Ransomware Targets Backups and ESXi While Callback Phishing Resurges

Charm · September 18, 2026 · 1 min read · 6 sources

News

FBI Warns of Resurgent "Luna Moth" Callback Phishing Campaigns

The FBI's IC3 is sounding the alarm on a fresh wave of callback phishing campaigns. Attackers are impersonating help desks from major brands to trick victims into installing remote access tools on their endpoints—a classic pivot that bypasses email filters.

Malware

Qilin Ransomware Deploys New Linux/ESXi Encryptor

The Qilin group is expanding beyond Windows, shipping a new encryptor specifically designed for VMware ESXi hypervisors. If you're running virtualized infrastructure, this is a direct signal to harden your hypervisor access controls.

PumaBot Campaign Targets IoT via SSH Credential Stuffing

PumaBot is a new Go-based botnet aggressively brute-forcing weak SSH credentials to compromise Linux-based IoT devices. Once inside, it drops cryptocurrency miners and uses the host for proxy jacking.

Incident Response

Ransomware Groups Now Systematically Wiping Cloud Backups

Modern ransomware operations are shifting tactics to target cloud-based backups and object storage (S3/GCS) early in an attack chain. This makes immutable backups and air-gapped recovery copies non-negotiable for any contingency plan.

Vulnerabilities

SSRF Flaw Found in AI Service Deployment

Security researchers identified a Server-Side Request Forgery (SSRF) flaw in an AI service, highlighting the continuous need to harden APIs even in newer AI-driven stacks. It's a reminder that not all vulnerabilities are in legacy code.

Tools

Nuclei Templates Repository Gets Major Update

Projectdiscovery just merged a major update to the nuclei templates repository, adding detection logic for over 110 new vulnerabilities. If Nuclei is part of your scanning pipeline, pulling this update should be on your to-do list for the week.

Stay Ahead

Delivered each morning.