What, you didn't think the top gangs were busy watching agents escape their sandboxes too, did you?

Ransomware attacks saw a significant increase in July, with 799 incidents recorded, marking a nearly 20 percent rise from June's 668 incidents. This surge made July the second busiest month of the year for ransomware, closely trailing March, which saw 805 attacks. Of the July incidents, 51 were confirmed by the affected organizations.
The distribution of targets shifted notably in July. While attacks on utility companies, legal firms, and government agencies decreased by 44 percent, 31 percent, and 11 percent respectively, other sectors experienced substantial increases. Financial companies saw a 71 percent rise in attacks, tech firms 62 percent, pharmaceutical companies and medical billers 46 percent, and the education sector 44 percent. This trend aligns with observations that manufacturing, education, healthcare, and financial sector firms are among the most likely to pay ransoms, with even the least likely among these, finance, paying out in 51 percent of cases.
The United States was the most frequently targeted country, accounting for 322 of the 799 attacks in July. Germany followed distantly with 40 incidents.
Two prominent ransomware gangs were particularly active in July. "The Gentlemen," a relatively new but highly prolific operation, claimed responsibility for 135 victims. This group was previously linked to an attack on UK software consultancy Adaptavist Group earlier in the year. Qilin, known for its 2024 attack on UK pathology provider Synnovis that disrupted NHS services, claimed 125 victims. Together, these two groups were responsible for nearly a third of all ransomware attacks logged in July.
The methods of initial access for these attacks were not detailed for July's incidents. However, previous analysis of "The Gentlemen" suggests the use of stolen credentials, while Qilin has claimed to exploit zero-day vulnerabilities, as it did in the Synnovis breach in June 2024.
The overall increase in ransomware activity underscores the ongoing threat posed by these attacks, even as attention in the cybersecurity landscape may be drawn to emerging areas like artificial intelligence. Organizations are advised to maintain robust security practices, including multi-factor authentication, regular system updates, and consistent data backups.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed