LIVE · cybersecurity feed
Live wire
OpenAI locks down Astra over potential critical cyber capabilitiesCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleSecurity Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
ransomware

New StormEncryptor ransomware used by former Medusa affiliate

A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]

zeroday.news ·

A financially motivated threat actor, previously linked to the Medusa ransomware operation, has been observed deploying a new ransomware strain named StormEncryptor. Microsoft Threat Intelligence, which tracks this actor as Storm-1175, indicates that recent attacks likely leveraged an authentication-bypass vulnerability, CVE-2026-18577, in the N-central remote monitoring and management (RMM) tool.

Storm-1175 is believed to be based in China and has a history of exploiting zero-day and N-day vulnerabilities in various products, including GoAnywhere MFT, SmarterTools SmarterMail, Microsoft Exchange, Ivanti Connect Secure, and JetBrains TeamCity. The deployment of StormEncryptor marks the first activity observed from Storm-1175 by Microsoft Threat Intelligence since April 2026, signaling a shift away from their previous use of Medusa ransomware.

The StormEncryptor malware is written in C++ and appends the `.encrypted` filename extension to encrypted files. It drops a ransom note titled `!!!README_FIRST!!!.txt` in every scanned directory. This note gives victims a three-day window to contact the attackers for ransom negotiation, threatening to leak stolen data online if payment is not made.

Upon gaining initial access to a target network, Storm-1175 utilizes tools like AnyDesk or SimpleHelp for remote management, Advanced IP Scanner for network discovery, and Mimikatz to extract credentials from the Local Security Authority Subsystem Service (LSASS) process. Microsoft emphasizes that this threat actor moves rapidly from initial compromise to data exfiltration and ransomware deployment, often completing these stages within a few days.

N-able, the vendor of the N-central RMM tool, addressed the CVE-2026-18577 vulnerability with a hotfix, 2026.3 HF1 (build 2026.3.1.7), released on August 2. The company urged customers to install this patch immediately.

N-able previously advised administrators to look for indicators of compromise, such as an `svchost.exe` file located in users' device Documents folders, a registered service named "Cloudflared," and inbound connections from specific IP addresses detailed in their advisory. Organizations are encouraged to monitor for Storm-1175 activity and apply security patches promptly to mitigate risks.

ransomwarefinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped.

phishing

North Korean spies are running local LLMs to cause AI mischief

Kimsuky's phishing attacks get an AI boost

malware

Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list

What wouldst thou ask of the monkey's paw?

cloud

Outdated Cybercrime Laws Put Security Researchers at Risk

A public policy expert mapped global cybercrime laws to develop a five-point framework for protecting ethical hackers and good-faith security research.

security

Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)

Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the blockchain, APIs are provided for developers. These APIs will either "speak" JSON or gRPC. One implementation often used for development is "surfpool," which is used to test programs before deploying them to a Solana network.

security

Poland uncovers second heat plant cyberattack that went hidden for months

The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.