Panzer Ransomware Targets Italian Manufacturers and Telecom Firms With ESXi-Ready RaaS
New Panzer ransomware-as-a-service operation lists Italian firms Doimo Cucine and NTE Italia as victims, offering encryptors for Windows, Linux, FreeBSD, and ESXi.
Panzer, a ransomware-as-a-service operation that surfaced August 5, listed a kitchen manufacturer in Treviso (Doimo Cucine) and a telecommunications engineering firm in Catanzaro (NTE Italia) among alleged victims, claiming 30 GB and 16 GB of stolen data respectively. The group advertises encryptors for Windows, Linux, FreeBSD, and VMware ESXi, a Tox-based affiliate recruitment process with screening, an affiliate dashboard, and an 80/20 revenue split. Neither victim had publicly confirmed the incidents when researcher Andrea Fortuna's report was published, and the group's first access method and payload have not been independently analyzed. Panzer posted victims across 11 countries as claimed Italian ransomware incidents reached 212 by September 6, already above 2025's full-year total of 169.
Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware
FBI warns Medusa ransomware-as-a-service has hit over 500 critical infrastructure organizations while significantly improving its tactics, techniques and procedures.
The FBI warned that the Medusa ransomware-as-a-service operation has compromised more than 500 critical infrastructure organizations. The agency said the group has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counter. Defenders in critical infrastructure sectors should review exposure and harden against Medusa's updated TTPs.
Latin America governments are prime targets for ransomware due to lack of resources, analysis argues
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
Cisco Talos reports 90 ransomware incidents hit Japanese organizations in H1 2026, led by The Gentlemen, with Qilin using AI for efficiency.
Cisco Talos observed 90 ransomware incidents against Japanese organizations from January to July 2026, up about 4.7% year over year, with manufacturing accounting for 34% of victims. The Gentlemen was the most active group with 14 incidents; its leak-site listings grew from 48 in January to 105 in July. Qilin and SafePay followed with seven incidents each, and Talos notes Qilin is leveraging AI to improve operational efficiency.
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Kaspersky details NightEagle, Hacking Cat, and Toy Ghouls targeting Russian enterprises with Exchange backdoors, Gorilla RAT, and destructive Monkey ransomware.
Kaspersky reports three threat clusters targeting Russian enterprises: NightEagle (APT-Q-95), the pro-Ukrainian hacktivist group Hacking Cat, and Toy Ghouls. NightEagle uses compromised VPN credentials and the GhostContainer modular backdoor to fully compromise Microsoft Exchange servers, chaining CVE-2020-0688 exploitation, BlueKeep (CVE-2019-0708), Active Directory vulnerabilities, and DCSync to seize domain controllers. Hacking Cat exploits Exchange flaws including CVE-2021-26855 and CVE-2026-42897 to deliver the Gorilla RAT and multiple Monkey ransomware variants written in Rust, .NET, C++, and Golang targeting Windows, Linux, and VMware ESXi, with some variants acting as wipers that never store the encryption key.
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
Microsoft warns of Teams IT-impersonation intrusions deploying Node.js implants; Spring Ring vishing hit 150+ employees across 10 companies; The Gentlemen ransomware claims 683 victims.
Microsoft warned of a human-operated campaign abusing Teams external collaboration to impersonate IT help desk staff, deploy malicious MSI packages staging Node.js runtimes and obfuscated JavaScript implants, then pivot to domain controllers over WinRM. Unit 42 documented the Spring Ring vishing operation targeting over 150 employees across at least 10 companies using 26 attacker identities, including an NTLM relay variant against domain controllers. Sophos reported The Gentlemen ransomware (Gold Sherwood) reached 683 total victims by end of July 2026, adding 169 in July, with a playbook using BYOVD-based EDR killers and backup tampering. Group-IB found the Outsider phishing-as-a-service platform created 700+ new phishing pages within a month despite law enforcement takedowns.
PaperCut NG/MF vulnerabilities exploited in zero-day attacks
PaperCut warns of active zero-day exploitation chaining CVE-2026-81578 and CVE-2026-82078 for pre-auth remote code execution in NG/MF print management.
PaperCut Software confirmed attackers are chaining two vulnerabilities in PaperCut NG and MF: CVE-2026-81578, an improper access control flaw in the web management interface allowing unauthenticated configuration changes, and CVE-2026-82078, unsafe dynamic class loading in database connection utilities enabling arbitrary Java bytecode execution. Huntress reproduced a pre-authentication remote configuration takeover and full RCE chain against PaperCut NG 25.0.11.75758 and observed limited exploitation at two customers, including post-exploitation whoami and ver commands. The vendor released Emergency Patch Release 2 with additional hardening and urged restricting Application Server web access to trusted IPs. In 2023, Clop and LockBit affiliates abused CVE-2023-27350 and CVE-2023-27351 in the same software.
GentleKiller targets more than 400 security processes across 48 products
ESET details the Gentlemen ransomware gang's in-house GentleKiller EDR-killer framework targeting over 400 security processes across 48 products, supplied to affiliates.
ESET analyzed the Gentlemen ransomware gang's in-house GentleKiller EDR-killer framework, confirmed through an internal data leak from May 2026. The framework has at least eight variants impersonating legitimate security products and abusing vulnerable or malicious kernel drivers, targeting more than 400 process names across 48 security products. Gentlemen emerged in late 2025, became one of the five most active ransomware gangs in Q1 2026, offers affiliates a 90% ransom share, and practices double extortion using Go-based and C-based ESXi encryptors. The suite also reuses outside tools including HexKiller, ThrottleBlood, and HavocKiller, unified by a shared evasion layer that mimics well-known security vendors.
Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras
Slovakia's NBU found an SMS-triggered backdoor in Russian-made NERO R-ONE traffic cameras, pausing a 279-unit deployment.
Slovakia's national security service NBU issued an alert against NERO R-ONE high-speed traffic cameras after finding a backdoor that grants shell and network access via SMS from hardcoded Russian phone numbers. The cameras are a rebranded version of the Russian CORDON PRO.M model by St. Petersburg firm Semicon, purchased via a Cyprus shell company under a €30 million EU-funded project. The report also found SecureBoot disabled, vulnerable web management, and unauthenticated live streams; the Interior Ministry paused deployment of 279 cameras pending independent assessment.
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
GuidePoint reports a ransomware affiliate posing as 'Ransom Busters' charges victims $20,000-$60,000 to delete stolen data, and details UNC6671's $8M AitM extortion wave.
GuidePoint's GRIT team reports that 'Ransom Busters', likely a ransomware affiliate active across multiple RaaS operations including DragonForce, Settra and Anubis, proactively emails victims claiming it deleted their stolen data and backups for a $20,000-$60,000 fee, citing claimed access to RaaS administrative panels for over three years. Two analyzed intrusions shared tooling: SoftPerfect Network Scanner for reconnaissance, s5cmd-based exfiltration to AWS cloud storage, an RMM tool installed via PowerShell, a backdoor account with password 'Numlock!123' and the same attacker hostname DESKTOP-BBETH6K. Separately, GRIT detailed UNC6671's (Cordial Spider) adversary-in-the-middle vishing operation running since April under five extortion brands, with more than $8 million across 15 Bitcoin wallets, an average of $600,000 per payment, and 78 phishing sub-domains across 76 organizations, 40% in financial services.
Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
CISA, FBI, and HHS updated their Medusa ransomware advisory, reporting over 500 victims and detailing the gang's access-broker and exploit tactics.
A joint advisory update from CISA, the FBI, and HHS expands the March 2025 Medusa guidance, drawing on a year of FBI investigations. The ransomware-as-a-service group's known victim tally grew from more than 300 to more than 500 between March 2025 and April 2026, with the Healthcare and Public Health sector frequently hit. Medusa pays access brokers $100 to $1 million, has exploited flaws such as Fortra GoAnywhere and BeyondTrust vulnerabilities, and leverages newly announced exploits within 24 hours, sometimes a week before public disclosure. The group uses living-off-the-land techniques, remote monitoring and management software, and RDP for lateral movement, and has been linked to actors including Microsoft-tracked Storm-1175 and North Korean hackers targeting healthcare.
Attackers turn to AI for help identifying files worth stealing
Gambit Security documents three threat actors using AI: a ransomware operator with Claude Code, credential harvester Zerofot, and the AI-built RAGE cryptomining framework.
Gambit Security examined three unrelated threat actors using AI across different stages of intrusions. A suspected operator tied to The Gentlemen ransomware-as-a-service used Claude Code running Claude Sonnet 4.6 in late June 2026 at six organizations, including an Australian energy utility, where it ran reconnaissance, ranked valuable databases, staged SQL Server dumps for exfiltration, and modified firewall configurations, accidentally taking one utility firewall offline. The Zerofot credential-harvesting operation, built with OpenAI Codex and Claude Code, collected 2,975 validated credentials from 1,742 hosts between April 5 and May 23, 2026, including SSH private keys and AWS access keys. The AI-generated RAGE Python framework exploits exposed Redis, Elasticsearch, Docker, Tomcat, and other services to harvest credentials and deploy cryptominers, guided at runtime by a DeepSeek-backed AI Orchestrator.
Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout
'The Gentlemen' ransomware group hijacked AnMed's Facebook page, claiming theft of 6TB of sensitive patient data during an ongoing cyberattack on the hospital system.
AnMed, a nonprofit medical system with four hospitals in Georgia and South Carolina, is still responding to a July 26 cyberattack involving malware, with 10 facilities remaining closed as of Monday. On Tuesday its Facebook page displayed unauthorized posts claiming 'The Gentlemen' ransomware group exfiltrated 6 terabytes of data, including records on sexual assault, mental health, abortions and harassment; AnMed said the claims are unverified and patient data impact has not been confirmed. The Gentlemen, believed founded by a former Qilin affiliate using the moniker 'hastalamuerte,' extorted 332 victims in the first five months of 2026 per CheckPoint and claimed 125 industrial attacks in Q2 2026 per Dragos. The group typically breaches networks through edge devices, credential brute-forcing and known vulnerabilities, and offers affiliates tools to disable EDR.