Medusa Ransomware 500 Victims — What the CISA Advisory Means

Medusa ransomware 500 victims: CISA, FBI and HHS updated their advisory Aug 18. What changed, who's at risk, and how to cut your exposure.

Medusa ransomware 500 victims is now the official U.S. federal tally: CISA, the FBI and the Department of Health and Human Services updated their joint advisory on August 18, 2026, confirming the ransomware-as-a-service group has breached more than 500 U.S. critical infrastructure organizations since June 2021 — up from the 300-plus figure in their original…

Read More

PTC Windchill CVE-2026-12569 Extortion Hits Shell, Philips

Clops PTC Windchill CVE-2026-12569 Erpressung nennt Shell, Philips, GE und Fiserv als Opfer — Monate nachdem die Lücke gepatcht wurde.

The PTC Windchill CVE-2026-12569 extortion campaign run by the Clop ransomware group went fully public on August 12–13, when Clop named Shell, Philips, General Electric, Fiserv and roughly 45 other organizations on its leak site as victims of a data-theft operation running through the same PTC Windchill/FlexPLM flaw DIESEC has already covered twice this year.…

Read More

Microsoft Teams Vishing Ransomware Hits in 17 Hours

A Microsoft Teams vishing ransomware campaign, STAC4749, breached dozens of firms via fake IT-helpdesk calls, encrypting networks within 17 hours.

A Microsoft Teams vishing ransomware campaign has hit dozens of North American organizations since February 2026, using two-minute fake IT-helpdesk phone calls to gain a foothold that, in the fastest confirmed case, ended in full Chaos ransomware encryption within 17 hours of first contact. What Happened Security vendor Sophos tracked the campaign to a financially…

Read More

Stadler Rail Everest Ransomware: SFr10m Demand Refused

Stadler Rail Everest Ransomware: SFr10m Demand Refused

The Stadler Rail Everest ransomware incident shows what a mature extortion response looks like: the Swiss train manufacturer confirmed that the Everest group stole supplier technical data through a shared data-exchange platform and demanded roughly SFr10m (about $12.3M) — and Stadler refused outright, filing a criminal complaint instead of negotiating. What Happened Stadler Rail, an…

Read More

GodDamn Ransomware PoisonX Driver Kills EDR

GodDamn ransomware PoisonX driver

The GodDamn ransomware PoisonX driver is a Microsoft-signed kernel tool that ransomware operators use to silently kill EDR and antivirus processes before deploying encryption — and because the driver carries a legitimate Microsoft signature, standard driver-trust checks wave it straight through. What Happened Symantec disclosed on July 9, 2026 that a ransomware family called GodDamn…

Read More