Okta Warns of Vishing Attacks Targeting Microsoft 365 Customers
Vishing campaign bypasses Microsoft 365 MFA through fake passkeys, compromising accounts in six industries. Okta's O-UNC-066 threat, active since April 2026, targets data extortion.
ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Latest cybersecurity ransomware news, analysis, and intelligence.
Vishing campaign bypasses Microsoft 365 MFA through fake passkeys, compromising accounts in six industries. Okta's O-UNC-066 threat, active since April 2026, targets data extortion.
Karen Vardanyan, 34, pleaded guilty to deploying Ryuk ransomware against U.S. companies and faces 15 years prison plus $1.1M+ restitution. His conviction represents another major victory against the now-defunct syndicate that operated through mid-2020.
Ransomware negotiator Angelo Martino was sentenced to 70 months for supplying BlackCat ransomware operators with victim intelligence, becoming the third security insider prosecuted for aiding threat actors and exposing critical vulnerabilities in the cybersecurity industry.
Armenian ransomware affiliate Vardanyan pleaded guilty for $15M ransom attacks, ordered to pay $1.1M restitution. Canada's CSE disclosed active offensive cyber operations against criminal networks.
China-linked Silver Fox masks the sophisticated Rust RAT MODBEACON behind simple fake-software distribution, using encrypted gRPC for command control—a contrast revealing upgraded capabilities.
Ransomware negotiator Angelo Martino was sentenced to 70 months for leaking clients' insurance limits and negotiation strategies to BlackCat operators, enabling attackers to maximize ransom demands. His betrayal demonstrates how insider threats can amplify ransomware attacks and the risks of corrupt
Ransomware negotiator Angelo Martino was sentenced to 70 months for orchestrating BlackCat attacks, exploiting insider knowledge of victims' insurance policies and negotiation strategies to maximize extortion payouts alongside two other cybersecurity insiders.
Israeli startup QIZ Security raised $17M in seed funding to address post-quantum cryptography governance across enterprises. The platform helps organizations discover, inventory, and remediate encryption vulnerabilities as they transition to quantum-resistant standards.
GodDamn ransomware exploits Microsoft-signed drivers to disable security software before encrypting networks. This BYOVD technique represents an alarming escalation, weaponizing legitimate software to evade enterprise defenses.
GodDamn ransomware uses Microsoft-signed drivers to disable security before encrypting systems. The Hyadina collective's attack demonstrates kernel-level defense evasion targeting enterprises across industries.
JadePuffer is the first autonomous AI ransomware requiring minimal human oversight. It performs reconnaissance, exploitation, and encryption while adapting to defenses—a new era of AI-enabled cybercrime.
Mexico's cybersecurity plan faces trial by fire hosting FIFA 2026, when the tournament becomes a magnet for ransomware, hacktivists, and disinformation. How the nation responds will shape its security credibility globally.
JadePuffer is the first autonomous LLM-driven ransomware attack, exploiting Langflow to steal data and demand ransom without human operators. This marks a dangerous inflection point in AI-driven cybercrime, with threat actors now operating at machine speed.
U.S. government paid $1M to Kairos extortionists who stole and threatened to publish sensitive data—without encryption. The case highlights a growing trend: data theft as standalone extortion.
Avalon combines credential theft, lateral movement, and backup disruption in a ransomware toolkit. Distributed via phishing, it enables rapid attacks—marking an evolution in ransomware-as-a-service operations.
The Gentlemen, a Qilin splinter from a commission dispute, became the second-most prolific RaaS in 18 months. They claimed 300+ victims and 10% of global ransomware incidents by mid-2026.
FortiBleed stole credentials from 430,000+ firewalls globally, directly fueling ransomware attacks by INC Ransom and Lynx families. The operation demonstrates how compromised network infrastructure enables large-scale enterprise extortion campaigns.
Medtronic confirmed a 9 million-record breach by extortion group ShinyHunters, exposing SSNs, medical data, and PII. The attackers demanded ransom via a dark web listing with an April 21 deadline.
FortiBleed compromised 73,000+ Fortinet firewalls linked to INC and Lynx ransomware groups. Attackers harvested credentials using packet-sniffing tools to fuel ransomware attacks.
InfernoGrabber, an AI-generated ransomware, runs entirely in browsers to steal data, encrypt files, and demand ransom without native payloads—proving frontier AI models can operationalize previously theoretical threats.
Microsoft accelerated its PQC transition to 2029 after quantum breakthroughs. Recent advances make breaking RSA-2048 encryption feasible now, requiring urgent infrastructure-wide cryptography upgrades.
Microsoft set a 2029 deadline for quantum-safe encryption on critical systems, responding to "harvest now, decrypt later" attacks where adversaries collect encrypted data now for future decryption. State-sponsored actors and criminal groups are already executing this strategy, stealing encrypted dat
Blackfield gang demands $2M from Nidec Corp after compromising its Taiwanese subsidiary—the second attack in 8 months. The breach threatens global supply chains for automotive, computing, and industrial motors.
Attackers are harvesting encrypted data today for decryption by quantum computers expected within 15 years. Post-quantum cryptography adoption is urgent to protect current credentials and systems before quantum machines break RSA and ECC encryption.
Education institutions faced 1,252 breaches in 2025, with 65% involving ransomware. The critical threat: vendor software vulnerabilities cascade across entire school ecosystems, compromising thousands of institutions simultaneously despite strong internal defenses.
Europe is ransomware's new epicenter with 684 attacks in early 2026—a 55% surge from 2025. This geographic shift from the US-dominated pattern signals criminals adapting after law enforcement disruption.
Mistic backdoor, linked to KongTuke IAB, targets insurance/education/IT sectors in ransomware attacks. In-memory execution with self-deletion and anti-forensics enables stealthy persistent access.
The 2026 FIFA World Cup in North America faces escalating cyber threats from phishing, ransomware, ticketing fraud, and DDoS attacks targeting fan accounts, staff, and tournament infrastructure across three nations. Cybercriminals and nation-state actors are exploiting the event's massive attack sur
International agencies dismantled Amadey and StealC malware networks. The operation recovered 27M credentials, restricted $47M in crypto, and disrupted ransomware and fraud infrastructure.
Mistic RAT, deployed by access broker Woodgnat, enables six major ransomware families. Using DLL sideloading, it establishes persistence for reconnaissance and lateral movement before ransomware deployment.