LIVE · cybersecurity feed
Live wire
Zero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentials
ransomware

Ransomware attackers are zeroing in on mid-market companies

Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and June 2026, according to Black Kite. The analysis covered 13,336 incidents with known revenue and defined mid-market companies as businesses with annual revenue between $10 million and $1 billion. Their share of incidents remaine

zeroday.news ·

Mid-sized companies have become the primary target for ransomware and data extortion attacks, accounting for nearly three-quarters of publicly disclosed incidents in North America and Europe between January 2023 and June 2026. An analysis of 13,336 incidents with known revenue, conducted by Black Kite, defined mid-market companies as those with annual revenues ranging from $10 million to $1 billion. This segment consistently represented between 72% and 75% of all reported incidents throughout the period, indicating a sustained targeting trend.

The majority of these mid-market victims, over half, fell within the lower end of the revenue spectrum, specifically between $10 million and $50 million annually. The manufacturing sector was the most heavily impacted industry, comprising more than a quarter of all mid-market victims. It was followed by professional, scientific, and technical services, and then construction.

Attackers frequently exploit common weaknesses to gain initial access to company systems. A review of over 120,000 mid-market organizations revealed that 54.7% had at least one significant patch-management deficiency on a public-facing system. Furthermore, more than a quarter of these organizations had vulnerabilities that were already known to be actively exploited by threat actors.

Stolen credentials represent another significant entry point. Nearly one-third of the monitored organizations showed evidence of "stealer-log" findings, indicating that their credentials had been compromised by information-stealing malware. These stolen login details can be used by attackers for direct account access, lateral movement within networks, or as a preparatory step for more extensive attacks.

The challenge for security teams, particularly in mid-sized companies with limited staff and resources, lies in prioritizing which vulnerabilities to address first. The continuous emergence of new vulnerabilities, coupled with the increasing speed of their discovery and analysis facilitated by artificial intelligence, exacerbates this problem. While AI tools can assist security teams in identifying vulnerabilities and processing large volumes of security data, attackers also leverage similar capabilities to pinpoint weaknesses more rapidly.

This dynamic creates a greater workload for mid-sized companies already struggling to manage numerous vulnerabilities with constrained staff. Simply identifying a vulnerability does not automatically convey its urgency; teams must still determine if the affected system is internet-exposed, if the weakness is being actively exploited, and what level of access it could provide. Without this context, treating every vulnerability as equally critical becomes unmanageable when facing thousands of potential issues.

Mid-sized companies are also deeply embedded in complex supply chains, acting as both providers to larger organizations and consumers of services from their own suppliers, cloud platforms, and technology vendors. A security incident at one company can therefore ripple across the entire supply chain. A compromised supplier, for instance, could expose customer data, disrupt services, or offer attackers an alternative route into connected organizations.

Managing these intricate relationships presents another hurdle. The analysis noted that a typical vendor-risk team might consist of only two individuals responsible for overseeing more than 300 suppliers. Additionally, some software and services may operate outside formal vendor inventories, leaving security teams with an incomplete view of their third-party risk exposure.

However, regulatory requirements are increasingly bringing supply chain risks into focus. Directives such as the EU's NIS2 and U.S. regulations like NYCRR 500 and HIPAA mandate that organizations address risks associated with their suppliers. Consequently, mid-sized vendors may face growing demands from customers to provide detailed information about their security controls. For smaller security teams, understanding which vulnerabilities and third-party connections pose the greatest risk is crucial for effectively allocating their limited resources.

ransomware
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a screwdriver Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assume

ai

Product showcase: AI Paper Trail shows the privacy cost of talking to AI

Proton’s AI Paper Trail is a free tool designed to make the information accumulated across AI conversations easier to see. It analyzes exported ChatGPT or Claude conversation data and produces a personal privacy report showing what can be inferred from those conversations. Proton says the uploaded data is deleted after analysis and is not stored on Lumo’s servers. AI conversations can reveal a sur

patch

Weekly Update 518: IoT Doorlock Nirvana with UniFi

I genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've worked out how to put it all into a residential house and have it make sense. There are a few basic tenets: Main power (never have to rely on

cloud

AWS makes it easier to spot firewall rules that have gone quiet

AWS Network Firewall’s rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping them identify unused or redundant rules and validate whether security controls are working as intended. The capability covers stateful rules in both custom and managed rule groups, while stateless rules are not supported. The feature is enabled by defaul

malware

ToxicPanda Android malware uses VPN permissions to block Google Play

The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]

iran

UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks

Hackers linked to Iran have successfully disabled a small UK power plant for four days, marking the first confirmed attack of its kind against the nation's energy infrastructure. The incident occurred concurrently with cyberattacks targeting water facilities across 12 US states. While the UK power plant's outage did not impact the national grid, the attack served as a demonstration of capability, with intentions likely focused on showcasing access rather than causing widespread disruption.