threat-intel A new extortion cocktail: office printers, small ransoms, and BitLocker Two separate incidents – one in Colombia and another in Mexico – highlight a concerning trend of attackers leveraging misconfigured systems and built-in Microsoft tools to deploy BitLocker encryption and demand ransom pa… Securelist · Jul 21, 2026 High COMXransomwarebitlockerrdp
threat-intel Intel fortifies Foundry with an actual customer: Fortinet This article covers a range of cybersecurity and technology news, including AMD's challenge to Nvidia's AI compute platform, a Russian phishing campaign mimicking Signal support, and a security acquisition by EQT in the… The Register · Jul 21, 2026 Medium vulnerabilityphishingransomware
threat-intel Kenya probes hack of president's website after bitcoin ransom demand Kenya’s presidential website was hacked, with attackers demanding a ransom of five bitcoins in exchange for not releasing sensitive information. The incident follows a previous coordinated attack in November 2025, highli… The Record · Jul 21, 2026 Medium KEcyberattackransomwaregovernment
threat-intel Anubis menace Coca-Cola via Fairlife The Anubis ransomware group is threatening to publicly release 1 terabyte of stolen data from Fairlife, a dairy products subsidiary of Coca-Cola, unless Coca-Cola pays a ransom by July 27th. Anubis claims to have encrypt… ZATAZ · Jul 21, 2026 High ransomwaredata breachextortion
threat-intel Coinbase Cartel menace Caterpillar Coinbase Cartel, a ransomware group, is attempting to intimidate Caterpillar with a threat to leak information to the press if the company doesn't respond. They are using a tactic of creating a countdown and threatening… ZATAZ · Jul 21, 2026 Medium ransomwareextortioncybercrime
threat-intel New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack A new ransomware, ENCFORGE, is targeting AI model files and infrastructure, leveraging a vulnerability in Langflow (CVE-2025-3248) to gain remote code execution. The ransomware, developed by a threat actor linked to a pr… The Hacker News · Jul 21, 2026 High CVE-2025-3248CVE-2026-33017ransomwarelangflowdocker
threat-intel Attackers pummel critical WordPress vuln to create all sorts of mischief This article covers a range of cybersecurity and technology news, including a vulnerability exploited to create mischief, a Russian phishing campaign mimicking Signal support, and a significant acquisition in the cyberse… The Register · Jul 20, 2026 Medium CVE-2026-63030CVE-2026-60137vulnerabilityphishingransomware
threat-intel Malicious cloud customers can bring down the power grid This article covers a range of cybersecurity and technology news, including a report on Russian phishing attacks posing as Signal support, a Microsoft SharePoint vulnerability, and a broader discussion about the evolving… The Register · Jul 20, 2026 Medium IRphishingvulnerabilityransomware
threat-intel India says allegedly leaked nuclear plant files pose no safety risk A cybercrime group, World Leaks (formerly Hunters International ransomware), has allegedly leaked thousands of files related to India's Kudankulam Nuclear Power Plant, claiming they originated from a breach involving Rel… The Record · Jul 20, 2026 High INcybercrimedata breachnuclear
threat-intel ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More This week saw a flurry of vulnerabilities and attacks, including a WordPress core flaw leading to remote code execution, exploitation of zero-day vulnerabilities in SonicWall VPN appliances, and a new malware framework (… The Hacker News · Jul 20, 2026 High CVE-2026-63030CVE-2026-60137CVE-2026-15409INTÜBRvulnerabilityzero-dayransomware
threat-intel Inc Ransomware Exploits SonicWall SMA Zero-Days A major ransomware group, Inc, has been exploiting two zero-day vulnerabilities in SonicWall SMA appliances to gain remote code execution and escalate privileges, allowing them to infiltrate enterprise networks, steal cr… Dark Reading · Jul 17, 2026 High CVE-2026-15409CVE-2026-15410zero-dayransomwarevulnerability
threat-intel In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint This week’s cybersecurity news highlights a range of concerning events, including a Dutch telecom breach potentially linked to local cybercriminals, a Lidl data breach impacting customers in Belgium and the Netherlands,… SecurityWeek · Jul 17, 2026 High NEBEGEcyberattackransomwaredata breach
threat-intel Dairy company Fairlife suspends production in US after cyber incident Coca-Cola’s Fairlife dairy unit has temporarily halted U.S. production following a ransomware attack. The company is investigating the incident, and while product quality and consumer data are not believed to be compromi… The Record · Jul 17, 2026 Medium cyberattackransomwaredairy
threat-intel Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man A Russian tourist, Aleksandr Yuryevich Ermakov, is being held in Armenia on a U.S. extradition warrant, despite his lawyers arguing he is the wrong man. The U.S. seeks Aleksandr Gennadievich Ermakov, a Russian national p… The Hacker News · Jul 17, 2026 High AUUSRUransomwareextraditionidentity-error
threat-intel Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei A cyberattack disrupted operations at Nichirei, a major Japanese frozen food producer, impacting its logistics, warehousing, and shipping services. The company disconnected systems as a precaution, and is investigating a… SecurityWeek · Jul 17, 2026 Medium JPcyberattackdata-breachransomware
threat-intel ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files ACR Stealer, an infostealer active since 2024, is leveraging deceptive lures – primarily mimicking Claude AI assistant pages and fake CAPTCHAs – to steal browser credentials, Microsoft 365 files, and sensitive documents.… The Hacker News · Jul 17, 2026 High infostealerdeceptive lureransomware
threat-intel Coca-Cola Suspends US Fairlife Production Due to Ransomware Attack Coca-Cola has temporarily halted Fairlife production in the US due to a ransomware attack that compromised production systems. The company is investigating the scope of the incident and working with cybersecurity experts… SecurityWeek · Jul 17, 2026 Medium ransomwarecyberattackproduction
threat-intel AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report Unit 42’s 2026 Global Incident Response Report indicates that while AI is increasingly being used by attackers to speed up attacks and streamline operations – like malware development and command-and-control – the fundam… Palo Alto Unit 42 · Jul 16, 2026 Medium UNaicybersecuritythreat intelligence
ransomware Anubis ransomware: what you need to know The Anubis ransomware, delivered as a service, is targeting healthcare organizations, but its reach extends beyond this sector. This RaaS operation is causing significant disruption and data loss for affected entities, h… Graham Cluley · Jul 16, 2026 High ransomwareraashealthcare
threat-intel Begun, the Patch Wars have Cisco Talos has identified a sophisticated, financially motivated Russian-speaking adversary, UAT-11795, actively targeting users in the U.S. and Europe since June 2025. This campaign utilizes trojanized software install… Cisco Talos · Jul 16, 2026 High UNRUEUsupply-chainaptzero-day