Ransomware
Sysdig Reports JadePuffer Deploys ENCFORGE Ransomware Purpose-Built to Wipe AI Model Files
The first purpose-built AI-model ransomware lands from JadePuffer — a defender review for organizations hosting AI infrastructure this week.
Actionable insights into the global threat landscape. Analysis of TTPs, Indicators of Compromise (IoCs), and emerging attack patterns.
Ransomware
The first purpose-built AI-model ransomware lands from JadePuffer — a defender review for organizations hosting AI infrastructure this week.
Nation-State Cyber Threats
A Dutch intelligence advisory raises the stakes on Russian camera-hijacking activity — critical-infrastructure defender teams review IP-camera posture this week.
Threat Intelligence
A novel Microsoft 365 calendar-abuse malware framework — defender detection-engineering review this week.
Supply Chain Attack
Ecosystem supply-chain compromises now extend to RubyGems — three malicious gems built to skip CI runners and land on developer machines make this week's defender inventory work a Ruby-dependency audit.
Threat Intelligence
A second SonicWall SMA attribution lands — Volexity names UTA0533 alongside the Dark Reading INC Ransomware framing this weekend.
Nation-State Cyber Threats
CERT-UA names UAC-0145 as the Sandworm sub-cluster behind the ClickFix CAPTCHA activity against Ukrainian devices - a GRU-affiliated crew, and defender awareness for Ukraine-adjacent teams this weekend.
Policy & Government
A cryptocurrency-user targeting arrest via a novel Steam-games vector — law-enforcement coverage this weekend.
Threat Intelligence
A botnet targeting self-hosted AI tooling for cloud keys — defender review for organizations exposing AI services this weekend.
Supply Chain Attack
A code-signing-integrity attribution against a Chinese cybercrime subgroup — and a prompt for supply-chain defenders to review how much trust their pipelines place in a valid signature.
Ransomware
INC Ransomware named as the SonicWall SMA zero-day exploiter — defender teams stay in accelerated verification posture this weekend.
Supply Chain Attack
Another JavaScript-ecosystem compromise with a novel blockchain-C2 angle — seven scoped npm packages impersonating the Vite tooling namespace, and defender inventory work this weekend.
Vulnerabilities
Rapid7 goes deep on the SharePoint CVSS-9.8 RCE — defender-team detection-engineering review this weekend.