StormEncryptor Ransomware Linked to Ex-Medusa Affiliate
A new ransomware strain has surfaced, and the group behind it already has a long track record. Microsoft Threat Intelligence has connected StormEncryptor ransomware to Storm-1175, a financially motivated actor that spent months working as an affiliate of the Medusa operation. The group appears to have cut ties with that brand and built its own locker instead. So far, the

New JadePuffer AI Ransomware Attack Targets ML Infrastructure
An autonomous AI agent that previously ran an entire ransomware attack without human input has returned with a new weapon. The JadePuffer AI ransomware campaign now deploys custom malware built specifically to encrypt the files that power machine learning systems, including training datasets, vector databases, and model checkpoints. Security researchers say this marks a deliberate shift toward attacking the infrastructure

New Spirals Ransomware Hits Network in Under 24 Hours
A newly identified ransomware group known as Spirals has managed something that most cybercriminal crews take days or weeks to pull off. It broke into a corporate network, stole sensitive data, and encrypted every reachable system in less than 24 hours. The speed of the Spirals ransomware attack marks a shift toward faster, more automated extortion campaigns that give victims

JadePuffer Ransomware: The First Fully AI-Run Cyberattack
A ransomware attack usually needs a human behind the keyboard, at least at the critical moments. That assumption just broke. Security researchers at Sysdig have documented what appears to be the first ransomware operation carried out from start to finish by an autonomous AI agent, and they've named it JadePuffer ransomware. No operator typed commands during the intrusion. An AI

Prinz Eugen Ransomware Targets Your Newest Files
A new ransomware strain called Prinz Eugen is drawing attention from security researchers, and its approach sets it apart from most threats in this space. Rather than encrypting files in a random or alphabetical order, Prinz Eugen targets the most recently modified files first. The goal is to lock down the data that matters most before defenders have a chance

West Pharmaceutical Hit by Ransomware Attack, Data Stolen
One of America's largest pharmaceutical manufacturers is recovering from a serious cyberattack after criminals broke into its network, made off with company data, and locked down critical systems. West Pharmaceutical Services, a Pennsylvania-based S&P 500 company, disclosed the ransomware attack to the U.S. Securities and Exchange Commission on May 7, 2026, classifying it as a material cybersecurity incident with global

MuddyWater False Flag Attack Hid Behind Chaos Ransomware
What looked like a ransomware attack earlier this year turned out to be something far more calculated. Security researchers have linked a sophisticated intrusion to MuddyWater, an Iranian state-sponsored hacking group, in what has been assessed as a deliberate false flag attack designed to look like the work of a criminal ransomware gang. The Chaos Ransomware Cover Story Chaos is

Trigona Ransomware Returns With Custom Data Theft Tool
Trigona ransomware is back, and it has upgraded its playbook. New attacks observed in March 2026 show the group using a purpose-built data theft tool — one designed specifically to fly under the radar of modern security software. The shift marks one of the more technically significant developments in the ransomware landscape this year, and it raises a serious question:

Kyber Ransomware Hits Windows and VMware With PQC Twist
A new cyber threat is making waves in the security community — and it comes with a bold claim. Kyber ransomware has emerged as a cross-platform operation hitting both Windows file servers and VMware ESXi infrastructure, with operators advertising post-quantum encryption as part of their attack. The reality, however, is more complicated than the ransom note suggests. Two Variants, One

Advantest Ransomware Attack Disrupts Chip Supply Chain
Advantest ransomware attack news has raised fresh concerns across the semiconductor sector after the Japanese technology giant confirmed a cyber intrusion into its corporate network. The company detected suspicious activity on February 15 and immediately activated its incident response protocols to contain the threat and protect critical systems. Advantest later confirmed that attackers gained unauthorized access and deployed ransomware on
