New Prinz Eugen ransomware prioritizes recent files for encryption

2026-06-21T07:23:26Z52289daa49d50713fdfd63ccc92e8023434bcc0bedaf4aae919eba98c7d2910b
BlueNoroffCISAEDR evasionFortiBleedFortinetGentlemen ransomwareGravity SMTPIcarusKlueMastra AIOAuth breachPII exposurePrinz EugenSapphire SleetSplunk EnterpriseTexas Parks and WildlifeUSB wormWordPressactive exploitationcredentials leakcryptocurrency malwaredata breachinformation disclosureransomwaresupply chain

What happened

Collection of Jun 18–20, 2026 security reports: a new Prinz Eugen ransomware prioritizes recently modified files and leaves no ransom note; Microsoft links the Mastra AI supply-chain compromise of 140+ npm packages to North Korea’s Sapphire Sleet (BlueNoroff); Klue confirms an OAuth token breach enabling the Icarus extortion group to access customer Salesforce environments; an unauthenticated information disclosure in the Gravity SMTP WordPress plugin is being actively exploited on ~100k sites; Texas Parks and Wildlife vendor breach exposed >3 million driver’s license records; CISA warns of an

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
52289daa49d50713fdfd63ccc92e8023434bcc0bedaf4aae919eba98c7d2910b
Enrichment time
2026-06-21T07:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.