Ransomware Activity Rebounds in July
New data indicates a sharp rise in ransomware incidents throughout July 2026, breaking a multi-month period of lower activity.
Data breaches, ransomware payouts, and phishing operations rarely make the news until the damage is already done. This is where Xploitwire tracks the attackers — who they are, how they got in, and what it means for the organizations and people caught in the blast radius.
New data indicates a sharp rise in ransomware incidents throughout July 2026, breaking a multi-month period of lower activity.
A self-propagating malware campaign has compromised over 1,300 npm packages, leveraging legitimate GitHub workflows to spread.
A cyberattack on the CRM provider Beacon has resulted in the potential theft of sensitive database backups for numerous UK charities.
New data reveals a surge in violent physical thefts targeting cryptocurrency holders, with millions lost in the first half of 2026.
A Canadian national has admitted to his role in a massive 2024 campaign that compromised over 165 major corporate Snowflake accounts.
The Police National Legal Database confirms a data breach involving over 100,000 records of officers and legal professionals.
New npm malware hides command-and-control infrastructure within zero-value Ethereum transfer addresses to bypass traditional detection.
Phishing service Greatness uses spoofed RingCentral emails to bypass MFA and compromise Microsoft 365 accounts.
Researchers identify a sophisticated phishing campaign using brand impersonation to deploy remote access malware on Windows.
A malicious campaign on the Open VSX marketplace deployed 77 counterfeit extensions to harvest developer metadata.
A malicious version of the Xeno Executor mod is infecting computers with a RAT, granting attackers full control over user devices.
A new report identifies a strategic shift among threat actors, moving away from simple malware toward identity and trust-based exploits.
Microsoft identifies a state-sponsored campaign exploiting hotel captive portals to deploy infostealers and harvest credentials.
The extortion group ShinyHunters has leaked 41 gigabytes of data following a security incident at the Dallas-based home security firm.
Threat actors are actively chaining two critical SonicWall vulnerabilities to deploy ransomware and escalate privileges to root.
A firmware vulnerability in Coinkite devices has been linked to the loss of over 1,300 Bitcoin in recent address sweeps.
A federal judge declined to block a Minnesota law targeting image-manipulation software, citing significant delays in legal filing.
Researchers have identified a threat actor using the DeepSeek AI model to automate the lifecycle of cyberattacks on exposed servers.
Researchers report a rise in AI-driven malware and evolving social engineering, marking a shift in how attackers scale operations.
A health IT firm is notifying over 350,000 individuals following an unauthorized access incident within its AWS environment.