Malware Attack Forces South Carolina Health System AnMed to Close 79 of 106 Facilities
AnMed shut most of its clinics after a malware disruption hit its network; emergency rooms stayed open and physician offices began reopening Tuesday.
Signal
21 articles covering "ransomware"
AnMed shut most of its clinics after a malware disruption hit its network; emergency rooms stayed open and physician offices began reopening Tuesday.
CVE-2026-15409 and CVE-2026-15410 were exploited together against SMA1000 appliances before patches shipped, CISA says.
Sysdig says JadePuffer used an LLM agent to exploit Langflow flaw CVE-2025-3248, run 600-plus payloads, and encrypt 1,342 Nacos config items.
Symantec ties the in-memory Mistic backdoor to access broker KongTuke, whose footholds have fed Qilin, Akira, Black Basta and other ransomware groups since April 2026.
Law enforcement seized 326 servers and froze 47 million dollars in crypto, while Microsoft filed RICO claims against five defendants after AI tools tied the two malware suites to shared infrastructure.
A logic flaw in Check Point's deprecated IKEv1 certificate validation let attackers bypass VPN authentication. CISA added it to KEV with a June 11 deadline.
Rapid7 links a Chaos ransomware intrusion in early 2026 to Iranian state-linked MuddyWater, finding no encryption deployed — only credential theft and data exfiltration under ransomware cover.
The 2026 DBIR finds 31% of breaches now begin with unpatched vulnerabilities -- surpassing credential abuse for the first time in the report's 19-year history -- as median patch time climbs to 43 days and ransomware reaches 48% of all breaches.
Microsoft's Digital Crimes Unit seized signspace.cloud and revoked more than 1,000 fraudulent code-signing certificates after Fox Tempest sold access to Azure Artifact Signing for $5,000–$9,000 per transaction to ransomware groups including Rhysida, Akira, and Qilin.
World's largest electronics manufacturer acknowledges cyberattack claimed by Nitrogen ransomware group on North American factories; attackers allege 8 TB data theft including confidential schematics for Apple, Nvidia, Google and others, with production now resuming.
CISA's April 24 KEV update flags four actively exploited vulnerabilities tied to ransomware against managed service providers and Mirai DDoS botnets, with a May 8 federal patching deadline.
A researcher's protest disclosure turned Microsoft Defender's remediation engine into an attack vector, with two of three zero-days remaining unpatched as ransomware actors move in.