Ransomware

Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Keio Corporation confirmed a ransomware attack disrupted business systems over the weekend. Railway operations continued but administrative functions impacted.
Cybersecurity
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure
JadePuffer ransomware group used autonomous AI agents to delete Azure virtual machines, databases, and storage after hijacking service principals.
Cybersecurity
NeedyMantis Malware Maintains Long-Term Access in Targeted Intrusions
Microsoft disclosed NeedyMantis malware used in targeted attacks against telecommunications, universities, medical nonprofits, and government contractors.
DC Health Agency Exposes 400,000 Medicaid Beneficiary Records Online
Application Security
DC Health Agency Exposes 400,000 Medicaid Beneficiary Records Online
Washington D.C. Department of Health Care Finance exposed approximately 400,000 Medicaid beneficiary records through a misconfigured web portal accessible without authentication.
Cybersecurity
Ransomware Gangs Exploit Critical TeamCity Flaw Patched in July
CISA warned federal agencies that ransomware groups are actively exploiting a critical JetBrains TeamCity vulnerability patched in July 2026.
Application Security
Malicious npm Package indexed-btree Hides Payload in Runtime Code
indexed-btree npm package hides malicious behavior in application runtime code instead of lifecycle scripts, evading npm security controls, per Checkmarx researchers.
KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft
Cybersecurity
KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft
Previously undocumented Brazilian banking malware KREMLIN installs malicious extensions on Chrome and Edge, bypassing security checks to steal credentials and session tokens.
Application Security
GoldFactory and Mantax Otax Target Indonesian Android Bank Users
Two concurrent Android banking malware campaigns — GoldFactory's Gigabud trojan and Mantax Otax ransomware-spyware hybrid — target Indonesian users with credential theft and harassment.
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Russian-speaking Aurora ransomware group leveraged Cursor AI coding assistant to conduct hands-on exploitation against 10 targets between April and May 2026.
Cybersecurity
Boston Scientific Cyberattack Disrupts Manufacturing and Shipping
August 25 cyberattack hit Boston Scientific's on-premises IT, disrupting manufacturing, order processing, and some cardiac monitor remote activations.

Threat actors