Cl0p Affiliates Are Breaching PTC Windchill Servers to Steal Product Blueprints Before Extortion
Cl0p-linked attackers are chaining an unauthenticated information disclosure bug with a critical deserialization flaw in PTC Windchill and FlexPLM to steal engineering and product-design data from manufacturers, automakers,...
Chaos Ransomware’s New msaRAT Tool Hijacks Chrome and Edge as a Stealth Command Channel
Cisco Talos has identified msaRAT, a Rust-based tool tied to the Chaos ransomware group that quietly launches Chrome or Edge in headless mode and turns the browser into...
Qilin Ransomware Affiliates Exploit Palo Alto Firewall Bypass to Skip Straight Past Perimeter Defenses
A critical PAN-OS authentication bypass, CVE-2026-0257, is being actively exploited by Qilin ransomware affiliates to gain direct VPN access to corporate networks. Arctic Wolf Labs traced multiple June...
Spirals Ransomware: From First Foothold to Full Encryption in Under 24 Hours
A newly identified ransomware strain called Spirals encrypted an entire IT services company's network in South Asia within a single day, using an IIS web shell, tunneling tools,...
Coca-Cola’s Fairlife Brand Halts US Production After Ransomware Hits Manufacturing Systems
Coca-Cola disclosed in an SEC filing that its Fairlife dairy subsidiary suffered a ransomware attack that forced a temporary halt of US production, while Canadian operations continued unaffected....
The Gentlemen Ransomware: Custom EDR/AV Killers Fuel Rapid Global Expansion
The Gentlemen ransomware group, tracked by Microsoft as Storm-2697, has claimed over 500 victims in 70+ countries using a custom EDR/AV-killing toolkit called GentleKiller and a self-propagating worm...
SEO-Poisoned Bing Search Delivers BumbleBee Loader and Akira Ransomware to Enterprise Network
An IT administrator searching Bing for ManageEngine OpManager was redirected to a trojanized installer, triggering a 44-hour intrusion that ended with Akira ransomware deployed network-wide and 75GB of...
Bajaj Auto Confirms Ransomware Attack — Both Parent Company and Tech Subsidiary Affected
Bajaj Auto disclosed a ransomware attack on June 23, 2026, affecting systems at the company and its subsidiary BATL. The firm has notified CERT-In and is working to...