SentinelLABS found macOS.Gaslight, a DPRK-linked Rust backdoor that embeds 38 fake system messages to make AI malware-triage agents abort. It is the first implant built to attack the analyst’s LLM, not the sandbox.
Akira has stayed a top-tier ransomware operation into 2026 by hammering SonicWall SSL-VPNs via CVE-2024-40766, deploying within an hour and using BYOVD to bypass EDR.
Coca-Cola disclosed a ransomware attack on its Fairlife dairy subsidiary in a July 16 SEC filing, suspending all US production. No group has claimed it.
Arctic Wolf found 292+ fake GitHub repositories impersonating security and fintech brands to deliver a BoryptGrab-lineage infostealer, with payloads that rotate every 60 seconds.
Microsoft’s July 2026 Patch Tuesday fixed a record 570 flaws and three zero-days, two already exploited in AD FS and SharePoint identity infrastructure.
Qilin, formerly Agenda, was the most prolific ransomware-as-a-service of H1 2026 with 641 claimed victims, including the Asahi brewery attack.
In 48 hours the US, UK and EU indicted a bulletproof host and sanctioned VPN and cryptor sellers behind LockBit, Play and BlackSuit ransomware.
The Gentlemen ransomware weaponised a zero-day in Kontron’s ktapi.sys driver to gain kernel access and kill EDR from Microsoft, ESET, Palo Alto, and SentinelOne, researchers found.
Arctic Wolf says Anubis ransomware affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) and abusing legitimate RMM tools to breach networks, then deploying an irreversible data wiper.
A US government entity paid Kairos about $1 million to keep stolen files offline, a Ransom-ISAC case study shows. Kairos never encrypted a machine, it just threatened to publish.