LIVE · cybersecurity feed
Live wire
CVE-2026-46817high

Ransomware Attacks Hit Financial, Defense, and Manufacturing Firms

Several organizations, including River Bank & Trust, Indra Group, and Nidec, have recently fallen victim to ransomware attacks. These incidents have led to potential data exfiltration and service disruptions. Additionally, a new AI-driven ransomware technique has been demonstrated that exploits browser APIs to encrypt user files.

zeroday.news · 26d ago

Several organizations across the financial, defense, and manufacturing sectors have recently disclosed ransomware attacks or data breaches. These incidents include a US financial institution, a Spanish defense contractor, a Japanese industrial manufacturer, and a US insurance firm's Japanese operations.

River Bank & Trust, a US financial institution, experienced a ransomware incident after an unauthorized actor accessed the network of its parent company, River Financial Corporation, on June 16. The bank confirmed the presence of ransomware on parts of its server environment and is currently evaluating whether personal data was accessed or exfiltrated.

Indra Group, a Spanish defense, aerospace, and technology contractor and a member of the NATO cyber coalition, confirmed a ransomware attack that impacted one of its subsidiaries. The Gentlemen ransomware gang claimed responsibility and threatened to leak allegedly stolen data. Indra Group, however, stated that the incident was contained and that service continuity was maintained.

Nidec, a Japanese electric motor and industrial manufacturer, disclosed a ransomware attack affecting the network of its Taiwanese subsidiary, Nidec Chaun Choung Technology. The BlackField group claimed responsibility for this attack, alleging the theft of over two terabytes of corporate data. This allegedly stolen data includes employee, financial, procurement, manufacturing, legal, and IT records.

Separately, US insurance firm Aflac disclosed a data breach affecting its Japan operations. Attackers accessed its policyholder portal between June 15 and June 25, exposing personal and financial data for nearly 4.4 million customers. The compromised information included policyholder details and premium payment account information.

In other cybersecurity news, researchers have identified new attack techniques and vulnerabilities. A browser-native ransomware technique, generated by a large language model, has been demonstrated to abuse Chrome's File System Access API. This method uses a fake image-enhancement page to trick users into granting folder access, subsequently reading, exfiltrating, and encrypting photos within the browser on Android and Windows devices.

Furthermore, shell command injection weaknesses were found in open-source AI coding agents, with 10 out of 11 popular tools failing to block obfuscated destructive commands. Simple rewrites allowed attackers to bypass filters and perform actions like file deletion. Only the Continue agent was noted to properly parse commands. Researchers also warned about attackers exploiting LLM phantom squatting by registering AI-generated domains to hijack traffic and deliver phishing attacks, recording 250,000 hallucinated domains and subsequent registrations, including an AI-built phishing kit named Montana Empire.

Several critical vulnerabilities have also been addressed. Oracle E-Business Suite is affected by CVE-2026-46817, a critical remote code execution flaw reportedly exploited against approximately 950 internet-exposed instances globally, which could grant attackers control over ERP systems. Linux kernel maintainers patched CVE-2026-46242, a "Bad Epoll" privilege escalation flaw affecting Linux servers, desktops, and Android devices. This race-condition use-after-free vulnerability allows unprivileged local users to gain root access, with a public exploit demonstrating reliable exploitation.

Citrix addressed CVE-2026-8451, a NetScaler ADC and NetScaler Gateway memory disclosure flaw impacting SAML Identity Provider configurations, with active exploitation observed less than 24 hours after disclosure, enabling attacks to leak session tokens. Progress also addressed CVE-2026-8037, a critical OS command injection flaw in Kemp LoadMaster load balancers with a CVSS score of 9.6. Exploitation attempts for this vulnerability began on June 29, potentially allowing unauthenticated remote code execution.

Threat intelligence reports highlighted a North Korea-aligned supply-chain campaign, PolinRider, which published 108 malicious packages and a Chrome extension across open-source registries, abusing VS Code auto-run tasks and hidden JavaScript loaders to deploy DEV#POPPER and OmniStealer. A partnership between the Vect ransomware group and TeamPCP, a supply chain credential-theft gang, was observed, industrializing ransomware delivery, with at least one Vect attack confirmed using TeamPCP-sourced credentials. The ChocoPoC campaign was also detected, weaponizing fake proof-of-concept exploits on GitHub and PyPI to infect vulnerability researchers with a Python RAT that steals files and browser data. Lastly, analysis of 3,000 live ClickFix payloads revealed rotating wrappers, custom command generation, and a Downloads-folder technique designed to bypass AMSI protections, indicating its evolution into an API-driven malware delivery ecosystem.

ransomwaredata breachaicyber attackfinancial sector
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]