Ransomware & Extortion
Microsoft Teams Vishing Ransomware Hits in 17 Hours
A Microsoft Teams vishing ransomware campaign has hit dozens of North American organizations since February 2026, using two-minute fake IT-helpdesk phone calls to gain a foothold that, in the fastest confirmed case, ended in full Chaos ransomware encryption within 17 hours of first contact. What Happened Security vendor Sophos tracked the campaign to a financially…
Read MoreStadler Rail Everest Ransomware: SFr10m Demand Refused
The Stadler Rail Everest ransomware incident shows what a mature extortion response looks like: the Swiss train manufacturer confirmed that the Everest group stole supplier technical data through a shared data-exchange platform and demanded roughly SFr10m (about $12.3M) — and Stadler refused outright, filing a criminal complaint instead of negotiating. What Happened Stadler Rail, an…
Read MoreGodDamn Ransomware PoisonX Driver Kills EDR
The GodDamn ransomware PoisonX driver is a Microsoft-signed kernel tool that ransomware operators use to silently kill EDR and antivirus processes before deploying encryption — and because the driver carries a legitimate Microsoft signature, standard driver-trust checks wave it straight through. What Happened Symantec disclosed on July 9, 2026 that a ransomware family called GodDamn…
Read MoreDragonForce Ransomware Hides C2 Traffic Inside Microsoft Teams Relay Servers
Ransomware operators found a backdoor into your network. It looks exactly like a Teams meeting. Symantec and Carbon Black disclosed that DragonForce ransomware affiliates deployed Backdoor.Turn — a Go-based implant that tunnels its command-and-control traffic through Microsoft Teams TURN relay servers. The malware obtains an anonymous Teams visitor token, uses a legitimate Microsoft relay for…
Read MoreYour Check Point VPN has a zero-day. Qilin ransomware is already using it.
Your Check Point VPN has a zero-day. Qilin ransomware is already using it. The vulnerability requires no stolen credentials, no phishing, no user interaction. It requires only that your VPN still supports a protocol from 2005. CVE-2026-50751, disclosed on June 8, is an authentication bypass in Check Point Remote Access VPN and Mobile Access. The…
Read More
