Ransomware Surges, Zero-Days Emerge, AI Fuels Attacks
This daily cybersecurity summary highlights a significant increase in ransomware attacks, particularly targeting European supply chains, with a 55% surge reported. The ransomware ecosystem is fragmenting, with new groups emerging rapidly. Government agencies are also experiencing daily ransomware incidents, though some have successfully resisted demands. A critical Windows zero-day, 'LegacyHive,' has been patched by 0Patch, granting local attackers SYSTEM privileges. SonicWall SMA devices are vulnerable to zero-day exploits leveraged by the Inc Ransomware group, allowing for command execution and malware deployment. The AI-powered ransomware 'JadePuffer' is now deploying 'ENCFORGE' to target and destroy machine learning models, exploiting critical vulnerabilities in Langflow. The healthcare sector remains vulnerable, with Craneware experiencing a data breach, underscoring supply chain risks. In the UK, 26% of businesses have faced supply chain attacks, with many continuing to work with insecure suppliers. On the defensive front, Cisco has released open-weight AI models, 'Antares,' for code analysis to aid in vulnerability detection. However, attackers are also leveraging AI, with an exposed server revealing an AI-powered phishing toolkit targeting Windows users in Mexico. Furthermore, China-aligned APT groups are integrating public AI tools into espionage campaigns, compromising systems in Thailand, Afghanistan, and Taiwan. Defenders should review behavior-based detection, attack surface management, and credential rotation strategies in light of these evolving threats.
Jul 21, 2026
10 articles (4 new, 6 updated)
1 Critical 6 High
CyberattackData BreachMalwarePhishingPolicy and Compliance +6 more