Ransomware's Triple Threat: Backups, Linux, and AI Flaws

Charm · September 20, 2026 · 1 min read · 6 sources

News

Ransomware Actors Now Erase Cloud Backups to Maximize Impact

This is the new baseline. Attackers aren't just encrypting data; they're systematically destroying recovery options. Your backup strategy needs to be immutable and offline, yesterday.

Qilin Ransomware Adds Dedicated Linux Encryptor for ESXi

The Linux/ESXi attack surface keeps getting hotter. If you're running virtualized infrastructure, hardening just got more urgent. This is a direct threat to cloud and data center ops.

FBI Warns of Luna Moth's Evolved Callback Phishing Campaigns

Callback phishing is a proven initial access vector. This update means the social engineering playbook is getting more sophisticated. Train your helpdesk and implement strict verification.

PumaBot Malware Campaign Aggressively Targets Linux via SSH

Another botnet exploiting weak SSH credentials on Linux. This isn't new, but the campaign's scale is a reminder: automate credential rotation and enforce key-based auth.

Tools

Nuclei Templates Expand with New Scan Automation

More templates mean faster, broader vulnerability scanning. This is a force multiplier for red teams and defensive automation. Keep your template library updated.

Analysis

Critical SSRF Flaw Found in AI Service Infrastructure

AI tools are becoming the new attack surface. A server-side request forgery flaw here can lead to internal network pivoting. Patch or mitigate immediately if you're using similar services.

Stay Ahead

Delivered each morning.