Linked to INC, Lynx Ran… SecurityWeek · Jul 2, 2026 High
ransomware AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack A security firm, Sysdig, has identified what appears to be the first fully automated ransomware attack orchestrated by an AI agent, dubbed JADEPUFFER. The agent exploited a vulnerability in Langflow, an open-source AI ap… The Hacker News · Jul 2, 2026 High CVE-2025-3248CVE-2021-29441CHairansomwareautomation
ransomware SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation A high-severity remote code execution (RCE) vulnerability (CVE-2026-45659) in Microsoft SharePoint Server has been added to the CISA KEV catalog due to active exploitation. This vulnerability, stemming from deserializing… The Hacker News · Jul 2, 2026 High CVE-2026-45659CVE-2025-11371USremote code executionsharepointvulnerability
ransomware Teen suspect in Scattered Spider hacks is extradited to US A 19-year-old man, Peter Stokes, with dual citizenship, has been extradited to the United States to face charges related to his involvement with the Scattered Spider cybercrime group. The investigation centers around a r… The Record · Jul 1, 2026 High USESFIphishingsocial engineeringransomware
ransomware AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android A new type of ransomware, dubbed ‘InfernoGrabber v9.0’, has emerged utilizing AI-generated code to exploit vulnerabilities in Chromium-based browsers on Windows and Android. The malware, created using the DeepSeek AI mod… The Hacker News · Jul 1, 2026 High CVE-2023-4863USairansomwarebrowser
ransomware Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints A critical Remote Code Execution (RCE) vulnerability (CVE-2026-33017) in Langflow is being exploited by threat actors to deploy a Monero cryptocurrency miner on exposed AI application endpoints. The campaign, active from… The Hacker News · Jun 30, 2026 Critical CVE-2026-33017CVE-2025-3248NOrcemoneroai
ransomware BlueHammer Vulnerability Exploited in Ransomware Attacks The Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released. The post BlueHammer Vulnerability Exploited in Ransomware Attacks appeared first on SecurityWeek . SecurityWeek · Jun 30, 2026 Critical CVE-2026-33825
ransomware The Gentlemen are knocking: сustom backdoors and evolving tactics This report details the activities of "The Gentlemen," a ransomware-as-a-service (RaaS) group that has been aggressively targeting large corporations and critical infrastructure since early 2026. The group employs sophis… Securelist · Jun 29, 2026 High USransomware-as-a-servicereconnaissancelateral movement
ransomware Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk Recent breaches targeting educational institutions, including ransomware attacks on Oracle E-Business Suite and Instructure's Canvas platform, highlight the vulnerability of the sector due to legacy technology, understaf… Dark Reading · Jun 27, 2026 High USthird-party riskransomwareeducation
ransomware Europe Evolves Into Ransomware's Favorite Region Ransomware attacks in Europe have dramatically increased, representing a significant shift from previous trends. Black Kite researchers report a 55% rise in ransomware attacks across the continent through the first four… Dark Reading · Jun 25, 2026 High UKGEFRransomwaresupply-chainai
ransomware Amadey and StealC Malware Network Disrupted, 27M Stolen Credentials Recovered A coordinated international law enforcement operation, involving Bitdefender, Bitsight, ESET, Microsoft, and Europol, successfully disrupted the Amadey and StealC malware networks, recovering 27 million stolen credential… The Hacker News · Jun 24, 2026 High NLCADEmaascredential theftransomware
ransomware Amadey, StealC malware operations disrupted in Operation Endgame action Operation Endgame, a coordinated law enforcement effort involving Microsoft, Europol, and international partners, successfully disrupted infrastructure used by the Amadey and StealC malware operations. The operation resu… BleepingComputer · Jun 24, 2026 High USCADKmalware-as-a-servicecredential theftransomware
ransomware Indian auto giant Bajaj Auto hit by ransomware incident The company said in a regulatory filing that it became aware of the incident on Tuesday morning and had taken precautionary measures to contain its impact. The Record · Jun 24, 2026 High
ransomware New ‘Mistic’ RAT Opens Door to Several Ransomware Families Mistic is used by Woodgnat, an initial access broker working with Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta. The post New ‘Mistic’ RAT Opens Door to Several Ransomware Families appeared first on SecurityWe… SecurityWeek · Jun 24, 2026 High
ransomware New Prinz Eugen ransomware prioritizes recent files for encryption A new ransomware variant, Prinz Eugen, is targeting organizations with a focus on encrypting recently modified files to maximize disruption. The group employs a hands-on-keyboard approach, utilizing legitimate RMM tools… BleepingComputer · Jun 20, 2026 High GBransomwarerdpencryption
ransomware The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes The Gentlemen ransomware-as-a-service (RaaS) operation is utilizing a sophisticated suite of EDR-terminating tools, centered around the GentleKiller framework, to disable security defenses before deploying ransomware. Th… The Hacker News · Jun 19, 2026 High RUSOWEransomware-as-a-serviceedr-killingbyovd
ransomware Gentlemen ransomware uses multiple EDR killers to disable defenses The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks. BleepingComputer · Jun 18, 2026 High