LIVE · cybersecurity feed
Live wire
ransomware

Ransomware attacks spike as world distracted by AI

What, you didn't think the top gangs were busy watching agents escape their sandboxes too, did you?

zeroday.news ·

Ransomware attacks saw a significant increase in July, with 799 incidents recorded, marking a nearly 20 percent rise from June's 668 incidents. This surge made July the second busiest month of the year for ransomware, closely trailing March, which saw 805 attacks. Of the July incidents, 51 were confirmed by the affected organizations.

The distribution of targets shifted notably in July. While attacks on utility companies, legal firms, and government agencies decreased by 44 percent, 31 percent, and 11 percent respectively, other sectors experienced substantial increases. Financial companies saw a 71 percent rise in attacks, tech firms 62 percent, pharmaceutical companies and medical billers 46 percent, and the education sector 44 percent. This trend aligns with observations that manufacturing, education, healthcare, and financial sector firms are among the most likely to pay ransoms, with even the least likely among these, finance, paying out in 51 percent of cases.

The United States was the most frequently targeted country, accounting for 322 of the 799 attacks in July. Germany followed distantly with 40 incidents.

Two prominent ransomware gangs were particularly active in July. "The Gentlemen," a relatively new but highly prolific operation, claimed responsibility for 135 victims. This group was previously linked to an attack on UK software consultancy Adaptavist Group earlier in the year. Qilin, known for its 2024 attack on UK pathology provider Synnovis that disrupted NHS services, claimed 125 victims. Together, these two groups were responsible for nearly a third of all ransomware attacks logged in July.

The methods of initial access for these attacks were not detailed for July's incidents. However, previous analysis of "The Gentlemen" suggests the use of stolen credentials, while Qilin has claimed to exploit zero-day vulnerabilities, as it did in the Synnovis breach in June 2024.

The overall increase in ransomware activity underscores the ongoing threat posed by these attacks, even as attention in the cybersecurity landscape may be drawn to emerging areas like artificial intelligence. Organizations are advised to maintain robust security practices, including multi-factor authentication, regular system updates, and consistent data backups.

ransomwareai
ShareXLinkedInWhatsAppFacebook

More News

view all →
malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

vulnerability

More than half of AI-generated patches are broken

Research finds your AI generated security patch is more likely to fail than fully fix a vulnerability. It might even introduce brand new flaws to exploit along the way. The post More than half of AI-generated patches are broken appeared first on CyberScoop.

security

New Mexico judge orders Meta to pay $567 million in kids online safety case

The money will be used to create a fund to mitigate social media harms, including by carving out $420 million for treatment for New Mexico youth who have been hurt on the platforms.

security

Military device manufacturer discloses cyber incident to SEC

IEH Corporation — which produces specialized products used in military satellites, missiles and fighter jets — said it discovered a cyberattack on Tuesday and immediately tried to contain it.

vulnerability

WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover

WordPress XSS2Shell flaw enables admin takeover and remote code execution. Users should update to patched versions. Researchers at Pwn just published a report on a vulnerability chain they’re calling XSS2Shell, and the entry point is quite simple: type a username that doesn’t exist, and WordPress echoes it back with a tiny formatting flaw baked into […]

vulnerability

AI-Generated Patches Fail Half the Time

A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.