Two recent incidents in Latin America show a new extortion pattern: attackers encrypt disks with BitLocker and trigger ransom notes via office printers. The cases also reveal recurring misuse of RDP, MSSQL misconfigurations, and RMM tools.
GenieLocker ransomware has been active since March 2026 and targets victims across multiple sectors. It runs on Windows, Linux and ESXi and uses a custom encryption mechanism.
In Central Asia, since January 2025, two new backdoors have been observed: OctLurk and SilkLurk. The attackers use customized loaders, heavy obfuscation, and additional functionality via plug-ins and LurkProxy.
Rapid7 has published a Python PoC to test for CVE-2026-16232. This SmartConsole auth bypass lets attackers obtain an admin login token if the setup allows unauthenticated access.
A critical Ruflo MCP flaw (CVE-2026-59726) lets attackers run commands without authentication. The impact includes API key theft and poisoning of persistent AI memory.
A cybercriminal group, Silver Fox, targeted a Japanese organization in the industrial manufacturing sector. With BYOVD and DLL sideloading, ValleyRAT is delivered for long-term remote access.
CISA added a Cisco FMC zero-day to its KEV catalog after reports of active exploitation. The flaw involves static credentials that could let attackers access sensitive data.
Researchers identified malicious npm packages that smuggled a cross-platform RAT into environments using Alibaba developer tools. The chain can persist, steal data, and move laterally.
Unit 42 investigated how malware on a Windows PC can abuse passkey-protected accounts via Google Password Manager in Chrome. The attack is post-compromise: it only starts once the device has already been taken over.
Resecurity reports that INC ransomware has been claiming victims faster since the beginning of August 2026 via SonicWall SMA 1000. The chain appears to be driven by zero-days that, among other things, abuse MFA seeds and credentials.