Cisco Talos warns of Cisco FMC vulnerabilities actively exploited in the wild. Attackers chain CVE-2026-20079 and CVE-2026-20316 to deploy ransomware.
Related Posts:
OnePlus Session Takeover Vulnerability Exposes Android Data
NVIDIA Patches Triton Inference Server Vulnerabilities
Apache Artemis Vulnerabilities Demand Immediate Action
The post Cisco FMC Vulnerabilities Actively Exploited in the Wild appeared first on Daily CyberSecurity.
When a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one of the sneakiest tracking tricks on the web.
Meanwhile, the intelligence agencies of the "Five Eyes" (not Five Guys) have got together and published advice on how companies should communicate after
When a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one of the sneakiest tracking tricks on the web.
Meanwhile, the intelligence agencies of the "Five Eyes" (not Five Guys) have got together and published advice on how companies should communicate after a cyber attack. The summary? For the love of God, stop calling every breach "sophisticated."
All this and more in episode 484 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.
CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business.
Read more in my article on the Fortra blog.
CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business.
Read more in my article on the Fortra blog.
Recent Node.js malware attacks target global firms. Attackers deploy Node.js malware using trusted runtimes and smart contracts to evade detection.
Related Posts:
Pegasus Spyware Hits Serbian Student Activist via Zero-Click iMessage
Python NodeStealer Adds Keylogging and Screen Capture Spyware
Packagist Themes iOS Spyware Steals Crypto Wallet Seeds
The post Node.js Malware Attacks Target Tech and Finance Sectors appeared first on Daily CyberSecurity.
Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web.
When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out this exact threat against Berlin after local authorities refused to pay a thirty Bitcoin ransom.
At the end of August, Berlin’s state government confirmed
Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web.
When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out this exact threat against Berlin after local authorities refused to pay a thirty Bitcoin ransom.
At the end of August, Berlin’s state government confirmed it was dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included.
Rhysida claimed it stole 5.79 TB of data, covering around 1.44 million files. The alleged dataset includes:
Personal data: 12,076 individuals, 16,389 email addresses, 11,963 phone numbers and 148 IBANs.
Sensitive records: more than 5,000 personnel files, more than 5,000 administrative-offence files, payroll data and leadership information.
Credentials: plaintext passwords and credentials for systems including GebäudAtlas, the ePayment PAYONE database and Z_ADMIN accounts.
Government and legal material: disciplinary proceedings, court cases, supervisory documents, NDA records and Bundesrat committee protocols.
Classified information: data related to classified-material handling and documents allegedly containing state secrets.
Critical infrastructure: vulnerability analyses concerning Berlin’s water supply.
Identity documents: passports and ID cards from personnel records.
Other material: contracts, financial documents, HR records, infrastructure files, health data, password stores and SQL/PST archives.
The group also claimed that the material could involve violations of GDPR, German classified-information rules, criminal law and KRITIS/BSIG requirements. These are Rhysida’s claims and have not been independently verified.
The scale of the breach is staggering. Investigators are now looking at roughly 1.4 million files containing personal details of civil servants, internal infrastructure records, and critical government data.
The fallout goes far beyond routine data theft. Investigative journalist Lars Winkelsdorf pointed out the gravity of the situation on social media.
Die absolute Vollkatastrophe ist eingetreten
Dieses Datenleck ist schlimmer als alle bisherigen Terroranschläge zusammen 1/xhttps://t.co/epU4mCYgew
“In addition to LKA documents related to investigations, the files also include plans concerning national defense—ranging from the federal government’s secret communication channels in the event of an apocalypse to defense-related companies and emergency plans developed by government agencies,” Winkelsdorf wrote.
Exposing crisis response plans and secret communication channels turns a financial shakedown into a national security headache.
Worse still, the leaked material includes files concerning chemical, biological, radiological, and nuclear threats.
“Among the published files is a folder titled “AG CBRN-Rahmenplanung.” CBRN stands for chemical, biological, radiological and nuclear threats,” notes the Euronews report
Having that kind of operational data floating around public forums gives hostile actors a blueprint for disaster.
Refusing to pay ransoms is the right policy, but it rarely stops the bleeding once the network is compromised. Governments keep treating cybersecurity like an IT expense rather than an existential line of defense.
Until boards start treating network segmentation with the same seriousness as physical security, we will keep watching expensive countdown timers tick down to zero.
Berlin’s state government announced the launch of a crisis response after the threat actors published the stolen data.
“A central crisis unit will oversee the review, verification and assessment of the leaked data and support efforts to inform affected citizens and businesses, said the city.” Reuters reports.
The Gentlemen ransomware, run by GOLD SHERWOOD, encrypts networks in under 24 hours. See the affiliate playbook and how to defend against it.
Related Posts:
PHP Web Server Rootkit Targets F5 BIG-IP Devices
StreamRat Banking Trojan Targets Spanish Android Users
Silver Fox Fake Software Installers Disable Windows Defender
The post The Gentlemen Ransomware Deploys in Under 24 Hours appeared first on Daily CyberSecurity.
The Gentlemen ransomware operation has been linked to a previously undocumented, cross-platform command-and-control framework named TukTuk, alongside EDR-disabling tooling, DLL sideloading research, and datasets apparently stolen from technology and healthcare organizations. Analysis of a Finland-hosted server identified what researchers assess as the complete TukTuk development project, providing an unusually detailed view into the group’s post-compromise capabilities. […]
The post The Gentleme
The Gentlemen ransomware operation has been linked to a previously undocumented, cross-platform command-and-control framework named TukTuk, alongside EDR-disabling tooling, DLL sideloading research, and datasets apparently stolen from technology and healthcare organizations. Analysis of a Finland-hosted server identified what researchers assess as the complete TukTuk development project, providing an unusually detailed view into the group’s post-compromise capabilities. […]
Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft.
Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” a
Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft.
Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included.
Rhysida claims it stole 5.79 TB of data, covering around 1.44 million files. The alleged dataset includes:
Personal data: 12,076 individuals, 16,389 email addresses, 11,963 phone numbers and 148 IBANs.
Sensitive records: more than 5,000 personnel files, more than 5,000 administrative-offence files, payroll data and leadership information.
Credentials: plaintext passwords and credentials for systems including GebäudAtlas, the ePayment PAYONE database and Z_ADMIN accounts.
Government and legal material: disciplinary proceedings, court cases, supervisory documents, NDA records and Bundesrat committee protocols.
Classified information: data related to classified-material handling and documents allegedly containing state secrets.
Critical infrastructure: vulnerability analyses concerning Berlin’s water supply.
Identity documents: passports and ID cards from personnel records.
Other material: contracts, financial documents, HR records, infrastructure files, health data, password stores and SQL/PST archives.
The group also claims that the material could involve violations of GDPR, German classified-information rules, criminal law and KRITIS/BSIG requirements. These are Rhysida’s claims and have not been independently verified.
The timing makes this attack especially sensitive. Berlin will elect its state parliament on September 20, less than a month after the breach, so an attack on government systems just before the vote was bound to raise questions. Interior Senator Iris Spranger said the election remains secure and that, so far, the attackers haven’t taken any election-related data. Security officials support that assessment.
Broadcaster RBB first reported on Thursday that Berlin had received ransom demands.
“The state of Berlin will not submit to extortion,” Berlin Mayor Kai Wegner and Berlin’s interior senator, Iris Spranger, said in a joint statement on Friday, before the ransomware group claimed the attack on their Tor data leak site.
That position follows long-standing advice from US federal agencies, which warn that paying a ransom doesn’t guarantee data recovery and can encourage more attacks. Saying no to the ransom is one thing; dealing with the consequences if the attackers publish the stolen data is another.
Berlin first disclosed the compromise on August 17, isolating the Senate Department for Mobility, Transport, Climate Protection and Environment along with a second department from the network. Forensic investigators later found the actual data exfiltration happened earlier than the public disclosure, sometime between August 7 and August 12, with the affected department having flagged an initial outflow internally on August 7, a full week before the network got cut off. That gap between first internal detection and actual network isolation is the kind of detail that tends to get scrutinized hardest once the immediate crisis passes.
Rhysida isn’t a new name to anyone tracking ransomware against government targets. The group has claimed roughly 280 victims since emerging in 2023, according to tracking services cited by Reuters, including nine in Germany alone and headline targets like the British Library and Chile’s army. Roughly half its victims sit in the US, with the UK, Canada, and Italy rounding out the next tier, a spread that suggests Rhysida isn’t picking targets based on geography so much as opportunity.
A joint advisory from CISA, the FBI, and the Multi-State Information Sharing and Analysis Center, first published in November 2023, lays out exactly how Rhysida typically gets in: compromised VPN credentials at organizations without multi-factor authentication, exploitation of the Zerologon vulnerability that Microsoft patched back in 2020, and old-fashioned phishing. None of those entry points are exotic or new, which is precisely the point; Rhysida doesn’t need novel techniques when so many organizations still haven’t closed gaps that have been publicly known for years.
Berlin reconnected all Senate departments to the network on August 23, but forensic teams are still checking the systems. The state’s data protection commissioner and Germany’s federal cybersecurity agency, the BSI, are following the investigation.
As of publication, neither Berlin’s data protection office nor the Senate Chancellery had given specific advice to the roughly 12,000 people whose data Rhysida claims to have stolen. If you’re among them and haven’t received any official message yet, don’t assume that means you’re safe. Investigators are still working to establish exactly what the attackers accessed and took.
PaperCut confirms a NG/MF vulnerability exploited in the wild. Restrict server access now and apply the emergency patch for versions 25 and 26.
Related Posts:
Critical MongoDB Security Vulnerabilities Require Immediate Patching
CVE-2026-73125: Ebyte NA111-M Flaws Let Attackers Fully Compromise the Device
D-Link DIR-X1860Z Flaw Lets Attackers Change the Admin Password Without Login
The post PaperCut NG/MF Vulnerability Exploited in the Wild, Emergency Patch Released appeared first on Daily Cyb
A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify stolen corporate data, identify regulatory risk. Founded on April 4, 2026, TITAN has been active since May and has listed 24 alleged victims across 10 countries. Italy accounts for 10 published victims, followed by Czechia with […]
The post TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation appeared fir
A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify stolen corporate data, identify regulatory risk. Founded on April 4, 2026, TITAN has been active since May and has listed 24 alleged victims across 10 countries. Italy accounts for 10 published victims, followed by Czechia with […]
A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine countries between April and July 2026, using the AI coding assistant Cursor to plan intrusion activity and Active Directory escalation. The exposed server offered an unusually complete view of a ransomware affiliate’s operational workflow. It contained victim-specific directories, shell history, […]
The post Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Orga
A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine countries between April and July 2026, using the AI coding assistant Cursor to plan intrusion activity and Active Directory escalation. The exposed server offered an unusually complete view of a ransomware affiliate’s operational workflow. It contained victim-specific directories, shell history, […]
The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more.
Read more in my article on the Fortra blog.
The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more.
Read more in my article on the Fortra blog.
Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability.
Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack many companies, then publish the victims’ names if they refuse to pay. The group claims it has targeted more than 40 organizations through a vulnerability in PTC’s Windchill and FlexPLM platforms, which manufacturers and engineering companies use to manage product and design data.
CVE-2026-
Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability.
Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack many companies, then publish the victims’ names if they refuse to pay. The group claims it has targeted more than 40 organizations through a vulnerability in PTC’s Windchill and FlexPLM platforms, which manufacturers and engineering companies use to manage product and design data.
CVE-2026-12569 (CVSS score of 9.3) is a critical remote code execution (RCE) vulnerability in PTC Windchill PDMlink and PTC FlexPLM. An attacker can exploit this vulnerability through the deserialization of untrusted data. The flaw impacts all CPS versions and Windchill and FlexPLM releases prior to 11.0 M030.
German police reportedly warned organizations directly that attacks were coming, which tells you the exploitation window here wasn’t exactly subtle to security researchers watching it unfold.
Cl0p group’s tooling for this campaign goes well beyond a basic web shell. Security firm ReliaQuest found the group deployed a custom implant built for full data theft on its own, no additional tools required to actually pull data out once inside.
A class loader like that turns a single web shell into an open-ended backdoor, useful for lateral movement, ransomware deployment, or just quietly sitting there for months.
“ReliaQuest identified the web shell as a fully equipped extortion platform: it maps sensitive vault data, decrypts every credential in the Windchill keystore, and includes a custom Java class loader that lets Clop execute any additional code inside the application process, extending the shell into an unlimited backdoor for follow-on activity such as lateral movement, ransomware, or persistence.” reads the report published by ReliaQuest. “The web shell gives attackers a direct path to credential theft and large-scale data exfiltration, with no additional tooling required. Unlike generic command shells, this implant decrypts credentials, delivers malware, and maps stored files for exfiltration.”
Cl0p’s naming strategy followed its usual slow build. The group initially posted partial company names on its leak site, then switched to full names starting August 12, and the victim count has climbed steadily since. For each organization, the listing includes what type of data got stolen and roughly how much, ranging anywhere from a single gigabyte up to multiple terabytes depending on the target.
The stolen data includes databases, project files, backups, engineering documents, blueprints, diagrams and corporate files, as well as images.
The victim list reads like a cross-section of major manufacturing and industrial names: Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, and Largan Precision, the company that supplies camera lenses for Apple’s devices. Researchers noticed that GE was on the list briefly before quietly disappearing from Cl0p’s site, a move that usually signals either a ransom payment or at least resumed negotiations behind closed doors. Shell, Philips, Fiserv, and GE have all publicly acknowledged awareness of the claims and said they’re investigating, though none has confirmed a significant breach so far.
None of this is a new pattern for Cl0p specifically; it’s the same mass-exploitation-then-extortion model the group has run repeatedly against Oracle E-Business Suite, MOVEit, Cleo, and GoAnywhere over the past few years. What’s different this time is the target: enterprise PLM software sits deep inside manufacturing supply chains, holding the exact kind of engineering data that competitors and nation-states alike would pay real money to see.
If your organization runs Windchill or FlexPLM and hasn’t checked for this specific CVE yet, that’s the item to move to the top of today’s list.
Ransomware remains one of the most disruptive cyber threats organizations face. Companies have strengthened their cyber defenses over the years, but attackers in 2026 have become faster, more targeted, and increasingly reliant on AI, forcing the need for a change in how organizations approach cyber resilience.
From the rise of AI-enabled attacks and extortion-only campaigns to growing concerns around third-party risk, several trends have emerged over the past several mo
Ransomware remains one of the most disruptive cyber threats organizations face. Companies have strengthened their cyber defenses over the years, but attackers in 2026 have become faster, more targeted, and increasingly reliant on AI, forcing the need for a change in how organizations approach cyber resilience.
From the rise of AI-enabled attacks and extortion-only campaigns to growing concerns around third-party risk, several trends have emerged over the past several months that are reshaping the ransomware landscape and raising new challenges for enterprise security leaders.
Ransomware attacks today are increasingly designed to disrupt business operations, steal sensitive data, and apply pressure far beyond an organization’s IT environment. Those developments signal that CISOs need to look beyond traditional cybersecurity controls to address operational resilience as well.
Ransomware has become a business disruption strategy
Ransomware has traditionally followed a straightforward model: Attackers encrypt systems and demand payment in exchange for a decryption key.
But today’s attacks are far more complex. Many ransomware groups now combine operational disruption with data theft, extortion, and reputational pressure. Instead of simply locking organizations out of their systems, attackers steal sensitive information before encrypting systems, creating multiple opportunities to pressure victims into paying.
Some campaigns have moved beyond encryption altogether. Rather than deploying ransomware, threat actors exfiltrate sensitive data and threaten to publish it or contact customers, partners, or regulators unless payment is made. These extortion-only attacks are often faster to execute, more difficult to detect, and capable of creating significant business disruption even when systems remain operational.
For IT leaders, this approach changes the conversation. The question is no longer whether systems can be restored. Now the question lies in whether the organization can continue operating while still protecting customer trust, regulatory obligations, and critical business relationships.
AI is changing both sides of the cybersecurity equation
AI expands the volume of valuable enterprise data by increasing the number of connected systems and introducing new third-party dependencies. At the same time, attackers are leveraging AI to accelerate phishing campaigns, identify exposed assets, and make scams that manipulate employees into revealing sensitive information more convincing and difficult to detect. This creates an environment where both defenders and attackers have access to increasingly sophisticated capabilities.
AI is also expanding the number of potential entry points attackers can target. Organizations are rapidly deploying generative AI assistants, integrating large language models into internal workflows, and connecting AI applications to enterprise data repositories. Each new integration introduces additional identities, APIs, and permissions that must be secured.
Without strong governance, these tools can inadvertently expose sensitive information or create new pathways for attackers to exploit. As AI adoption accelerates, CISOs should inventory where AI is being used, understand what data those systems access, and ensure security controls evolve alongside innovation. Technology leaders should evaluate not only how AI systems improve operations but also how these same systems affect identity management, data governance, access controls, and incident response planning.
Third-party risk expands the threat landscape
Enterprise organizations rarely operate in isolation. Cloud providers, software vendors, managed service providers, and AI platforms all have varying levels of access to corporate systems and sensitive information. As organizations become more interconnected, attackers increasingly view trusted third parties as potential entry points.
This means ransomware preparedness extends beyond internal infrastructure. Vendor risk assessments should evaluate cybersecurity maturity, incident response capabilities, and contractual obligations around breach notification. Organizations should also understand how quickly business partners can detect, contain, and communicate cyber incidents, particularly when shared systems or data are involved. A resilient security strategy depends on protecting your own environment and understanding the risks introduced by the broader technology ecosystem.
Cyber resilience has become a board-level priority
Ransomware is no longer viewed solely as an IT issue. Extended outages can interrupt revenue, halt operations, affect customer service, damage brand reputations, and trigger regulatory scrutiny. As cyber incidents become more consequential, boards are asking different questions. Rather than focusing exclusively on security tools, they want to understand recovery capabilities, operational dependencies, and the organization’s ability to maintain business continuity during an attack.
This shift places CIOs and CISOs in more strategic roles. In addition to overseeing technology and cybersecurity, they are increasingly responsible for helping executive leadership understand cyber risk in business terms. That includes communicating the potential operational impact of ransomware, prioritizing technology investments based on enterprise risk, and ensuring cybersecurity aligns with broader business resilience objectives.
Recovery time objectives, business continuity planning, and executive communication protocols are becoming just as important as endpoint protection and network monitoring. Organizations that regularly test recovery procedures, validate backup integrity, and conduct simulated cyber incident exercises with executive leadership are often better positioned to respond effectively when an incident occurs.
What CIOs and CISOs should prioritize now
While no organization can eliminate cyber risk entirely, several foundational practices can strengthen resilience against ransomware and improve an organization’s ability to respond when an incident occurs.
Technology leaders should prioritize the following:
Maintain and test offline backups. Store critical data in encrypted, offline environments and regularly test restoration procedures to ensure systems can be recovered quickly if production environments are compromised.
Strengthen identity and access controls. Require multifactor authentication for privileged accounts, limit employee access to only the systems and data they need to do their jobs and continuously monitor for unusual authentication activity.
Prioritize vulnerability management. Establish a disciplined patch management program to identify and remediate known vulnerabilities before they can be exploited by threat actors.
Develop a comprehensive incident response plan. Go beyond technical recovery by clearly defining executive decision-making, communications protocols, legal coordination, and stakeholder responsibilities before an incident occurs.
Evaluate third-party and AI-related risks. Regularly assess the security posture of cloud providers, technology vendors, and AI-enabled platforms to ensure security controls keep pace with an increasingly interconnected digital ecosystem.
Looking ahead
Ransomware is continuing to evolve faster than many organizations’ security strategies and the benchmark for victory can no longer be preventing every attack.
Future success will depend on treating ransomware as an enterprise resilience challenge rather than a purely technical problem. The organizations best positioned for the future won’t necessarily be those with the largest security budgets, but those that have embedded cyber resilience into every aspect of technology strategy. In an environment where both technology and threats continue to evolve rapidly, resilience will increasingly be measured by whether organizations can prevent every attack and by how effectively they can anticipate, respond to, and recover from the incidents that inevitably occur.
A threat actor calling itself “Ransom Busters” is targeting ransomware victims with a deceptive recovery offer, claiming it can restore encrypted files and delete stolen data from ransomware infrastructure. GuidePoint Security’s Research and Intelligence Team (GRIT) assesses with moderate confidence that the purported recovery service is actually a ransomware affiliate attempting to divert extortion payments […]
The post Ransom Busters Ransomware Affiliate Targets Victims With Fake Data Recovery
A threat actor calling itself “Ransom Busters” is targeting ransomware victims with a deceptive recovery offer, claiming it can restore encrypted files and delete stolen data from ransomware infrastructure. GuidePoint Security’s Research and Intelligence Team (GRIT) assesses with moderate confidence that the purported recovery service is actually a ransomware affiliate attempting to divert extortion payments […]
Akira attackers used Safe Mode to disable EDR before deploying ransomware, but memory issues caused the encryptor to fail.
An Akira ransomware affiliate broke into a company through an MFA-less SonicWall VPN on August 4, stole credentials and file shares, and then rebooted the compromised host into Safe Mode with Networking to kill the security tools before launching the encryptor. The plan worked on the EDR. It did not work on the ransomware.
“After gaining access via an exposed SonicWal
Akira attackers used Safe Mode to disable EDR before deploying ransomware, but memory issues caused the encryptor to fail.
An Akira ransomware affiliate broke into a company through an MFA-less SonicWall VPN on August 4, stole credentials and file shares, and then rebooted the compromised host into Safe Mode with Networking to kill the security tools before launching the encryptor. The plan worked on the EDR. It did not work on the ransomware.
“After gaining access via an exposed SonicWall VPN, an Akira affiliate rebooted the victim host into Safe Mode with Networking to defeat EDR, a first for this ransomware variant in our telemetry.” reads the report published by Huntress.
“In this incident, Safe Mode also broke the ransomware. In its stripped-down memory environment, the Akira process tree hit an out-of-virtual-memory failure seconds after launching.”
The attacker also added AnyDesk to the Safe Mode registry before rebooting, so their remote access survived the restart even though everything else didn’t. For ten minutes, the host had no working EDR and Defender’s real-time protection was down.
The attack followed Akira’s standard playbook almost exactly: VPN credential spray resolved into a successful login at 03:52 UTC, then two hours of quiet before the operator RDP’d to the domain controller, dumped all Active Directory users and computers with a PowerShell enumeration that disabled truncation to capture every group membership, archived mapped file shares with WinRAR using the same flags documented in previous Akira campaigns, and uploaded the data to an attacker-controlled S3 bucket using s5cmd. Exfiltration happened before any encryption attempt, which matters, because it means the victim can still be extorted even when the ransomware fails.
The ransomware failed because Safe Mode limited available memory. About 13 seconds after launching, akira.exe triggered multiple memory errors, apparently overwhelming the stripped-down environment and causing the encryption process to fail.
“akira.exe executed at 06:34:29 UTC and spawned its child-process burst at 06:36:21 UTC. About 13 seconds later, the host started throwing memory errors:” continues the report. “Safe Mode boots with a stripped-down environment and constrained virtual memory, and the Akira process tree appears to have starved it, getting the “Out of Virtual Memory” pop-up and the cascade of PowerShell hard errors line up exactly with the moment the payload tried to kick things off.”
Defender’s scheduled scan eventually detected akira.exe as Ransom:Win32/Akira.B!ibt, but couldn’t quarantine it while real-time protection was disabled in Safe Mode. The file was only removed after the attacker rebooted back to normal mode, restoring Defender’s protections, at which point their own anti-EDR move undid itself.
Huntress notes that Snatch and AvosLocker have abused Safe Mode for years, but this is the first time the company observed Akira using it. The more uncomfortable takeaway is that a host with more RAM or a larger page file might have given the encryptor enough memory to run successfully in Safe Mode. Akira’s developers could also reduce the payload’s memory footprint to make Safe Mode launches reliable, which means the same lucky failure won’t necessarily repeat.
The detection guidance is specific: alert on msconfig.exe or bcdedit activity, watch for Kernel-Boot Event ID 27 with a SAFEBOOT load option, Kernel-General Event ID 12 with BootMode=2, and third-party services stopping. Also watch for remote-access tools being added to the Safe Mode service registry, that’s the tell that the operator is planning to maintain access through the reboot.
“The takeaway is a little uncomfortable. While Safe Mode blinded our controls, it may also have prevented the encryption it was meant to enable. That’s a lucky side effect of the attacker’s own mistake in these circumstances, not a defence you can plan around.” concludes the report. “Ultimately, this could be a case of winning the battle, but not the war. It’s possible that a host with more physical memory or a larger page file might give akira.exe enough virtual memory to encrypt the endpoint in Safe Mode. Akria’s developers or affiliates could retool the encryptor to reduce its memory demands or make its Safe Mode launch sequence more reliable, meaning that the same failure may not occur in a future intrusion.”
A newly surfaced criminal AI service named MessiahGPT is being marketed on BreachForums as an unrestricted offensive model capable of generating ransomware, phishing kits, stealers, crypters, rootkits, and social-engineering content on demand. The Trellix Advanced Research Center has reported that this service operates through the domain messiahgpt[.]de and promotes an associated Telegram community, marking a […]
The post MessiahGPT Unrestricted AI Model Lets Hackers Generate Ransomware and Phis
A newly surfaced criminal AI service named MessiahGPT is being marketed on BreachForums as an unrestricted offensive model capable of generating ransomware, phishing kits, stealers, crypters, rootkits, and social-engineering content on demand. The Trellix Advanced Research Center has reported that this service operates through the domain messiahgpt[.]de and promotes an associated Telegram community, marking a […]
A newly surfaced criminal AI service called MessiahGPT is being openly marketed on BreachForums as a purpose-built offensive model that writes ransomware, phishing kits, stealers, crypters, and rootkits on demand, according to findings published by the Trellix Advanced Research Center.
The service runs a live platform at messiahgpt[.]de alongside an active Telegram community, and its operators are not being subtle about who they are selling to.
What makes MessiahGPT different from the endl
A newly surfaced criminal AI service called MessiahGPT is being openly marketed on BreachForums as a purpose-built offensive model that writes ransomware, phishing kits, stealers, crypters, and rootkits on demand, according to findings published by the Trellix Advanced Research Center.
The service runs a live platform at messiahgpt[.]de alongside an active Telegram community, and its operators are not being subtle about who they are selling to.
What makes MessiahGPT different from the endless stream of jailbreak prompts circulating in underground channels is its underlying claim. The operator says the model was not jailbroken at all, but trained from scratch with what they describe as zero ethical constraints: no Reinforcement Learning from Human Feedback, no Constitutional AI layer, and no internal concept of harm or illegality.
Tool page (Image Source: Trellix)
The advertised training corpus reads like a catalog of everything mainstream labs filter out: unrestricted manuals, dark web archives, leaked documentation, and raw internet scrapes with no post-filtering applied.
The listed architecture is a Mixture-of-Experts design with 128 experts, 16 of which are active per token. None of these technical claims can be independently verified from outside the platform, and researchers are careful to say so. What is verifiable is that the service is live, reachable, and being promoted on one of the most trafficked criminal forums on the internet.
The commercial model is aggressively low-friction. MessiahGPT offers 50 free queries with no registration at all, letting prospective buyers test output quality before spending anything.
Paid plans then start at roughly $8 per month, payable only in cryptocurrency with no KYC checks. That price point matters more than it might appear.
For under the cost of a streaming subscription, a low-skilled actor gains a tool that will reportedly produce complete, compilable malware and ready-to-deploy phishing kits capability that previously required either genuine development skill or a relationship with a malware-as-a-service vendor.
The use cases listed in the advertisement are explicit rather than euphemistic. Alongside ransomware and phishing kit generation, the operator promotes social engineering scripts, fraud and carding guides, data breach exploitation, physical attack planning, and chemical and explosive synthesis.
The listing even includes a benchmark comparison table pitting MessiahGPT against ChatGPT-4o, DeepSeek-V3 and Mistral-Large, positioning itself as the only model that returns usable output across every category the others refuse.
APEX AI Dark Web Advertisement (Image Source: Trellix)
That framing is a strong signal about the audience: these are buyers who have already hit refusal walls on commercial platforms and are shopping specifically for a model without them.
MessiahGPT is not operating in isolation. Trellix also tracked DarkGPT, a persistently advertised uncensored AI service circulating across multiple Russian-language Telegram channels, which offers bot access with three free queries before paid tiers kick in.
Its marketing openly promises full freedom to write malicious code and exploits without restrictions, custom hacker scripts tailored to the buyer, real-time “instant hacks” for complex scenarios, a 24/7 assistant, access to a hacker community, and what the advertisement literally brands as BlackHat AI uncensored power for darknet projects.
Whether DarkGPT is a genuinely fine-tuned local model or simply a jailbroken wrapper around a public LLM cannot be verified externally. What the repeated reposting across channels does indicate is durable demand: the operators are still spending on promotion, which suggests the revenue justifies it.
Between DarkGPT’s staying power and MessiahGPT’s custom-model ambitions, uncensored AI has become a standing product category rather than a novelty.
Researchers place both services within a broader 2026 shift toward the commercialization of criminal AI, where uncensored AI-as-a-service has moved from informal Telegram bots to dedicated platforms with versioned websites, demo channels, support communities, and tiered pricing.
Defenders should assume that phishing lures, ransomware variants and social engineering pretexts arriving in 2026 may be AI-generated, higher in volume, and cheaper to produce than ever.
Signature-based detection and template-matching phishing filters degrade quickly against machine-generated variation, making behavioral detection, strong identity controls and continuous user awareness training the more durable defenses.
Defenders should assume that phishing lures, ransomware variants and social engineering pretexts arriving in 2026 may be AI-generated, higher in volume, and cheaper to produce than ever.
Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks.
Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group previously relied on Medusa ransomware. StormEncryptor is written in C++ and encrypts files and adds the .encrypted extension, then leaves a !!!README_FIRST!!!.txt ransom note in each scanned directory. The change sugges
Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks.
Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group previously relied on Medusa ransomware. StormEncryptor is written in C++ and encrypts files and adds the .encrypted extension, then leaves a !!!README_FIRST!!!.txt ransom note in each scanned directory. The change suggests an evolution in the group’s ransomware operations.
“While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the CVE-2026-18577 authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026.” wrote Microsoft on X.
On August 2, 2026, the financially motivated cybercriminal actor tracked by Microsoft Threat Intelligence as Storm-1175 began deploying a new ransomware strain called StormEncryptor.
Storm-1175’s deployment of StormEncryptor marks the threat actor’s first activity observed by… pic.twitter.com/wNbchat8ZU
— Microsoft Threat Intelligence (@MsftSecIntel) August 7, 2026
Storm-1175 is known for fast ransomware campaigns that exploit newly disclosed vulnerabilities before organizations can patch them. In recent attacks, the group used tools such as AnyDesk and SimpleHelp for remote access, Advanced IP Scanner to map networks, and Mimikatz to dump LSASS credentials.
Microsoft says the attackers can move from initial access to data theft and ransomware deployment within days, highlighting the need for rapid patching and monitoring.
China-based actor Storm-1175 carries out fast, financially driven ransomware attacks by exploiting newly disclosed vulnerabilities before organizations patch them. The group targets exposed systems and quickly moves from initial access to data theft and ransomware deployment, sometimes within 24 hours. The financially motivated group mainly targets sectors such as healthcare, education, finance, and services across the US, UK, and Australia. The attackers often chain exploits, create new accounts for persistence, move laterally using remote tools, steal credentials, and weaken security defenses. Their speed and focus on unpatched systems make them highly effective.
Microsoft researchers report that the group quickly exploits newly disclosed flaws in web-facing systems to gain access. Since 2023, the group has targeted many platforms, including Microsoft Exchange, Ivanti, ConnectWise, JetBrains, and others. It often weaponizes vulnerabilities within days, or even one day, before organizations apply patches.
“Storm-1175 rapidly weaponizes recently disclosed vulnerabilities to obtain initial access.” reads the report published by Microsoft. “Since 2023, Microsoft Threat Intelligence has observed exploitation of over 16 vulnerabilities, including:
The attackers also chain multiple exploits to achieve deeper access, such as remote code execution, and have targeted both Windows and Linux systems. In some cases, the threat actor used zero-days even before public disclosure, showing advanced capabilities. By focusing on unpatched systems and acting fast, Storm-1175 maximizes impact and maintains a strong advantage over defenders.
Storm-1175 chains multiple exploits to gain deeper access, as seen in attacks on Microsoft Exchange where it moved from initial access to remote code execution. The group also targets Linux systems and has used zero-day flaws before public disclosure, showing advanced skills.
After gaining access, it installs web shells or remote tools, creates admin accounts, and moves laterally using tools like PowerShell, PsExec, RDP, and Cloudflare tunnels. It also abuses legitimate RMM tools and software like PDQ Deployer and Impacket to spread across networks. The attackers can deploy ransomware in as little as one day, highlighting their speed and efficiency.
U.S. and South Korean authorities warn about the growing Gunra ransomware threat as the operation expands its capabilities and affiliate network.
The post US, South Korea Warn of Growing Gunra Ransomware Threat appeared first on TechRepublic.