<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Ransomware</title><description>Cybersecurity articles tagged #Ransomware on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Silver Fox Malware Campaign Impersonates Software Vendors</title><link>https://runtimerebel.com/blog/silver-fox-malware-campaign-impersonates-software-vendors</link><guid isPermaLink="true">https://runtimerebel.com/blog/silver-fox-malware-campaign-impersonates-software-vendors</guid><description>An active Silver Fox malware campaign uses fake software download sites to disable Windows Update and weaken Microsoft Defender defenses.</description><pubDate>Wed, 02 Sep 2026 19:06:22 GMT</pubDate><category>Silver Fox</category><category>ValleyRAT</category><category>Gh0st RAT</category><category>Ransomware</category><category>Phishing</category></item><item><title>AI-Assisted Cyber Attacks Accelerate Enterprise Breaches</title><link>https://runtimerebel.com/blog/ai-assisted-cyber-attacks-accelerate-enterprise-breaches</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-cyber-attacks-accelerate-enterprise-breaches</guid><description>Unit 42 reveals how AI agents dramatically accelerate enterprise network breaches, compressing weeks of attack activity into hours for ransomware operations.</description><pubDate>Wed, 02 Sep 2026 12:27:38 GMT</pubDate><category>Ransomware</category><category>MITRE ATT CK</category><category>Unit 42</category><category>Enterprise Security</category><category>Cloud Security</category></item><item><title>CVE-2026-84115: Cleo Harmony Auth Bypass Exploit Published</title><link>https://runtimerebel.com/blog/cve-2026-84115-cleo-harmony-auth-bypass-exploit-published</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-84115-cleo-harmony-auth-bypass-exploit-published</guid><description>An exploit is published for CVE-2026-84115, an authentication bypass in Cleo Harmony allowing remote privilege escalation. Immediate patching to v5.8.1.11 is urged.</description><pubDate>Wed, 02 Sep 2026 12:26:27 GMT</pubDate><category>Authentication Bypass</category><category>Privilege Escalation</category><category>Ransomware</category><category>CVE-2026-84115</category><category>Cleo Harmony</category></item><item><title>Threat Actors Prefer Repeatable Playbooks Over Novel Exploits</title><link>https://runtimerebel.com/blog/threat-actors-prefer-repeatable-playbooks-over-novel-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/threat-actors-prefer-repeatable-playbooks-over-novel-exploits</guid><description>Analysis of modern cyberattacks reveals threat actors increasingly favour scalable, repeatable playbooks over novel exploit development.</description><pubDate>Tue, 01 Sep 2026 12:54:04 GMT</pubDate><category>Ransomware</category><category>Zero-Day</category><category>Phishing</category><category>Credential Theft</category><category>Malware</category></item><item><title>Mexico’s Cybersecurity Plan 2025-2030: Addressing Rising Threats</title><link>https://runtimerebel.com/blog/mexicos-cybersecurity-plan-2025-2030-addressing-rising-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/mexicos-cybersecurity-plan-2025-2030-addressing-rising-threats</guid><description>Mexico&apos;s National Cybersecurity Plan 2025-2030 aims to strengthen defenses against ransomware, state-sponsored espionage, and cybercrime.</description><pubDate>Tue, 25 Aug 2026 16:30:54 GMT</pubDate><category>Mexico</category><category>Ransomware</category><category>State Sponsored Espionage</category><category>Cybercrime</category><category>LockBit</category></item><item><title>State of AI-Enabled Malware: Real-World Impact and Defenses</title><link>https://runtimerebel.com/blog/state-of-ai-enabled-malware-real-world-impact-and-defenses</link><guid isPermaLink="true">https://runtimerebel.com/blog/state-of-ai-enabled-malware-real-world-impact-and-defenses</guid><description>Unit 42 reports AI-enabled malware is primarily proof-of-concept, with minimal operational activity. Existing defenses effectively detect current threats.</description><pubDate>Tue, 25 Aug 2026 16:29:19 GMT</pubDate><category>LLM</category><category>Ransomware</category><category>Malware Analysis</category><category>Social Engineering</category><category>AI Enabled Malware</category></item><item><title>CVE-2026-21962: Oracle WebLogic RCE Under Active Attack</title><link>https://runtimerebel.com/blog/cve-2026-21962-oracle-weblogic-rce-under-active-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-21962-oracle-weblogic-rce-under-active-attack</guid><description>CISA urges immediate patching for CVE-2026-21962, a critical Oracle WebLogic Server Proxy plugin vulnerability actively exploited in the wild.</description><pubDate>Tue, 25 Aug 2026 08:32:45 GMT</pubDate><category>CVE-2026-21962</category><category>Oracle</category><category>WebLogic</category><category>Zero-Day</category><category>Ransomware</category></item><item><title>SynkLoader Multitool Malware Employs Screen Hijacking</title><link>https://runtimerebel.com/blog/synkloader-multitool-malware-employs-screen-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/synkloader-multitool-malware-employs-screen-hijacking</guid><description>SynkLoader multitool malware leverages screen hijacking techniques and novel features for password theft, signaling potential ransomware threats.</description><pubDate>Mon, 24 Aug 2026 16:27:26 GMT</pubDate><category>Malware</category><category>Ransomware</category><category>Credential Theft</category><category>SynkLoader</category></item><item><title>AI-Powered PLC Attacks Target Critical Infrastructure</title><link>https://runtimerebel.com/blog/ai-powered-plc-attacks-target-critical-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-powered-plc-attacks-target-critical-infrastructure</guid><description>U.S. agencies warn that threat actors are using AI to target internet-exposed Siemens S7 Series PLCs in critical infrastructure sectors.</description><pubDate>Mon, 24 Aug 2026 16:24:49 GMT</pubDate><category>Siemens</category><category>Zero-Day</category><category>Ransomware</category><category>Supply Chain Attack</category><category>Vulnerabilities</category></item><item><title>SynkLoader Malware Steals Credentials in Microsoft Teams Phishing</title><link>https://runtimerebel.com/blog/synkloader-malware-steals-credentials-in-microsoft-teams-phishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/synkloader-malware-steals-credentials-in-microsoft-teams-phishing</guid><description>New SynkLoader malware distributed via Microsoft Teams phishing campaigns uses a fake lock screen to steal Windows credentials, enabling corporate network access.</description><pubDate>Sat, 22 Aug 2026 00:40:08 GMT</pubDate><category>Malware</category><category>Phishing</category><category>Microsoft Teams</category><category>Credential Theft</category><category>Ransomware</category></item><item><title>CISA Warns of Active Ray Exploit and Medusa Ransomware Campaign</title><link>https://runtimerebel.com/blog/cisa-warns-of-active-ray-exploit-and-medusa-ransomware-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-warns-of-active-ray-exploit-and-medusa-ransomware-campaign</guid><description>SecurityWeek weekly briefing highlights active exploitation of Ray flaw by RondoDox botnet, Medusa ransomware, and Salt Typhoon breaches.</description><pubDate>Fri, 21 Aug 2026 16:23:31 GMT</pubDate><category>Ray Project</category><category>CVE-2025-62593</category><category>Medusa</category><category>Salt Typhoon</category><category>Ransomware</category></item><item><title>Mitigating Large-Scale Credential Attacks and Password Spraying</title><link>https://runtimerebel.com/blog/mitigating-large-scale-credential-attacks-and-password-spraying</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitigating-large-scale-credential-attacks-and-password-spraying</guid><description>Analysis of large-scale password spraying and credential theft campaigns targeting enterprise identity perimeters, edge devices, and cloud tenants.</description><pubDate>Wed, 19 Aug 2026 00:42:17 GMT</pubDate><category>Credential Theft</category><category>Ransomware</category><category>Phishing</category><category>Zero-Day</category></item><item><title>AI Overwhelms Patching: Rapid7 Warns of Exposure Crisis</title><link>https://runtimerebel.com/blog/ai-overwhelms-patching-rapid7-warns-of-exposure-crisis</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-overwhelms-patching-rapid7-warns-of-exposure-crisis</guid><description>Rapid7 analysis reveals an AI-driven surge in vulnerabilities is overwhelming traditional patching, requiring a shift to exposure management.</description><pubDate>Wed, 19 Aug 2026 00:41:09 GMT</pubDate><category>AI</category><category>Vulnerability Management</category><category>Patching</category><category>Ransomware</category><category>Nation State</category></item><item><title>Ransom Busters Ransomware Affiliate Poses as Recovery Firm</title><link>https://runtimerebel.com/blog/ransom-busters-ransomware-affiliate-poses-as-recovery-firm</link><guid isPermaLink="true">https://runtimerebel.com/blog/ransom-busters-ransomware-affiliate-poses-as-recovery-firm</guid><description>A ransomware affiliate masquerades as an incident recovery service to intercept victims, divert negotiations, and manipulate ransom payments.</description><pubDate>Tue, 18 Aug 2026 16:22:56 GMT</pubDate><category>Ransomware</category><category>Threat Intelligence</category><category>Incident Response</category><category>Social Engineering</category></item><item><title>Microsoft Removes WMIC Tool in Windows 11 to Curb Living-off-the-Land Tactics</title><link>https://runtimerebel.com/blog/microsoft-removes-wmic-tool-in-windows-11-to-curb-living-off-the-land-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-removes-wmic-tool-in-windows-11-to-curb-living-off-the-land-tactics</guid><description>Microsoft removes the legacy WMIC tool from Windows 11 builds to disrupt living-off-the-land techniques used by ransomware and malware.</description><pubDate>Tue, 18 Aug 2026 08:25:06 GMT</pubDate><category>Microsoft</category><category>Windows 11</category><category>Ransomware</category><category>Malware</category><category>Living-off-the-Land</category></item><item><title>Clop Ransomware Exploits CVE-2026-12569 in PTC Products</title><link>https://runtimerebel.com/blog/clop-ransomware-exploits-cve-2026-12569-in-ptc-products</link><guid isPermaLink="true">https://runtimerebel.com/blog/clop-ransomware-exploits-cve-2026-12569-in-ptc-products</guid><description>Shell investigates potential data theft by Clop gang after exploitation of critical CVE-2026-12569 in PTC Windchill and FlexPLM instances.</description><pubDate>Sun, 16 Aug 2026 08:18:07 GMT</pubDate><category>Ransomware</category><category>Data Theft</category><category>PTC Windchill</category><category>Clop</category><category>CVE-2026-12569</category></item><item><title>Data Analyst Sentenced to Prison for Extorting Brightly Software</title><link>https://runtimerebel.com/blog/data-analyst-sentenced-to-prison-for-extorting-brightly-software</link><guid isPermaLink="true">https://runtimerebel.com/blog/data-analyst-sentenced-to-prison-for-extorting-brightly-software</guid><description>A former data analyst contractor was sentenced to two years in prison for orchestrating a $2.5 million cryptocurrency extortion scheme against Brightly.</description><pubDate>Fri, 14 Aug 2026 08:59:48 GMT</pubDate><category>Data Breach</category><category>Credential Theft</category><category>Ransomware</category><category>Insider Threat</category></item><item><title>Picus Blue Report 2026: Enterprise Edge Defenses vs Post-Compromise</title><link>https://runtimerebel.com/blog/picus-blue-report-2026-enterprise-edge-defenses-vs-post-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/picus-blue-report-2026-enterprise-edge-defenses-vs-post-compromise</guid><description>Analysis of the Picus Labs Blue Report 2026 reveals strong enterprise perimeter defenses, but severe blind spots for internal reconnaissance and credential theft.</description><pubDate>Fri, 14 Aug 2026 01:06:18 GMT</pubDate><category>Credential Theft</category><category>Malware</category><category>Ransomware</category><category>Zero-Day</category><category>Threat Intel</category></item><item><title>Ransomware Attack Hits Colombian Justice Ministry</title><link>https://runtimerebel.com/blog/ransomware-attack-hits-colombian-justice-ministry</link><guid isPermaLink="true">https://runtimerebel.com/blog/ransomware-attack-hits-colombian-justice-ministry</guid><description>A ransomware attack targets the Colombian Justice Ministry days before a presidential transition, highlighting regional risks.</description><pubDate>Wed, 12 Aug 2026 16:49:50 GMT</pubDate><category>Ransomware</category><category>Critical Infrastructure</category><category>Government</category><category>Colombia</category></item><item><title>Gunra Ransomware Exploits Fortinet Flaws and Bypasses MFA</title><link>https://runtimerebel.com/blog/gunra-ransomware-exploits-fortinet-flaws-and-bypasses-mfa</link><guid isPermaLink="true">https://runtimerebel.com/blog/gunra-ransomware-exploits-fortinet-flaws-and-bypasses-mfa</guid><description>Gunra ransomware targets critical infrastructure using leaked Conti code, old Fortinet vulnerabilities, and MFA bypass techniques.</description><pubDate>Wed, 12 Aug 2026 09:05:47 GMT</pubDate><category>Ransomware</category><category>Fortinet</category><category>Credential Theft</category><category>Critical Infrastructure</category></item><item><title>Deadlock Ransomware Uses Blockchain for C2 Resilience</title><link>https://runtimerebel.com/blog/deadlock-ransomware-uses-blockchain-for-c2-resilience</link><guid isPermaLink="true">https://runtimerebel.com/blog/deadlock-ransomware-uses-blockchain-for-c2-resilience</guid><description>Deadlock ransomware uses Polygon blockchain smart contracts and Session to resist infrastructure takedown and evade law enforcement.</description><pubDate>Wed, 12 Aug 2026 01:06:22 GMT</pubDate><category>Ransomware</category><category>Blockchain</category><category>Polygon</category><category>Malware</category><category>Double Extortion</category></item><item><title>Geopolitical AI Supply Chain Threats and Cyber Espionage</title><link>https://runtimerebel.com/blog/geopolitical-ai-supply-chain-threats-and-cyber-espionage</link><guid isPermaLink="true">https://runtimerebel.com/blog/geopolitical-ai-supply-chain-threats-and-cyber-espionage</guid><description>Examine how state-sponsored threat groups and criminal syndicates target the global AI supply chain, from rare earth minerals to silicon chips.</description><pubDate>Tue, 11 Aug 2026 16:53:21 GMT</pubDate><category>Threat Intel</category><category>Ransomware</category><category>Zero-Day</category><category>Supply Chain Attack</category><category>RedJuliett</category></item><item><title>Hackers Breach Polish CHP Plant via Private APN and Teltonika Router</title><link>https://runtimerebel.com/blog/hackers-breach-polish-chp-plant-via-private-apn-and-teltonika-router</link><guid isPermaLink="true">https://runtimerebel.com/blog/hackers-breach-polish-chp-plant-via-private-apn-and-teltonika-router</guid><description>Attackers breached a Polish combined heat and power plant via a private APN, shutting down a steam turbine and water treatment system.</description><pubDate>Tue, 11 Aug 2026 08:44:42 GMT</pubDate><category>Critical Infrastructure</category><category>Ransomware</category><category>Fortinet</category><category>Teltonika</category><category>Siemens</category></item><item><title>SonicWall SMA1000 Exploited: Ransomware Targets CVE-2026-15409/15410</title><link>https://runtimerebel.com/blog/sonicwall-sma1000-exploited-ransomware-targets-cve-2026-15409-15410</link><guid isPermaLink="true">https://runtimerebel.com/blog/sonicwall-sma1000-exploited-ransomware-targets-cve-2026-15409-15410</guid><description>CISA confirms ransomware exploitation of SonicWall SMA1000 flaws CVE-2026-15409 and CVE-2026-15410, urging immediate patching.</description><pubDate>Mon, 10 Aug 2026 16:44:58 GMT</pubDate><category>Ransomware</category><category>Zero-Day</category><category>CVE-2026-15409</category><category>CVE-2026-15410</category><category>CVE-2025-40602</category></item><item><title>AI-Driven Vulnerability Surges and UAT-11795 Starland RAT Campaign</title><link>https://runtimerebel.com/blog/ai-driven-vulnerability-surges-and-uat-11795-starland-rat-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-driven-vulnerability-surges-and-uat-11795-starland-rat-campaign</guid><description>Analysis of a record Patch Tuesday driven by AI vulnerability research, alongside Cisco Talos findings on UAT-11795 deploying Starland RAT.</description><pubDate>Sat, 08 Aug 2026 08:31:29 GMT</pubDate><category>Threat Intel</category><category>Zero-Day</category><category>Ransomware</category><category>Remcos</category><category>Python</category></item><item><title>Cisco Talos Previews AI Threats and Warlock Ransomware at Black Hat</title><link>https://runtimerebel.com/blog/cisco-talos-previews-ai-threats-and-warlock-ransomware-at-black-hat</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-talos-previews-ai-threats-and-warlock-ransomware-at-black-hat</guid><description>Cisco Talos outlines research on AI threat actor tactics, Warlock ransomware, and agent identity security ahead of Black Hat USA 2026.</description><pubDate>Sat, 08 Aug 2026 08:30:27 GMT</pubDate><category>Ransomware</category><category>Zero-Day</category><category>Threat Intel</category></item><item><title>Russia&apos;s Defense Economy and Ongoing Cyber and Physical Threats</title><link>https://runtimerebel.com/blog/russia-s-defense-economy-and-ongoing-cyber-and-physical-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/russia-s-defense-economy-and-ongoing-cyber-and-physical-threats</guid><description>Analysis of Russia&apos;s defense-based economy, rising military spending, elite patronage networks, and the resulting high-risk threat environment.</description><pubDate>Sat, 08 Aug 2026 01:03:43 GMT</pubDate><category>Threat Intel</category><category>Ransomware</category><category>Supply Chain Attack</category></item><item><title>Q2 2026 IR Trends: Phishing, MFA Bypass, RMM Tool Abuse</title><link>https://runtimerebel.com/blog/q2-2026-ir-trends-phishing-mfa-bypass-rmm-tool-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/q2-2026-ir-trends-phishing-mfa-bypass-rmm-tool-abuse</guid><description>Talos Q2 2026 incident response data shows rising phishing and MFA bypass, with new actors like UAT-11764 and Sinobi ransomware leveraging RMM tools.</description><pubDate>Sat, 08 Aug 2026 00:57:13 GMT</pubDate><category>Phishing</category><category>MFA Bypass</category><category>Ransomware</category><category>Microsoft 365</category><category>UAT 11764</category></item><item><title>Emerging Cyber Threats and Espionage Risks in Neurotechnology</title><link>https://runtimerebel.com/blog/emerging-cyber-threats-and-espionage-risks-in-neurotechnology</link><guid isPermaLink="true">https://runtimerebel.com/blog/emerging-cyber-threats-and-espionage-risks-in-neurotechnology</guid><description>Examine growing security threats to neurotechnology and brain-computer interfaces, focusing on IP theft, biometric data collection, and state-sponsored espionage.</description><pubDate>Fri, 07 Aug 2026 02:14:32 GMT</pubDate><category>Zero-Day</category><category>Ransomware</category><category>Supply Chain Attack</category><category>Credential Theft</category></item><item><title>UNC6671 Rebrands: Multi-Brand Vishing and Cloud Extortion</title><link>https://runtimerebel.com/blog/unc6671-rebrands-multi-brand-vishing-and-cloud-extortion</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6671-rebrands-multi-brand-vishing-and-cloud-extortion</guid><description>Google Threat Intelligence Group tracks UNC6671 shifting through Redact, Pink, Helix, and Falcon extortion brands while targeting cloud environments.</description><pubDate>Fri, 07 Aug 2026 02:12:08 GMT</pubDate><category>UNC6671</category><category>Phishing</category><category>Credential Theft</category><category>Ransomware</category><category>Cloud Security</category></item><item><title>Canadian Threat Actor Pleads Guilty in Snowflake Extortions</title><link>https://runtimerebel.com/blog/canadian-threat-actor-pleads-guilty-in-snowflake-extortions</link><guid isPermaLink="true">https://runtimerebel.com/blog/canadian-threat-actor-pleads-guilty-in-snowflake-extortions</guid><description>Connor Riley Moucka pleaded guilty to computer fraud and extortion involving 165 Snowflake client organizations and AT&amp;T customer records.</description><pubDate>Fri, 07 Aug 2026 02:10:26 GMT</pubDate><category>Credential Theft</category><category>Ransomware</category><category>Data Breach</category><category>Snowflake</category></item><item><title>Automated SSH Actors Achieve Persistence in 22 Seconds</title><link>https://runtimerebel.com/blog/automated-ssh-actors-achieve-persistence-in-22-seconds</link><guid isPermaLink="true">https://runtimerebel.com/blog/automated-ssh-actors-achieve-persistence-in-22-seconds</guid><description>Analysis of a Cowrie SSH honeypot reveals automated threat actors moving from credential compromise to system persistence in just 22 seconds.</description><pubDate>Thu, 06 Aug 2026 01:59:52 GMT</pubDate><category>Ransomware</category><category>Brute Force</category><category>Credential Theft</category><category>SSH</category></item><item><title>Talos Q2 2026 Report: Phishing and Living-off-the-Land Trends</title><link>https://runtimerebel.com/blog/talos-q2-2026-report-phishing-and-living-off-the-land-trends</link><guid isPermaLink="true">https://runtimerebel.com/blog/talos-q2-2026-report-phishing-and-living-off-the-land-trends</guid><description>Cisco Talos Q2 2026 report reveals spikes in MFA-bypassing phishing and malicious use of remote management tools.</description><pubDate>Thu, 06 Aug 2026 01:57:17 GMT</pubDate><category>Phishing</category><category>Ransomware</category><category>Credential Theft</category><category>Multi Factor Authentication</category><category>Threat Intel</category></item><item><title>Ransom Cartel Ransomware Creator Sentenced to 16 Years in Prison</title><link>https://runtimerebel.com/blog/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison</link><guid isPermaLink="true">https://runtimerebel.com/blog/ransom-cartel-ransomware-creator-sentenced-to-16-years-in-prison</guid><description>Maksim Silnikau, creator of the Ransom Cartel ransomware operation, receives a 16-year prison sentence following international law enforcement cooperation.</description><pubDate>Thu, 06 Aug 2026 01:56:23 GMT</pubDate><category>Ransom Cartel</category><category>Ransomware</category><category>REvil</category><category>Credential Theft</category><category>Extortion</category></item><item><title>Smoke#Screen RMM Takeover Campaign Targets Enterprise Networks</title><link>https://runtimerebel.com/blog/smoke-screen-rmm-takeover-campaign-targets-enterprise-networks</link><guid isPermaLink="true">https://runtimerebel.com/blog/smoke-screen-rmm-takeover-campaign-targets-enterprise-networks</guid><description>Discover how the Smoke#Screen phishing campaign uses rotating payloads and ScreenConnect to achieve persistent remote network access.</description><pubDate>Wed, 05 Aug 2026 01:42:03 GMT</pubDate><category>Phishing</category><category>Ransomware</category><category>Credential Theft</category><category>Screenconnect</category></item><item><title>Operation Cronos: FBI&apos;s Strategy to Disrupt LockBit Ransomware-as-a-Service</title><link>https://runtimerebel.com/blog/operation-cronos-fbi-s-strategy-to-disrupt-lockbit-ransomware-as-a-service</link><guid isPermaLink="true">https://runtimerebel.com/blog/operation-cronos-fbi-s-strategy-to-disrupt-lockbit-ransomware-as-a-service</guid><description>Analysis of Operation Cronos&apos;s success in disrupting LockBit, focusing on how law enforcement leveraged affiliate trust to dismantle the ransomware giant.</description><pubDate>Mon, 27 Jul 2026 21:13:16 GMT</pubDate><category>LockBit</category><category>Operation Cronos</category><category>Ransomware</category><category>FBI</category><category>Affiliate Trust</category><category>RaaS</category></item><item><title>Coca-Cola Subsidiary Fairlife Impacted by Ransomware Data Theft</title><link>https://runtimerebel.com/blog/coca-cola-subsidiary-fairlife-impacted-by-ransomware-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/coca-cola-subsidiary-fairlife-impacted-by-ransomware-data-theft</guid><description>The Coca-Cola Company confirms a data breach at subsidiary Fairlife following a ransomware attack. Learn about the impact and mitigation strategies.</description><pubDate>Mon, 27 Jul 2026 17:43:54 GMT</pubDate><category>Fairlife</category><category>Coca Cola</category><category>Ransomware</category><category>Data Exfiltration</category><category>Third Party Risk</category></item><item><title>PTC Windchill RCE via CVE-2022-25247 — Mitigation Guide</title><link>https://runtimerebel.com/blog/ptc-windchill-rce-via-cve-2022-25247-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/ptc-windchill-rce-via-cve-2022-25247-mitigation-guide</guid><description>Attackers are exploiting a critical deserialization flaw in PTC Windchill PLM software to deploy ransomware. Learn how to detect and patch CVE-2022-25247.</description><pubDate>Mon, 27 Jul 2026 14:40:34 GMT</pubDate><category>CVE-2022-25247</category><category>PTC Windchill</category><category>Ransomware</category><category>RCE</category><category>PLM Software</category></item><item><title>Ransomware as a Defensive Metric: Leveraging AI for Attack Path Remediation</title><link>https://runtimerebel.com/blog/ransomware-as-a-defensive-metric-leveraging-ai-for-attack-path-remediation</link><guid isPermaLink="true">https://runtimerebel.com/blog/ransomware-as-a-defensive-metric-leveraging-ai-for-attack-path-remediation</guid><description>Learn why ransomware reveals architectural defense gaps. This analysis explains how AI and proactive threat intelligence can fortify defenses and remediate critical…</description><pubDate>Fri, 24 Jul 2026 17:43:13 GMT</pubDate><category>Ransomware</category><category>Threat Intelligence</category><category>AI</category><category>Attack Paths</category><category>Cybersecurity Strategy</category><category>Defensive Architecture</category></item><item><title>Multi-Threat Brief: AI Malware, Zimbra Exploits, Linux Kernel Flaws</title><link>https://runtimerebel.com/blog/multi-threat-brief-ai-malware-zimbra-exploits-linux-kernel-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/multi-threat-brief-ai-malware-zimbra-exploits-linux-kernel-flaws</guid><description>Analysis of recent threats including DolphinX AI malware, state-sponsored Zimbra exploits, Siemens industrial switch vulnerabilities, and 400 Linux kernel flaws.</description><pubDate>Fri, 24 Jul 2026 17:42:24 GMT</pubDate><category>DolphinX</category><category>Emerald Sleet</category><category>Winter Vivern</category><category>UNC4841</category><category>Zimbra</category><category>Linux Kernel</category><category>Siemens ROX II</category><category>Industrial Control Systems</category><category>APT</category><category>Ransomware</category><category>LockBit</category></item><item><title>PTC Windchill and FlexPLM Targeted in Clop Data Theft Campaign</title><link>https://runtimerebel.com/blog/ptc-windchill-and-flexplm-targeted-in-clop-data-theft-campaign</link><guid isPermaLink="true">https://runtimerebel.com/blog/ptc-windchill-and-flexplm-targeted-in-clop-data-theft-campaign</guid><description>Clop ransomware targets PTC Windchill and FlexPLM systems. Learn about the CVE-2022-25247 exploit risks and how to secure exposed PLM instances from extortion.</description><pubDate>Fri, 24 Jul 2026 10:20:39 GMT</pubDate><category>Clop</category><category>PTC Windchill</category><category>FlexPLM</category><category>CVE-2022-25247</category><category>Ransomware</category></item><item><title>Ransomware Attack Freezes Japanese Food Supply Chain Operations</title><link>https://runtimerebel.com/blog/ransomware-attack-freezes-japanese-food-supply-chain-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/ransomware-attack-freezes-japanese-food-supply-chain-operations</guid><description>A ransomware attack on a Japanese food and logistics firm severely disrupted frozen food supply to thousands of clients, including KFC. Analyze the impact.</description><pubDate>Thu, 23 Jul 2026 02:52:03 GMT</pubDate><category>Ransomware</category><category>Supply Chain Attack</category><category>Food Sector</category><category>Japan</category><category>Logistics</category></item><item><title>Enterprise GenAI Amplifies Ransomware Risk: Containment Strategies</title><link>https://runtimerebel.com/blog/enterprise-genai-amplifies-ransomware-risk-containment-strategies</link><guid isPermaLink="true">https://runtimerebel.com/blog/enterprise-genai-amplifies-ransomware-risk-containment-strategies</guid><description>Enterprise GenAI tools can accelerate ransomware attacks by inheriting excessive permissions.</description><pubDate>Wed, 22 Jul 2026 17:22:10 GMT</pubDate><category>GenAI</category><category>Ransomware</category><category>AI Security</category><category>Least Privilege</category><category>Identity Management</category></item><item><title>Everest Ransomware Targets Stadler Rail&apos;s Supply Chain</title><link>https://runtimerebel.com/blog/everest-ransomware-targets-stadler-rail-s-supply-chain</link><guid isPermaLink="true">https://runtimerebel.com/blog/everest-ransomware-targets-stadler-rail-s-supply-chain</guid><description>Stadler Rail faced a $12.3M ransom demand from Everest ransomware after a data breach affecting a supplier data exchange platform.</description><pubDate>Wed, 22 Jul 2026 17:21:52 GMT</pubDate><category>Everest Ransomware</category><category>Stadler Rail</category><category>Supply Chain Attack</category><category>Data Breach</category><category>Ransomware</category></item><item><title>PAN-OS GlobalProtect Authentication Bypass Exploited by Qilin</title><link>https://runtimerebel.com/blog/pan-os-globalprotect-authentication-bypass-exploited-by-qilin</link><guid isPermaLink="true">https://runtimerebel.com/blog/pan-os-globalprotect-authentication-bypass-exploited-by-qilin</guid><description>The Qilin ransomware gang is actively exploiting a critical Palo Alto Networks PAN-OS GlobalProtect authentication bypass vulnerability to breach corporate networks.</description><pubDate>Tue, 21 Jul 2026 10:40:15 GMT</pubDate><category>Palo Alto Networks</category><category>PAN OS</category><category>GlobalProtect</category><category>Ransomware</category><category>Qilin</category><category>Authentication Bypass</category><category>VPN</category></item><item><title>ENCFORGE Ransomware Targets AI Systems via Langflow RCE</title><link>https://runtimerebel.com/blog/encforge-ransomware-targets-ai-systems-via-langflow-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/encforge-ransomware-targets-ai-systems-via-langflow-rce</guid><description>New ENCFORGE ransomware, attributed to JADEPUFFER, leverages a Langflow RCE vulnerability to encrypt AI model files, weights, and training data.</description><pubDate>Tue, 21 Jul 2026 10:39:45 GMT</pubDate><category>ENCFORGE</category><category>Ransomware</category><category>JADEPUFFER</category><category>Langflow</category><category>RCE</category><category>AI</category><category>Sysdig</category><category>Golang</category></item><item><title>JadePuffer Ransomware Targets AI Model Data with EncForge</title><link>https://runtimerebel.com/blog/jadepuffer-ransomware-targets-ai-model-data-with-encforge</link><guid isPermaLink="true">https://runtimerebel.com/blog/jadepuffer-ransomware-targets-ai-model-data-with-encforge</guid><description>JadePuffer, an autonomous AI agent, now employs EncForge ransomware to encrypt AI training datasets, vector databases, and model checkpoints, posing a significant threat…</description><pubDate>Mon, 20 Jul 2026 21:13:32 GMT</pubDate><category>JADEPUFFER</category><category>ENCFORGE</category><category>Ransomware</category><category>AI Security</category><category>AI Models</category></item><item><title>Inc Ransomware Exploits SonicWall SMA Zero-Days for Root Access</title><link>https://runtimerebel.com/blog/inc-ransomware-exploits-sonicwall-sma-zero-days-for-root-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/inc-ransomware-exploits-sonicwall-sma-zero-days-for-root-access</guid><description>Inc Ransomware is actively exploiting chained zero-day vulnerabilities in SonicWall SMA appliances, achieving root-level capabilities.</description><pubDate>Fri, 17 Jul 2026 20:59:26 GMT</pubDate><category>INC Ransomware</category><category>SonicWall SMA</category><category>Zero-Day</category><category>Root Access</category><category>Ransomware</category></item><item><title>Diverse Threat Landscape: Military Tracking, macOS Malware, Defense Ransomware</title><link>https://runtimerebel.com/blog/diverse-threat-landscape-military-tracking-macos-malware-defense-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/diverse-threat-landscape-military-tracking-macos-malware-defense-ransomware</guid><description>Analysis of diverse threats including reported Iranian tracking of US military phones, CrashStealer macOS malware, ransomware on a naval firm, and a Lidl data breach.</description><pubDate>Fri, 17 Jul 2026 17:14:58 GMT</pubDate><category>Iran</category><category>US Military</category><category>CrashStealer</category><category>macOS Malware</category><category>Ransomware</category><category>Naval Defense</category><category>TKMS</category><category>Lidl</category><category>Data Breach</category></item><item><title>Fairlife Ransomware Attack Halts US Dairy Production</title><link>https://runtimerebel.com/blog/fairlife-ransomware-attack-halts-us-dairy-production</link><guid isPermaLink="true">https://runtimerebel.com/blog/fairlife-ransomware-attack-halts-us-dairy-production</guid><description>Coca-Cola&apos;s Fairlife dairy subsidiary suffered a ransomware attack, halting US production. Understand the operational impact and defense strategies.</description><pubDate>Fri, 17 Jul 2026 02:46:05 GMT</pubDate><category>Ransomware</category><category>Fairlife</category><category>Coca Cola</category><category>Food Beverage</category><category>Operational Technology</category><category>Supply Chain Attack</category></item></channel></rss>