Warlock Ransomware SharePoint Attacks

Warlock ransomware SharePoint attacks hit a water utility and a telecom provider. Symantec saw an EDR killer on 40 hosts in two hours. Patch and hunt.

Warlock ransomware SharePoint attacks have reached a water utility, a telecom provider, a regional government body and a university, according to Symantec and Carbon Black. The China-linked group still gets in through on-premises SharePoint, switches off endpoint protection on dozens of machines within about two hours, and then launches ransomware from a share that every…

Read More

McKesson Breach: How the Okta Vishing Attack Happened

An Okta vishing attack gave ShinyHunters access to McKesson's Salesforce and Snowflake data, followed by a $55 million ransom demand.

An Okta vishing attack — a phone call, not a piece of malware — is how the extortion group ShinyHunters claims it broke into US healthcare and pharmaceutical distribution giant McKesson. McKesson has confirmed unauthorized access to third-party applications and data exfiltration, but has not confirmed the attack path itself: according to ShinyHunters’ own account,…

Read More

Berlin Ransomware Attack: State Refuses to Pay

Berlin ransomware attack 2026 — Rhysida extortion of German state government network

A Berlin ransomware attack has put Germany’s capital in the position every public-sector CISO dreads: a confirmed data breach, a seven-figure ransom demand, and an election three weeks away. The ransomware group Rhysida claims it stole 5.79 terabytes from Berlin’s state administrative network and is demanding 30 Bitcoin, roughly €2.05 million, with a seven-day auction…

Read More

Medusa Ransomware 500 Victims — What the CISA Advisory Means

Medusa ransomware 500 victims: CISA, FBI and HHS updated their advisory Aug 18. What changed, who's at risk, and how to cut your exposure.

Medusa ransomware 500 victims is now the official U.S. federal tally: CISA, the FBI and the Department of Health and Human Services updated their joint advisory on August 18, 2026, confirming the ransomware-as-a-service group has breached more than 500 U.S. critical infrastructure organizations since June 2021 — up from the 300-plus figure in their original…

Read More

PTC Windchill CVE-2026-12569 Extortion Hits Shell, Philips

Clops PTC Windchill CVE-2026-12569 Erpressung nennt Shell, Philips, GE und Fiserv als Opfer — Monate nachdem die Lücke gepatcht wurde.

The PTC Windchill CVE-2026-12569 extortion campaign run by the Clop ransomware group went fully public on August 12–13, when Clop named Shell, Philips, General Electric, Fiserv and roughly 45 other organizations on its leak site as victims of a data-theft operation running through the same PTC Windchill/FlexPLM flaw DIESEC has already covered twice this year.…

Read More