Ransomware remains the most financially damaging category of cyber threat, with attackers encrypting critical data and demanding payment for its release. Modern ransomware operations function as organized businesses, often using double-extortion tactics that combine encryption with data theft. defend.network tracks ransomware campaigns daily, monitoring which groups are active, which sectors they target, and which vulnerabilities they exploit for initial access.
Infostealer malware targets Anthropic and Microsoft users; Aurora ransomware gang deploys Cursor AI; North Korean threat actors expand beyond IT into healthcare and sales.
Red Hat patches critical Keycloak account-takeover flaw; Microsoft releases 398 patches including one under active exploitation; WordlistLoader and SynkLoader malware families accelerate ransomware-adjacent payload delivery via ClickFix.
Microsoft Copilot Personal one-click data exfiltration flaws disclosed. MLflow and FUXA critical vulnerabilities exploited for cloud credential theft. Windows Task Host now actively exploited by ransomware gangs.
Kimsuky deploys offline AI for phishing and malware automation; StormEncryptor emerges from Medusa affiliate; Iran-linked actors target 12+ U.S. water systems via exposed PLCs.
SharePoint CVE-2026-50522 exploited to steal machine keys; WordPress flaws CVE-2026-60137 and CVE-2026-63030 chained for webshell deployment; Palo Alto PAN-OS abused by Qilin ransomware operators.
FakeGit campaign weaponizes 7,600 GitHub repositories to distribute SmartLoader malware. WordPress sites actively exploited via CVE-2026-60137/63030 chain within 72 hours of disclosure. SonicWall SMA1000 zero-days (CVE-2026-15409/15410) used in targeted attacks; Estée Lauder breach linked to Oracle E-Business flaw.
Two Scattered Spider members sentenced to 5.5 years for 2024 Transport for London attack. Microsoft releases record 570-CVE patch set. ClickLock macOS malware terminates apps until password stolen.
Microsoft patches record 622 flaws including two zero-days in Active Directory and SharePoint under active attack. SonicWall confirms exploitation of SMA1000 zero-days. GitHub supply-chain attack spreads 300 fake repositories with infostealer malware.
North Korean actors publish 108 malicious packages across npm, Packagist, Go, Chrome; Avalon modular framework combines credential theft with CrownX ransomware. U.S. government paid $1M extortion to Kairos group.
North Korean actors published 108 malicious packages across npm and other ecosystems; Linux kernel RCE affects Android; first documented LLM-automated ransomware attack observed.
Google and FBI disrupt 2M-device NetNut proxy network; Anubis ransomware actively exploits Citrix Bleed 2 (CVE-2025-5777); ToddyCat malware abuses Google APIs to hijack Gmail accounts; Microsoft 365 OAuth bypass attacks steal tokens in seconds.
Microsoft research exposes AI agent manipulation via poisoned tool descriptions; Langflow RCE (CVE-2026-33017) actively exploited for Monero mining; six critical shell-injection bypasses discovered in open-source AI coding agents.
Apple A12/A13 SecureROM exploited with unpatchable code execution; Gentlemen RaaS expands EDR-evasion toolkit targeting 400 processes; Fortinet FortiBleed now hits 86,644 devices. Klue OAuth breach spreads Salesforce credential theft to cybersecurity vendors.
F5 patched critical NGINX RCE (CVE-2026-42530). Microsoft disclosed active Windows clipboard-stealing malware spreading via USB worms since Feb 2026. INC ransomware claims 830+ victims; Salesforce data stolen through Klue OAuth breach by Icarus group.
Oracle PeopleSoft CVE-2026-35273 actively exploited by ShinyHunters targeting universities; Windows BitLocker bypassed via XML files; The Gentlemen ransomware claims 478 victims with worm-like spreading capability.
Microsoft released record 200 Patch Tuesday fixes including critical flaws; Veeam Backup & Replication RCE (CVE-2026-44963, CVSS 9.4) requires immediate patching; 73 GitHub repos remain compromised as Miasma supply-chain attack investigation continues.
Check Point VPN zero-day (CVSS 9.3) actively exploited since early May; Linux kernel use-after-free now has public exploit; NSO Group continues WhatsApp phishing despite federal court injunction.
Google Android zero-day (CVE-2025-48595) actively exploited; Gamaredon APT weaponizing WinRAR; WordPress Kirki plugin hijacking admin accounts. CISA adds Oracle WebLogic to KEV catalog.
Palo Alto PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) actively exploited; Dutch authorities arrest two hosting operators supporting Russian cyberattacks; Linux kernel CIFSwitch flaw allows privilege escalation.
Palo Alto PAN-OS GlobalProtect flaw (CVE-2026-0257) under active exploitation; CISA contractor exposed AWS GovCloud keys on GitHub; Linux kernel CIFSwitch privilege escalation disclosed.
Microsoft patched SharePoint RCE (CVE-2026-45659); CISA contractor exposed AWS GovCloud keys on GitHub; MuddyWater targeted nine organizations across four continents using DLL side-loading.
Critical supply-chain attacks via compromised npm/PyPI packages, Canvas ransomware disrupting education nationwide, and massive vulnerability patches (Microsoft 137, Adobe 52, Exim critical) require immediate response.
Critical supply chain compromise of Checkmarx Jenkins plugin, first AI-generated zero-day 2FA bypass exploit, and active Canvas education platform extortion campaign require immediate response.
Canvas ransomware disrupts universities nationwide; Ollama zero-day affects 300k+ servers; TCLBANKER targets financial platforms; critical infrastructure breached; supply-chain compromises detected.
Canvas learning platform compromised in extortion attack affecting hundreds of schools; supply-chain attacks hit JDownloader, Hugging Face, and Trellix; banking trojan TCLBANKER targets 59 financial platforms; critical ICS/OT breaches at water treatment plants.
Critical threats including TCLBANKER banking trojan, Canvas platform breach disrupting nationwide education, and active Ivanti zero-day exploitation require immediate response across financial, education, and government sectors.
Critical vulnerabilities in cPanel and MOVEit, widespread RMM-based phishing compromising 80+ organizations, and supply-chain malware in PyTorch Lightning demand immediate patching and credential rotation.
Critical Linux root access vulnerability added to CISA KEV with active exploitation confirmed. Multiple critical threats including cPanel mass-exploitation, source code breaches, and state-sponsored APT campaigns.
Critical cPanel RCE exploited for ransomware; Russian military harvesting Office tokens; 30K Facebook accounts compromised; Trellix source code breached; automated Azure OAuth attacks.
Critical vulnerabilities, state-sponsored token harvesting, large-scale phishing operations, and coordinated SaaS extortion attacks demand immediate defensive action across government and technology sectors.
Critical supply chain attacks via malicious Docker images and npm worms, state-sponsored credential theft campaigns targeting Microsoft Office, and destructive Lotus Wiper malware deployed against Venezuelan energy infrastructure require immediate response across all organizations.
Russian state-backed APT harvesting Microsoft tokens, 1,570+ Gentlemen ransomware victims, critical SD-WAN and RMM exploits, Windows Defender flaws—urgent patching required across infrastructure.
Critical vulnerabilities in Next.js, Cisco IMC, and Progress ShareFile actively exploited; $280M cryptocurrency theft attributed to North Korea; credential harvesting impacts 766 hosts
Critical supply chain attacks on LiteLLM and development tools, wiper attacks on medical device manufacturer, and RCE vulnerabilities in manufacturing systems demand immediate response.
Critical vulnerabilities in Oracle Identity Manager and Langflow actively exploited; Trivy supply chain attack escalates with CanisterWorm across 47 npm packages; Russian intelligence phishing campaigns compromise thousands.
Critical VMware ESXi vulnerability actively exploited by ransomware operators. BlackSuit group claims major U.S. healthcare breach. CISA adds 3 new CVEs. Microsoft patches Windows kernel zero-day. New PhishRelay kit enables real-time MFA bypass.
Subscribe free and never miss a threat briefing.