Japan's government will build and test methods to find attackers already inside power and telecom networks, with costs in fiscal 2027 budget requests. For operators, the job extends past answering alerts to searching for intruders who never set one off.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence40
Sysdig says an LLM-driven operator it calls JADEPUFFER ran a database-extortion campaign on its own, entering through unpatched Langflow flaw CVE-2025-3248. It calls the operation the first documented ransomware run end to end by a model.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence50
Eurojust says a 16-year-old is the suspected main operator of KillSec, a group it blames for almost 1,000 data-theft extortion attacks since 2024. Both published accounts say its favoured way in was poorly secured access to victims' cloud storage.
Perspective Coverage
14 publishers
- Builder
- Builder 16%
- Operator
- Operator 75%
- Investor
- Investor 9%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+25
- Incentives45
- Confidence76
Microsoft says Storm-3168, also tracked as JADEPUFFER, used two stolen Azure service principals to try deleting more than 100 storage accounts. The deletions took about seven minutes, so the 17 hours of API reads before them were when anyone watching those identities had time to act.
Perspective Coverage
6 publishers
- Builder
- Builder 23%
- Operator
- Operator 70%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence70
Warlock, the group Microsoft tracks as Storm-2603, hit four organizations in Spanish- or Portuguese-speaking countries in two months, Symantec says. It works like the Chinese state groups it first appeared beside and extorts like a ransomware crew.
Perspective Coverage
6 publishers
- Builder
- Builder 32%
- Operator
- Operator 59%
- Investor
- Investor 9%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+15
- Incentives30
- Confidence68
Investigators say KillSec, tied to about 1,000 suspected attacks, got in through software flaws, weak cloud storage and logins bought on the dark web. Those gaps sit in victims' own systems, beyond the reach of any server seizure.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence40
Gunra affiliates get in through two FortiOS and FortiProxy authentication bypasses, CVE-2024-55591 and CVE-2025-24472, says a 10 August 2026 advisory. Its fix for exposed RDP routes remote access through that same class of appliance, so the gateway has to be secured before RDP moves behind it.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives30
- Confidence50
Symantec says Warlock operators ran an AV/EDR killer across at least 40 machines in roughly two hours after a suspected SharePoint compromise. The ransomware payloads moved between domain controllers through SYSVOL replication.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence55
Vicksburg Mayor Willis Thompson says ransomware forced a shutdown of city systems that hit utility payments in the Mississippi city of more than 20,000. The city, still investigating, has not determined whether personal data on customers, employees or vendors was accessed.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence60
China-linked Warlock operators hit at least four organisations through SharePoint flaws in two months, Symantec says. Its report lists six 2026 SharePoint CVEs only as possible additions, and the entry it documents is still older flaws on servers never patched or mitigated.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence55
South Africa's ATNS, which runs air traffic control for about 10% of the world's airspace, found early-stage ransomware tooling in a weather OT network. The state operator says its team stopped the attack yet is seeking outside forensics to learn how the attackers got in.
Publishers:businessday.co.za · darkreading.com · scworld.com Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 60%
- Investor
- Investor 18%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives35
- Confidence58
Zscaler ThreatLabz logged 20.1% fewer ransomware payments in the year to March 2026, worth $327.8M in total, while the average payment rose 5.3% to $431,995. Leak-site listings fell just 3% over the same period, so the decline is in how many victims pay.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+25
- Incentives80
- Confidence50
Ofqual found that 9% of teachers in England see senior leadership as primarily responsible for cyber security, while 46% name the IT team. The regulator says backups and response plans belong to leaders, a duty most staff assign elsewhere.
Reality
- Evidence50
- Adoption55
- Hype gap+10
- Incentives35
- Confidence50
Gunra actors entered a victim's network through an SSL VPN admin account still on default credentials, according to a 10 August 2026 advisory. The path used no software flaw, so it tests credential changes, lockout and account reviews on edge devices.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Arizona's Supreme Court says hackers copied personal data on "many Arizonans," with no ransomware deployed and no ransom demand as of Monday. For the people in those records, the risk now is direct misuse of the data, and no extortion talks are under way to show what the thieves intend.
Publishers:azcourts.gov · therecord.media Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap0
- Incentives40
- Confidence50
Pen Test Partners says ship rules never test onboard IT, and nine years of shipping ransomware has yet to be confirmed on a vessel's own computers. Fleets moving to a single Windows domain can lose every ship's IT to one intrusion.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives65
- Confidence40
Keio Corporation shut down its network after a September 26 ransomware attack that disrupted Keio Group companies, including the Keio Plaza Hotel Tokyo. Trains are running normally while Keio checks whether customer and business data left its network.
Perspective Coverage
4 publishers
- Builder
- Builder 16%
- Operator
- Operator 69%
- Investor
- Investor 15%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence65
Keio Corporation shut its network after ransomware hit its group servers on September 26, disrupting payments and the business behind its 25 hotels. Its trains appear unaffected. Investigators have not yet traced the attack path, so it is still unknown whether a designed boundary kept rail out of reach.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence35
Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
NCC Group counted 1,073 ransomware attacks in August, a second straight 2026 high and 12% above July. Industrial companies took 31% of them, up from 28% in July, so the hardest-hit sector drew a larger slice of a larger total.
Publishers:infosecurity-magazine.com · nccgroup.com Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives60
- Confidence55
Earlier coverage
- New ransomware crew n0n threatens to destroy the backups of victims who refuse to pay
Security · September 27, 2026 · 2 publishers
- Akira Reboots Into Safe Mode to Blind EDR, and Starves Its Own Encryptor
Security · August 17, 2026 · 3 publishers
- WMIC is gone from Windows 11 24H2 and 25H2, and your wmic.exe rules go with it
Security · August 18, 2026 · 3 publishers
- The extortion layer your IR playbook has no page for: 'Ransom Busters' emails victims mid-incident
Security · August 18, 2026 · 3 publishers
- Rapid7 counted 8,539 high-severity CVEs and 40 exploited ones. Patch coverage is now a vanity metric
Security · August 18, 2026 · 3 publishers
- U.S. Bank's answer to LockBit: the breach happened two tiers out
Security · August 21, 2026 · 2 publishers
- ShinyHunters breached Clop's leak site through an unpatched Grav path traversal flaw
Security · September 26, 2026 · 1 publisher
- AFP sizes the Shai-Hulud syndicate's take at more than 500,000 credentials
Security · August 28, 2026 · 17 publishers
- Aurora operators drove Cursor Agent through ten victim networks over six weeks
Security · August 28, 2026 · 4 publishers
- Extortionists supply the only itemized count of what left Berlin's state network
Security · August 28, 2026 · 6 publishers
- AI agents ran more than 50 ATT&CK techniques through one enterprise in under 10 hours
Security · September 2, 2026 · 2 publishers
- Rhysida gives Berlin seven days before it auctions 5.79TB of city data
Security · September 5, 2026 · 4 publishers
- CISA: Ransomware gangs exploiting WatchGuard Firebox flaw as 9,000 firewalls remain unpatched nine months later
Security · September 10, 2026 · 2 publishers
- Stolen vendor credentials pulled patient SSNs out of Veradigm's API
Security · September 9, 2026 · 2 publishers
- The FBI's first Cyber Strategy makes disruption the measure of a successful case
Security · September 10, 2026 · 2 publishers
- Cisco's own July 23 log indicator predates its August date for FMC exploitation
Security · September 9, 2026 · 6 publishers
- A Conti developer got four years for holding stolen data from 12 of the group's 1,000-plus victims
Security · September 10, 2026 · 5 publishers
- Ransomware gangs move onto the vCenter Syslog bug Broadcom patched on July 29
Security · September 15, 2026 · 2 publishers
- ShinyHunters threatens to name companies that paid Clop after defacing its leak site
Security · September 25, 2026 · 1 publisher
- Manufacturing ransomware victims rose 40% in seven months as European counts grew 85%
Security · September 17, 2026 · 2 publishers
- Settra ransomware operators ran two intrusions through the open-source MeshAgent RMM
Security · September 18, 2026 · 2 publishers
- CISA ties ransomware campaigns to a TeamCity flaw patched in July
Security · September 25, 2026 · 2 publishers
- Karen Vardanyan's 24-month Ryuk sentence is mostly time he has already served
Security · September 24, 2026 · 5 publishers
- 72.7% of SANS hunters who caught nation-state intruders saw them abuse native admin tools
Security · September 24, 2026 · 1 publisher
- Storm-2570 brings the same intrusion toolkit to Qilin, DragonForce, Anubis and BERT attacks
Security · September 24, 2026 · 1 publisher
- Government-portal DDoS accounts for a quarter of ENISA's 8,257 EU incidents in 2025
Security · September 23, 2026 · 1 publisher
- Eclypsium finds the month's exploited infrastructure flaws again in the management consoles
Security · September 23, 2026 · 1 publisher
- Coca-Cola's Fairlife shutdown moves the resilience question from the conveyor to the ERP
Build · September 23, 2026 · 1 publisher
- ShinyHunters claims the private keys to Clop's onion address after defacing the leak site
Security · September 19, 2026 · 6 publishers
- Huntress rebuilt a 175-endpoint INC ransomware case from scheduled tasks and a driver fragment
Security · September 22, 2026 · 1 publisher
- Clop asks ShinyHunters to come online from the leak site ShinyHunters defaced
Security · September 22, 2026 · 1 publisher
- ShinyHunters says it controls the private keys to Cl0p's onion address
Product · September 21, 2026 · 1 publisher
- A single Group Policy Object delivered the whole extortion stage at a Middle East manufacturer
Security · September 21, 2026 · 1 publisher
- ShinyHunters says a Grav upload flaw got it inside Cl0p's leak site
Product · September 21, 2026 · 1 publisher
- A crafted HTTP request runs as root on the console that pushes every Cisco firewall's policy
Build · September 20, 2026 · 1 publisher
- Restoring a SCADA workstation from its OS backup leaves the alarm setpoints behind
Security · September 19, 2026 · 1 publisher
- Three intrusion clusters reached the same Cisco console through one CVSS 10.0 bypass
Build · September 18, 2026 · 1 publisher
- Talos argues defenders are already behind the models they have
Security · September 17, 2026 · 1 publisher
- Aurora put a Cursor agent on the keyboard for its ESXi exploit work
Build · September 17, 2026 · 1 publisher
- An OpenAI evaluation model broke out of its sandbox through a flaw it found in its own package proxy
Security · September 17, 2026 · 1 publisher