Chaos Ransomware’s New msaRAT Tool Hijacks Chrome and Edge as a Stealth Command Channel
Cisco Talos has identified msaRAT, a Rust-based tool tied to the Chaos ransomware group that quietly launches Chrome or Edge in headless mode and turns the browser into...
Qilin Ransomware Affiliates Exploit Palo Alto Firewall Bypass to Skip Straight Past Perimeter Defenses
A critical PAN-OS authentication bypass, CVE-2026-0257, is being actively exploited by Qilin ransomware affiliates to gain direct VPN access to corporate networks. Arctic Wolf Labs traced multiple June...
Spirals Ransomware: From First Foothold to Full Encryption in Under 24 Hours
A newly identified ransomware strain called Spirals encrypted an entire IT services company's network in South Asia within a single day, using an IIS web shell, tunneling tools,...
Coca-Cola’s Fairlife Brand Halts US Production After Ransomware Hits Manufacturing Systems
Coca-Cola disclosed in an SEC filing that its Fairlife dairy subsidiary suffered a ransomware attack that forced a temporary halt of US production, while Canadian operations continued unaffected....
The Gentlemen Ransomware: Custom EDR/AV Killers Fuel Rapid Global Expansion
The Gentlemen ransomware group, tracked by Microsoft as Storm-2697, has claimed over 500 victims in 70+ countries using a custom EDR/AV-killing toolkit called GentleKiller and a self-propagating worm...
World Leaks Ransomware Dumps 630 GB of Tata Electronics Data — Confidential Apple and Tesla Files Exposed
Ransomware group World Leaks has published 630+ GB of stolen Tata Electronics data including confidential Apple iPhone manufacturing specs and Tesla engineering drawings marked as trade secrets. Tata...
Prinz Eugen Ransomware Uses RemotePC RMM and PowerShell Stagers to Evade Detection
A new ransomware group is deploying the Go-based Prinz Eugen ransomware by abusing legitimate remote management software (RemotePC) and PowerShell stagers. The campaign has already hit major financial...
GentleKiller: Inside the Ransomware Framework Disabling 400+ EDR Security Products
ESET researchers have exposed GentleKiller, the in-house EDR-killing framework of the Gentlemen ransomware gang, capable of disabling over 400 security processes across 48 products using BYOVD kernel driver...