New Prinz Eugen ransomware prioritizes recent files for encryption
2026-06-21T07:23:26Z•52289daa49d50713fdfd63ccc92e8023434bcc0bedaf4aae919eba98c7d2910b
BlueNoroffCISAEDR evasionFortiBleedFortinetGentlemen ransomwareGravity SMTPIcarusKlueMastra AIOAuth breachPII exposurePrinz EugenSapphire SleetSplunk EnterpriseTexas Parks and WildlifeUSB wormWordPressactive exploitationcredentials leakcryptocurrency malwaredata breachinformation disclosureransomwaresupply chain
What happened
Collection of Jun 18–20, 2026 security reports: a new Prinz Eugen ransomware prioritizes recently modified files and leaves no ransom note; Microsoft links the Mastra AI supply-chain compromise of 140+ npm packages to North Korea’s Sapphire Sleet (BlueNoroff); Klue confirms an OAuth token breach enabling the Icarus extortion group to access customer Salesforce environments; an unauthenticated information disclosure in the Gravity SMTP WordPress plugin is being actively exploited on ~100k sites; Texas Parks and Wildlife vendor breach exposed >3 million driver’s license records; CISA warns of an
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 52289daa49d50713fdfd63ccc92e8023434bcc0bedaf4aae919eba98c7d2910b
- Enrichment time
- 2026-06-21T07:23:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.