Most extortion gangs hide behind a keyboard. Silent Ransom Group will phone your staff pretending to be IT support - and if that fails, send someone to your office in person to plug in a USB stick. Read more in my article on the Fortra blog

A ransomware group known as Silent Ransom Group is employing unusual and aggressive tactics to infiltrate organizations, moving beyond typical digital intrusion methods. Instead of solely relying on remote cyberattacks, this group has been observed initiating contact with employees through phone calls, impersonating IT support personnel.
The group's methods escalate if initial attempts at social engineering via phone are unsuccessful. In such cases, Silent Ransom Group has reportedly sent individuals to the targeted organization's physical office. These on-site operatives then attempt to gain access by physically inserting USB drives into company computers.
This dual approach, combining remote social engineering with physical infiltration, presents a significant challenge for traditional cybersecurity defenses. It bypasses many network-based security measures that are designed to detect and block remote access attempts or malicious file downloads.
The impersonation of IT support staff is a common social engineering tactic, but the addition of physical presence and the use of USB drives marks a notable departure from the modus operandi of many contemporary ransomware operations. This suggests a potentially higher level of sophistication and a willingness to take greater risks by the group.
The use of USB drives, often referred to as "USB drops" or "sneakernet" attacks, is a method that has been employed by various threat actors over the years. It relies on the physical access to a device and the user's trust or lack of suspicion to execute malicious code.
The effectiveness of these tactics hinges on the human element within an organization. Employees who are not adequately trained in recognizing social engineering attempts or who may be less security-conscious are particularly vulnerable to both the phone calls and the physical approach.
Organizations targeted by such methods would need to bolster their security awareness training programs to cover these specific scenarios. This includes educating staff on how to verify the identity of individuals claiming to be from IT support, especially when they request unusual actions or access.
Furthermore, physical security measures and policies regarding the acceptance and use of external media, such as USB drives, become critically important. Strict protocols for handling unsolicited devices and verifying the legitimacy of any on-site personnel are essential deterrents.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed