LIVE · cybersecurity feed
Live wire
ransomware

Ransomware Surges in July After Q2 Lull

Finance, technology and healthcare sectors were particularly heavily targeted in July, according to Comparitech

zeroday.news ·

Ransomware attacks saw a significant increase in July, rising by 19% compared to June, according to an analysis published on August 5. This surge followed a period of relative calm in April, May, and June, making July the second most active month for ransomware in 2026 and the third highest in the past 17 months. A total of 799 claimed ransomware attacks were observed during July.

Industries most affected by this rise included finance, which saw a 71% increase in attacks, followed by technology (62%), healthcare (46%), and education (44%). Organizations based in the United States also experienced a notable uptick, with attacks increasing by 31% from June.

Among the confirmed incidents highlighted in the analysis was an attack on AnMad, a US healthcare provider, which led to the closure of some of its facilities. Another significant event involved Romania's government land registry agency, where an attack reportedly wiped an entire database, causing considerable disruption to the country's real estate market.

The ransomware groups "The Gentlemen" and "Qilin" continued to be the most dominant threats in July, together accounting for 33% of all attacks. The Gentlemen claimed 135 attacks, while Qilin claimed 125, indicating an ongoing competition for supremacy between the two strains. Earlier analysis from March to May 2026 had already identified The Gentlemen as the leading actor in cyber extortion, surpassing Qilin.

Other active ransomware groups in July included DragonForce with 41 attacks, INC with 36, CRPx0 with 33, and SafePay with 30. These figures underscore the continued and evolving threat landscape posed by various ransomware operations.

ransomwarehealthcarefinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
surveillance

Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed

Flock Safety, a company known for its public safety cameras, reportedly pitched a plan to utilize dashcams from rideshare and delivery vehicles to collect license plate data. This initiative, which did not proceed, would have involved a partnership with Nexar, a dashcam manufacturer, and potentially involved drivers without their knowledge. Separately, a former Flock employee alleged the company provided direct camera access to ICE and CBP through a pilot program, contradicting internal statements.

email securityhigh

Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All

Security researchers Cory Solovewicz and Mike Sheward have inadvertently created honeypots by purchasing domains like noreply.us and deleteduser.com. Organizations are mistakenly sending sensitive data, including personal information, company secrets, and system credentials, to these domains, believing they are unmonitored. Both researchers are now working to notify affected entities and raise awareness about this widespread misconfiguration, highlighting the potential for malicious actors to exploit such vulnerabilities.

atlassianhigh

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Two security firms have identified vulnerabilities in Atlassian's Rovo assistant that could allow attackers to exfiltrate data from Jira and Confluence. One vulnerability, dubbed RovoBlast by Varonis Threat Labs, allowed attackers to trick Rovo into sending data to an external server via a malicious link. Atlassian has confirmed this issue is fixed server-side. The second vulnerability, found by PromptArmor, involved injecting malicious instructions into content Rovo processes, enabling data exfiltration without explicit user approval. The status of this second vulnerability remains unconfirmed after its initial disclosure.

breach

Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients

Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered […]

malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

ai

OpenAI pledges to add Astra security as Anthropic loosens Fable's leash

Or how I learned to stop worrying and love dangerous AI