Ransomware

CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Russian-speaking Aurora ransomware group leveraged Cursor AI coding assistant to conduct hands-on exploitation against 10 targets between April and May 2026.
Cybersecurity
Boston Scientific Cyberattack Disrupts Manufacturing and Shipping
August 25 cyberattack hit Boston Scientific's on-premises IT, disrupting manufacturing, order processing, and some cardiac monitor remote activations.
CVE Vulnerability Alerts
FulcrumSec Claims 86GB Manchester Airports Data Breach
FulcrumSec claims theft of 86 gigabytes from Manchester Airports Group, exposing booking data for 8.7 million customers from a third-party database breach.
Application Security
McKesson Breach: ShinyHunters Demands $55M for 284M Records
ShinyHunters demands $55 million for 284 million McKesson records containing PHI, prescriptions, and billing data; threatens release by September 1.
Cybersecurity
Slovenian Casino Operator Hit Resumes After Three-Day Shutdown
Hit casino operator reopened six Slovenian and Bosnian casinos after a three-day cyberattack shutdown, with gaming functions and loyalty systems still offline.
Cybersecurity
Berlin Refuses Rhysida Ransom as Group Claims 5.7TB Data Theft
Rhysida ransomware group demanded 30 bitcoin for 5.7 terabytes of Berlin state data, but Governing Mayor Kai Wegner flatly refused to negotiate or pay.
CVE Vulnerability Alerts
TerminalFix Campaign Uses Reverse Tunnels in ClickFix-Style Attacks
TerminalFix deploys multistage PowerShell attacks incorporating reverse tunnels into victim networks, using ClickFix social engineering to trick users.
Cybersecurity
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
U.S. and South Korean intelligence agencies warn Gunra ransomware exploits Fortinet firewall flaws alongside a previously undocumented MFA bypass technique.
Application Security
SharePoint RCE CVE-2026-55040 First Confirmed Ransomware Exploit
CISA confirms ransomware operators exploit a CVSS 9.1 SharePoint Server RCE requiring no authentication and granting administrator access worldwide today.
CVE Vulnerability Alerts
Metabase Zero-Day SQL Injection Exploited Against Framework, Tally
Metabase confirmed an exploited CVSS 10.0 zero-day SQL injection vulnerability that let attackers access customer data at Framework, Tally, and LexisNexis.

Threat actors