Angola's Largest Telco Breached Hours Before IPO
Unitel, Angola's dominant telecom, suffered a cyberattack during its IPO—perfectly timed to undermine investor confidence. The attack appears to be ransomware or destructive rather than espionage.
ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Latest cybersecurity ransomware news, analysis, and intelligence.
Unitel, Angola's dominant telecom, suffered a cyberattack during its IPO—perfectly timed to undermine investor confidence. The attack appears to be ransomware or destructive rather than espionage.
INC Ransomware is actively exploiting SonicWall SMA1000 appliances to gain root access at enterprise network edges, enabling direct internal penetration before endpoint protections can engage. This perimeter compromise is particularly dangerous because attackers bypass EDR entirely and operate insid
River Bank disclosed a June ransomware attack that exfiltrated customer data, with attackers claiming deletion—but such promises lack cryptographic proof and are meaningless. This reflects the modern double-extortion model where criminals hold both encryption keys and stolen data to threaten publica
OpenAI's Astra model made advances in lattice cryptography, the foundation of post-quantum encryption standards. Using formal verification, it generated ten significant mathematical proofs at minimal cost—raising security concerns as AI proves capable of breaking math underlying next-generation secu
The STAC4749 campaign used Microsoft Teams impersonation to breach North American organizations and deploy Chaos ransomware, with one attack reaching full encryption in under 17 hours.
**Ransomware gang ExfilSquad claimed ADI's data then delisted them—suggesting negotiations began. Timing between Analog Devices' disclosed June breach and the gang's recent claim raises questions about whether these are truly two separate incidents.**
SSO concentrates access risk into one credential—a "master key" to dozens of applications. Ransomware groups like Scattered Spider exploit this, targeting identity providers as the quickest path to enterprise compromise.
The FBI's takedown of LockBit ransomware wasn't about seizing servers—it was about poisoning trust. By sowing doubt among the 200 affiliates in the $500M+ operation, law enforcement destroyed the psychological foundation of the criminal franchise far more effectively than any infrastructure seizure.
Anubis ransomware hit Fairlife, stealing 1TB of data and setting a countdown timer. The emerging threat group stands out for its wiper mode, which permanently destroys files if ransom isn't paid.
DevMan transitioned from RaaS affiliate to operator in eight months with portal v3. This SaaS-style ransomware platform shows how criminal operations are becoming professionalized enterprises.
Cl0p ransomware exploits Windchill vulnerabilities for unauthenticated RCE, stealing CAD files and engineering data. The group uses double extortion against manufacturing and aerospace firms.
Clop ransomware targets Windchill/FlexPLM platforms, stealing engineering designs and specs from aerospace/manufacturing. This represents a dangerous shift toward intellectual property theft.
msaRAT, a Chaos ransomware implant, launches hidden Chrome instances and injects JavaScript to relay C2 commands through Cloudflare and Twilio, disguising malicious traffic as normal browser activity to evade network detection.
Google now lets users enroll selfie videos as account recovery. The encrypted, opt-in feature excludes high-risk accounts but poses risks as AI deepfakes become cheaper and more convincing.
**Summary:** AI assistants deployed across enterprise systems inherit broad permissions to access multiple platforms and sensitive data. Compromising an agent's credentials grants attackers access to everything the agent can reach—CRM, email, file shares, workflows—creating a significant new ransom
Stadler Rail publicly refused Everest ransomware's $12.3 million extortion demand and filed a criminal complaint. The breach was limited to a supplier data exchange platform and contained only non-sensitive technical information, not critical production or security systems.
Ransomware attacks accelerated 60% in the second half of 2026, not because attackers became smarter or leveraged AI, but because barriers to entry collapsed—60+ new groups now operate using commoditized tools and Ransomware-as-a-Service platforms to target underfunded midmarket organizations. The th
Ransomware now specifically targets AI models. JadePuffer's EncForge exploited Langflow and Docker to autonomously iterate attack scripts in five minutes, hunting ML infrastructure and model weights.
Supply chain vulnerabilities dominated the week as major retailers fell victim through compromised third-party vendors. Ransomware drove a German textile firm into bankruptcy after a six-week shutdown, illustrating how interconnected security weaknesses cascade across industries.
Armenia arrested the wrong Aleksandr Ermakov following a U.S. extradition warrant for REvil ransomware crimes. The detained tourist is a former lawyer from Omsk; authorities allegedly confused him with a different namesake sanctioned for the 2022 Medibank hack, exposing how patronymic details get lo
Coca-Cola subsidiary Fairlife suspended US milk production after a ransomware attack compromised production systems. No product safety issues were confirmed, but supply chain disruption is expected as the company investigates the incident.
Anubis ransomware combines encryption with permanent data destruction via 'wipe mode.' With ~90 victims, it uniquely intensifies extortion pressure on healthcare and critical infrastructure by converting ransomware from recoverable to irreversible data loss.
Ransomware hit Coca-Cola's Fairlife dairy unit, halting U.S. production of milk and protein drinks. Production systems were compromised; Canadian ops unaffected and product safety confirmed.
Spirals, a new Rust-based ransomware, breached a South Asian IT firm in 24 hours after systematically disabling antivirus and 23 critical services including Veeam and VMware. Its precision and speed underscore urgent needs for faster threat detection and response capabilities.
Phishing and compromised credentials now drive 73% of ransomware attacks, replacing software exploits as the primary vector. Despite widespread MFA deployment, attackers favor these cheaper, more reliable human-centric tactics over technical exploitation.
US indicts Russian operators of ML.Cloud and Media Land—bulletproof hosting services used for ransomware, phishing, and cyberattacks targeting Americans. DOJ offering $10M for information leading to arrests.
US charges three Russians for running bulletproof hosting supporting ransomware gangs that caused $62M+ in damages. They provided infrastructure for command-and-control, payments, and anti-takedown measures.
OFAC sanctioned First VPN Service and a malware developer enabling ransomware attacks, blocking US assets and transactions. The enforcement targets criminal infrastructure providers rather than attackers themselves—a strategic shift in disrupting ransomware ecosystems.
The US sanctioned First VPN Service for enabling ransomware attacks against critical infrastructure—the first VPN OFAC has penalized—marking escalated enforcement against cyber attack infrastructure.
GigaWiper is a modular malware combining persistent C2 with on-demand destructive payloads like disk wiping and fake ransomware. Unlike traditional wipers, it lets attackers control when and how they destroy systems.