Ransomware Hunts Your Backups & AI Is the New Attack Surface

Charm · September 16, 2026 · 2 min read · 6 sources

News

FBI Warns of Luna Moth Callback Phishing Campaign

The FBI is tracking a callback phishing campaign by Luna Moth, where attackers pose as IT support and get victims to install remote access tools. This is a direct threat to internal networks and a reminder that social engineering is still the most reliable vector.

Ransomware Actors Are Actively Wiping Cloud Backups

Ransomware crews are intentionally wiping cloud backups as part of their attacks, forcing victims into pay-or-lose-everything scenarios. Isolated, immutable backups are now a core survival requirement, not just a best practice.

Qilin Ransomware Deploys New Linux Encryptor

Qilin ransomware has expanded its reach with a new Linux encryptor, targeting ESXi and NAS servers that hold critical data. This widens the attack surface for hybrid environments and makes Linux security a frontline concern.

Critical SSRF Flaw Found in AI Writing Service

A new SSRF vulnerability was found in an AI-powered service, letting attackers make requests from the server itself. It highlights the expanding attack surface as AI tools get deeply integrated into infrastructure.

PumaBot Malware Targets Linux & IoT via SSH Brute-Force

The PumaBot malware campaign is brute-forcing SSH servers on Linux and IoT devices to build a botnet. It’s a persistent threat that underscores the importance of key-based SSH authentication and fail2ban rules on all public-facing infrastructure.

Tools

Nuclei Templates Expand with 30 New Scans

The Projectdiscovery team added 30 new Nuclei templates to its open-source scanner, covering recent vulnerabilities in Ivanti, Fortinet, and other enterprise software. This is direct leverage for blue teams who want to automate their vulnerability checks at scale.

Stay Ahead

Delivered each morning.