Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7
Tag: ransomware (33 articles)Clear

Ransomware gangs now exploit a Windows Task Host flaw to gain SYSTEM

CISA confirmed that ransomware groups are now exploiting a Windows Task Host privilege-escalation flaw that has been flagged as actively exploited since April. Tracked as CVE-2025-60710 and scored 7.8, it is a link-following weakness in the component that runs background scheduled tasks as SYSTEM: a local attacker with only basic user rights can use a junction on a user-writable path to make a SYSTEM-level task act on files it should not, escalating to full control. Microsoft patched it in November 2025, and it affects Windows 11 and Server 2025. Privilege escalation like this is exactly what ransomware operators need to disable defenses and spread after gaining an initial foothold.

Check
Confirm the November 2025 update for this flaw is deployed across Windows 11 and Windows Server 2025 systems, prioritizing any that still lack it, since ransomware crews are now using it.
Affected
Windows 11 and Windows Server 2025 systems missing the November 2025 patch (CVE-2025-60710); a local attacker with basic rights can escalate to SYSTEM, and ransomware groups are actively exploiting it.
Fix
Apply the patch, prioritize privilege-escalation fixes in your patching since they enable ransomware to spread, monitor for junction abuse and unexpected SYSTEM-level file operations, and limit local footholds through least privilege.

Akira ransomware reboots Windows into Safe Mode to switch off security tools

Huntress detailed an Akira ransomware intrusion that reached in through an exposed SonicWall VPN and then forced Windows into Safe Mode to disable defenses. Because Safe Mode starts only a minimal set of services, the endpoint detection tools and Microsoft Defender did not load, leaving the attacker free to run their encryptor. The twist is that Safe Mode also starves the system of virtual memory, and thirteen seconds after the reboot the encryptor ran out of memory and crashed, so files were not encrypted, though the attacker still stole data. The technique remains a useful evasion play worth detecting even when the payload fails.

Check
Alert on boot-configuration changes and Safe Mode boots, watch for security services stopping and tools added to the Safe Mode service list, and require multi-factor authentication on every VPN account.
Affected
Windows environments reachable through exposed or weakly protected VPNs; an attacker who gains access can reboot endpoints into Safe Mode to bypass endpoint detection and Defender before attempting encryption or theft.
Fix
Require multi-factor authentication on VPNs and alert on failed login bursts, monitor for msconfig and bcdedit changes and Safe Mode boot events, and run security tooling in Safe Mode where supported.

US and South Korea warn of Gunra ransomware exploiting Fortinet VPN flaws

A joint advisory from the FBI, CISA, the NSA, the Secret Service, and South Korean police warns that the Gunra ransomware group is exploiting known Fortinet VPN vulnerabilities to bypass multi-factor authentication and break into networks, targeting government agencies and critical infrastructure. Gunra, believed to be built on leaked Conti source code, runs a double-extortion model: it steals data before encrypting, using a custom tool to pull files from Microsoft OneDrive and SharePoint and moving large archives to a file-sharing service with utilities like RClone and 7-Zip. The final payload appends a distinct extension and drops a ransom note. The group has grown into a ransomware-as-a-service operation recruiting access brokers.

Check
Patch Fortinet VPN appliances to close the known flaws Gunra exploits, confirm multi-factor authentication cannot be bypassed on remote access, and review VPN logs for suspicious authentication.
Affected
Government and critical-infrastructure organizations running unpatched Fortinet VPNs; Gunra exploits the known flaws to bypass multi-factor authentication, steal data from cloud storage, and deploy ransomware across the network.
Fix
Patch and harden remote access, enforce phishing-resistant multi-factor authentication, monitor for mass data transfers to file-sharing services and tools like RClone, keep offline backups, and follow the advisory's indicators.

Qilin ransomware crews break in through a Palo Alto VPN authentication bypass

Arctic Wolf Labs investigated multiple intrusions in June that began by exploiting an authentication bypass in Palo Alto Networks PAN-OS and ended in Qilin ransomware. CVE-2026-0257 affects the portal and gateway components and lets an unauthenticated remote attacker establish a VPN session without valid credentials, but only where authentication override cookies are enabled alongside specific certificate configurations. That narrow precondition makes it easy to assume you are unaffected without checking. The flaw is patched. Because it grants VPN access rather than code execution, the intrusions look like ordinary remote logins at the start, which delays detection until ransomware is deployed.

Check
Confirm PAN-OS is patched against this flaw and check whether authentication override cookies are enabled with the certificate configurations that make it exploitable, since the precondition is easy to overlook.
Affected
Organizations running unpatched PAN-OS portal or gateway components with authentication override cookies enabled (CVE-2026-0257); attackers establish VPN sessions without credentials, and Qilin affiliates have used this for initial access.
Fix
Patch PAN-OS, disable authentication override cookies where not required, require multi-factor authentication on VPN access, and hunt for VPN sessions lacking a corresponding authentication event or coming from unexpected locations.

Coca-Cola's Fairlife halts US dairy production after a ransomware attack

Coca-Cola disclosed in a securities filing that a ransomware attack on its Fairlife dairy subsidiary has disrupted operations and temporarily suspended production across the United States. The company said Fairlife detected unauthorized access to some systems, including production-related systems, and that it activated incident response and business continuity plans, brought in outside experts, and notified law enforcement. It says product quality and safety were not affected, and Canadian operations continue. The full impact is still being investigated, and no ransomware group has been named. Ransomware at food and beverage producers has caused weeks-long shutdowns and empty shelves in past incidents.

Check
Manufacturers should review their ability to keep production running during a cyberattack, confirm that business and production systems are segmented, and test backups and incident-response and continuity plans against a ransomware scenario.
Affected
Manufacturers and food and beverage producers whose production depends on connected systems; a ransomware attack can force a full production halt even when product safety is unaffected, as with Fairlife's US suspension.
Fix
Segment production and business networks, maintain tested offline backups, enforce phishing-resistant MFA on remote access, rehearse recovery, and prepare business-continuity plans that keep critical operations running during a systems shutdown.

GodDamn ransomware uses a Microsoft-signed malicious driver to disable defenses

Symantec detailed GodDamn, a ransomware operation that disables endpoint defenses using PoisonX, a malicious kernel driver its developers managed to get signed by Microsoft, an unusual escalation over the more common tactic of abusing a legitimate vulnerable driver. In an early-June attack, the operators used AnyDesk for remote access and a credential-harvesting toolkit that pulls passwords from browsers, Windows Credential Manager, cached domain credentials, email clients, and network traffic, before deploying the ransomware. Alongside the signed driver, they ran a user-mode tool disguised as a Symantec product to blind security software. Symantec links GodDamn to a developer it tracks as Hyadina and says the group is actively improving its defense-evasion capabilities.

Check
Watch for bring-your-own-driver activity and processes masquerading as security products, audit remote-access tools like AnyDesk in your environment, and monitor for credential-harvesting across browsers and Windows credential stores.
Affected
Windows organizations where attackers gain a foothold; GodDamn uses a Microsoft-signed malicious driver to switch off endpoint defenses, harvests credentials broadly, then encrypts systems, making detection before deployment much harder.
Fix
Enable driver block lists and tamper protection, restrict who can load kernel drivers, tightly control remote-access software, enforce phishing-resistant MFA, and keep monitored offline backups so encryption stays recoverable.

Mount Royal University confirms attackers stole and then deleted its files

Mount Royal University in Calgary has confirmed that attackers breached its network in June, stole data from its file storage systems, and then deleted the files to hinder recovery, as the hackers now publicly claim the attack. The intrusion, detected around June 18, disrupted phones, the university website, and other systems. The affected storage held academic material such as assignments and research, but the university acknowledges some students and staff may have kept personal information there, and a separate departmental drive was also wiped. Mount Royal is notifying affected individuals and offering credit monitoring to current and recent employees, though not to students.

Check
Students and staff of Mount Royal University should watch for a notification, take up offered credit monitoring where eligible, and stay alert to phishing referencing the university or their information.
Affected
Mount Royal University students and staff whose academic and possibly personal data sat on the affected drives; the attackers both stole the data and deleted it, complicating recovery and raising extortion pressure.
Fix
Maintain tested, offline backups so deleted data can be restored, segment and monitor file storage, enforce phishing-resistant MFA, and prepare incident-response and communication plans for attacks that both steal and destroy data.

Anubis ransomware hides in legitimate remote-management tools after breaching via Citrix

Arctic Wolf detailed how affiliates of the Anubis ransomware group break in and stay hidden, drawing on intrusions across healthcare, finance, and manufacturing this year. Initial access came from stolen VPN credentials and from exploiting CitrixBleed 2, a NetScaler flaw that leaks session tokens from memory and lets attackers bypass multi-factor authentication. Once inside, the affiliates leaned on legitimate remote-management software such as ScreenConnect, Zoho Assist, and MeshAgent to blend in with normal IT activity, moving through networks with RDP and PsExec toward domain controllers, backups, and storage devices. They stole data using common cloud-transfer tools before encrypting anything, which is exactly where defenders have the best chance to catch them.

Check
Patch NetScaler against CitrixBleed 2 and terminate all active sessions afterward, then audit your environment for remote-management tools like ScreenConnect, Zoho Assist, or MeshAgent that IT did not deploy.
Affected
Organizations running unpatched Citrix NetScaler Gateways or reusable VPN credentials; Anubis affiliates use these to get in, then hide inside legitimate remote-management tools while stealing data ahead of encryption.
Fix
Patch CitrixBleed 2 and kill existing sessions, enforce phishing-resistant MFA on VPNs, allowlist approved remote-management tools and alert on any others, and watch for RMM installs and exfiltration tools clustering together.

Case study reveals US county paid $1 million to data-theft extortion group

A Ransom-ISAC case study, built from a leaked negotiation chat and the blockchain trail, reconstructs how a US government entity quietly paid about $1 million to an extortion group called Kairos to keep stolen files from being published. Notably, Kairos never encrypted anything: there was no locker and no decryption key, just theft and the threat to leak, with special pressure applied to a folder of prosecutors' records. The month-long negotiation fell from a $3 million demand to a $1 million payment. The case reflects a broader shift, with roughly half of recent extortion now skipping encryption entirely, since data theft alone provides enough leverage.

Check
Review whether you could detect the signs seen here: password-guessed logins, repeated failed logins, and large outbound transfers to burner file-sharing links, and confirm sensitive record stores are segmented and monitored.
Affected
Organizations holding sensitive records, especially smaller government bodies with limited resources; data-theft extortion needs no ransomware, only stolen files and the threat to publish, to force a large payment.
Fix
Enforce multi-factor authentication and alert on failed logins, segment and monitor sensitive record stores, watch for large outbound transfers, and treat any promise to delete stolen data as worthless.

Avalon malware framework bundles phishing, remote access, and CrownX ransomware

Blackpoint Cyber documented Avalon, a previously undocumented modular malware framework that pulls credential theft, lateral movement, remote access, backup disruption, and ransomware into one toolkit, with its ransomware component named CrownX. The attack starts with a spoofed legal-document email pointing to a password-protected archive on Proton Drive. Inside is an ISO image rather than a direct attachment, which helps it slip past email scanning, and opening a document-themed Windows shortcut inside the mounted image kicks off the infection chain. By combining evasive delivery with a full attack toolkit under one roof, Avalon lets operators run an intrusion from initial access through data theft to encryption.

Check
Alert staff to legal-themed emails that link to password-protected archives on cloud storage, and hunt for mounted ISO images spawning shortcut files and the follow-on scripts that behavior triggers.
Affected
Organizations whose staff can open ISO images and shortcut files delivered through cloud-hosted archives; Avalon then chains credential theft, remote access, and backup disruption into CrownX ransomware deployment.
Fix
Block or restrict automatic mounting of ISO images and execution of shortcut files from downloads, filter links to shared cloud archives, maintain tested offline backups, and train staff on legal-document lures.