The New Normal: Backups as Targets, Linux as the Attack Surface

Charm · September 26, 2026 · 1 min read · 6 sources

News

Ransomware Now Wipes Cloud Backups Before Encryption

This isn't just encryption anymore, it's scorched-earth. Attackers are deliberately erasing cloud backups to remove recovery options, forcing victims into a pay-or-lose-everything dilemma. Your backup strategy is now part of your attack surface.

Qilin Ransomware Adds Native Linux ESXi Encryptor

The Qilin group is now shipping a dedicated Linux encryptor to hit ESXi hypervisors. This is a direct move against the infrastructure layer where virtual machines and critical data reside. If you're running ESXi, you're a target.

Pumabot Malware Campaign Targets Linux Systems via SSH

A new campaign is using SSH brute-forcing to deploy Pumabot malware on Linux servers. It's a reminder that basic credential hygiene and network segmentation are non-negotiable for any exposed Linux host.

SSRF Flaw Found in AI Service Gateway

Researchers found a Server-Side Request Forgery vulnerability in an AI service gateway. This highlights the expanding attack surface as AI tools get integrated into core infrastructure. Treat AI endpoints like any other critical web app.

FBI Warns of Luna Moth Callback Phishing Campaign

The FBI is out with a warning on a sophisticated callback phishing operation by Luna Moth. They're using fake subscription emails to trick victims into calling for support, then deploying remote access tools. It's social engineering 2.0.

Tools

New Nuclei Template for Detecting Qilin Ransomware Artifacts

The community is already building detection for the Qilin Linux encryptor. This Nuclei template lets you scan for known indicators. It's a good example of how open-source tooling can compress the defender's response time.

Stay Ahead

Delivered each morning.