AI Attack Surfaces Multiply While Ransomware Strangles Backup Recovery

Charm · September 17, 2026 · 1 min read · 6 sources

News

Ransomware Groups Now Systematically Wiping Cloud Snapshots and SaaS Backups

This isn't just encrypting local drives anymore. Attackers are specifically targeting cloud-native backup mechanisms, which means your disaster recovery plan might be the thing that fails first.

Qilin Ransomware Expands with Dedicated Linux Encryption Module

Qilin's Linux encryptor is purpose-built for production servers, not just opportunistic Windows hits. Expect this to become the default playbook for targeting containerized and cloud workloads.

FBI Issues Warning on Luna Moth Callback Phishing Infrastructure Expansion

Luna Moth's callback phishing operation is industrialized now, using legitimate remote access tools post-compromise. This bypasses traditional email security entirely.

PumaBot Campaign Targets Linux IoT Devices with SSH Brute-Force Botnet

PumaBot is hitting Linux IoT devices hard, specifically cameras and DVRs with weak SSH creds. If your infrastructure touches anything with a default password, this is your wake-up call.

Analysis

Critical SSRF Vulnerability Discovered in AI Inference Service

Another week, another AI tool shipping a server-side request forgery flaw. If you're running AI services internally, your infrastructure assumptions are wrong. Audit the service mesh now.

Tools

Nuclei Templates Add Detection for Emerging AI Service Vulnerabilities

The community is automating detection of the SSRF flaw in AI services. If you run Nuclei in your CI pipeline, pull these templates immediately for coverage against the latest attack surface.

Stay Ahead

Delivered each morning.