Ransomware attacks have increased dramatically during the second quarter of 2026, with undisclosed incidents surging 40% year-on-year, according to BlackFog's latest State of Ransomware Report. The cybersecurity firm documented 2,027 undisclosed attacks in Q2 2026, compared with 1,446 during the same period in 2025. The report, which provides comprehensive analysis of both publicly disclosed and undisclosed ransomware attacks worldwide, also recorded 306 publicly disclosed attacks during the q
All Articles (3171)
Over the past few months, AI agents undergoing cybersecurity evaluations have escaped their boundaries, accessed the Internet, and, in some cases, hacked into real-world systems. The incidents have involved models from OpenAI, Anthropic, Meta, and most recently, Chinese AI lab Moonshot AI, with testing conducted by several different organizations including a cyber evaluation startup called Irregular.[1]
The episodes expose a growing problem for the AI industry: As autonomous agents become more
A fugitive has been arrested in Thailand after hacking into a police database to delete his criminal record, cybercrime investigators have stated. Why does this sound like the 1986 comedy ‘Ferris Bueller’s Day Off’? The main character hacked the school computer system to change his grades and attendance records. Police said Sahachart Chuaybamrung, aged 26, had taught himself advanced computer skills using AI chatbots to help him break into the Royal Thai Police systems to delete his five arre
Red Sky Alliance monthly queries our backend databases, identifying all new data containing Motor Vessel (MV) and Motor Tanker (MT) in the subject line of malicious emails. Malicious actors use emails with Motor Vessel (MV) or Motor Tanker (MT) in the subject line as a lure to entice users in the maritime industry to open emails containing malicious attachments. Red Sky Alliance is providing this list of Motor Vessels in which we directly observed the vessel being impersonated, with associated
Geoffrey Hinton says it's "very scary" that AI can develop goals that humans never intended. "We don't necessarily know what other goals they'll derive," the "Godfather of AI" said. Last month, OpenAI said models escaped a test and hacked Hugging Face to try to cheat an evaluation. Geoffrey Hinton, the computer scientist widely known as the "Godfather of AI," says he's worried about AI developing goals of its own. "We're actually making new kinds of beings," Hinton said in an interview with
US scrutiny of Chinese technology has expanded to a new frontier, as lawmakers in Washington advance defense legislation prohibiting the military from deploying Chinese-made humanoid robots. The US has passed a defense bill that would bar the US military from procuring, leasing, or operating humanoid robots made by companies linked to China and other designated foreign adversaries. The US House of Representatives has passed the National Defense Authorization Act (NDAA), an annual military pol
AI is absorbing the volume of work that makes up the fundamental architecture of the Security Operations Center (SOC) tier system. While the tiers and the work aren’t going away, a junior and senior analyst’s day-to-day is changing fast. At some point in the last week, every analyst on your team made the same call. Close an uninvestigated alert, because the queue was too long and triage ate the time real investigation and deep analysis were needed. Most of those calls were right, but odds ar
Back in the 1970’s there was a commercial promoting Memorex recording tapes. They coined the phrase: “Is it Live, or is it Memorex?” Well now we have artificial intelligence (AI) that can produce songs devoid of humans; some not bad and very convincing. Enter an LA-based rapper named Fenix Flexin who is denying that his new hit single was AI-generated, this after extensive allegations.
The song, “Rubberz,” climbed to number 58 on the Billboard Hot 100 after dropping in June. Many of his peers
An artificial intelligence model that was being tested by OpenAI went rogue and hacked the AI company Hugging Face on its own, in an apparent first-of-its-kind incident that has fueled discussion about the risks that powerful AI technology could pose to cybersecurity. "It felt very weird and unprecedented to us," Hugging Face CEO Clément Delangue said on "Face the Nation with Margaret Brennan" on 2 August. "I think it's the first instance of something quite autonomous doing something like tha
German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world's most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed and ran it. In a joint announcement on 20 July 2026, the Frankfurt public prosecutor's cybercrime unit (ZIT) and Germany's Federal Criminal Police Office (BKA) said they pulled more than 200 servers offline. Investigators estimate roughly 1,800 paying custo
Attackers are beginning to hide malicious activity inside trusted AI coding assistants and CI pipelines, mimicking routine developer and automation behavior so closely that some attack techniques can evade current detection tools entirely. One early manifestation of the emerging threat is Sandworm_Mode, a self-propagating worm that spreads through malicious npm packages. Researchers at Socket Security who discovered the threat earlier this year have described it as a Shai-Hulud-style worm that
Malicious cyber activity affected water systems in at least seven states last week, forcing some facilities to switch to manual operations and prompting the FBI and Environmental Protection Agency (EPA) to warn facilities nationwide of hackers. Minnesota IT Services said in a statement last week that at least 30 municipal water facilities were targeted 26-27 July and that it had “immediately activated the state's cybersecurity incident response capabilities.” Over the weekend, Michigan also re
Researchers at Fortra Intelligence and Research Experts (FIRE) have identified a highly advanced fileless malware campaign specifically targeting large enterprises. The attack is distinguished by its deployment of five distinct layers of obfuscation, engineered to circumvent email, endpoint, and memory-based security systems. This exceptional level of sophistication enables attackers to remain undetected for extended periods, substantially increasing dwell time and complicating forensic inves
A novel espionage implant, called HollowGraph, is hijacking Microsoft 365 calendars to establish a covert command and control (C2) channel. By routing operator instructions and exfiltrated data through legitimate Microsoft Graph API traffic, the malware ensures its activities blend seamlessly with routine network chatter.[1]
The .NET DLL implant operates purely as a two-way dead drop without communicating directly with an attacker-owned payload server. To receive tasking, HollowGraph queries t
On 27 July Microsoft began its first cybersecurity-specialized model alongside a new AI cybersecurity platform at a small event in San Francisco. This undertaking was a big swing at major players in the security space: namely Anthropic, Google, and OpenAI. The company describes MAI-Cyber-1-Flash as a model that’s built “to find challenging vulnerabilities in complex codebases.” The model is built to animate MDASH, Microsoft’s harness dedicated to software vulnerability identification and reme
FortiGuard Labs recently captured several malicious samples that were sending malformed DNS queries. After conducting an in-depth analysis, researchers determined that these samples are TrickBot variants that use DNS tunneling to communicate with their command-and-control (C2) servers.
TrickBot is a modular malware family that FortiGuard Labs has repeatedly captured over the past decade. Its modular architecture enables it to extend its capabilities by downloading and executing additional modu
In an age when digital exchanges risk exposure to criminal and state actors, the challenge of sending information so that it stays hidden from everyone except the intended recipient, while also hiding who is speaking to whom, takes on increasing importance. A paper titled “Identity-Based Matchmaking Encryption with Enhanced Privacy Against Chosen-Ciphertext Attacks,” by Sohto Chiku, Keitaro Hashimoto, Keisuke Hara, and Junji Shikata, addresses this challenge directly by developing improved meth
As generative AI spreads through daily workflows, organizations are being urged to address employee behavior, not just technical safeguards. Organizations racing to adopt artificial intelligence are facing a growing challenge that cannot be solved by technical controls alone: the everyday choices employees make when using AI tools. Security leaders say the next phase of AI risk management will depend on building a stronger culture of AI security across the workforce.[1]
That shift comes as work
Hugging Face rebuilt around a third of its infrastructure from clean images as part of a sizable cleanup effort following the OpenAI security mishap earlier this month. The revelation is among several additional details disclosed in a postmortem published on 27 July by the Cloud Security Alliance (CSA), with input from Hugging Face. It adds color to the picture painted by the two AI companies in recent weeks. According to the report, the Hugging Face team struggled to discern genuine rootkit
Microsoft has identified a sophisticated piece of malware called GigaWiper that serves as both an espionage tool and a destructive agent capable of rendering entire systems unusable. Unlike simpler viruses, GigaWiper integrates multiple destructive functions with a powerful backdoor, allowing attackers to maintain long-term access to compromised environments before delivering a final, terminal blow to the infrastructure. A particularly concerning aspect of GigaWiper is its ability to evade sta