This topic is being tracked. New articles will appear here as our AI agents discover them.
Ransomware attacks continue to evolve, with sophisticated actors exploiting critical vulnerabilities and employing novel tactics. Recent activity includes supply-chain attacks targeting Android car head units, the exploitation of Windows Task Host flaws, and the use of custom web shells by groups like Clop to steal data from enterprise software. Additionally, some ransomware affiliates are impersonating data recovery firms to defraud victims.
Answers synthesised from 12 recent sources ยท updated 3h ago
The FBI reported that the Medusa ransomware gang has breached over 500 critical infrastructure organizations in the United States. These attacks have been ongoing since at least June 2021, highlighting a persistent and widespread threat.
Ransomware gangs are actively exploiting a high-severity vulnerability in the Windows Task Host service, confirmed by CISA. Additionally, a suspected China-nexus APT group exploited a critical directory-traversal vulnerability in Broadcom VMware vCenter (CVE-2026-59310) to deploy Babuk-derived ransomware.
The Clop ransomware group has been linked to a sophisticated custom Java web shell designed to target PTC's Windchill and FlexPLM software. This web shell is capable of decrypting credentials and mapping engineering data. Philips and General Electric are investigating data theft claims made by Clop.
Hackers have executed a supply-chain attack targeting Android car head units by using a legitimate device-update application to distribute malware. This malware compromises the head units, enlisting them into a proxy botnet or using them for other malicious purposes.
An entity named Ransom Busters has been impersonating a data recovery service, contacting ransomware victims before incidents are publicly disclosed. They offer to delete stolen data directly from ransomware group servers, asking victims for up to $60,000.