INC Ransomware Thrives by Mastering the Basics

2026-06-18T02:51:47Z8454404d66c0990cfd0711ed298d525612c55915ad50da8db0eb75e7446ac05f
Android-trojanCVE-2025-8088Check-PointChina-nexus-espionage','threat-actors','patching','CISA','AI-risCopilotExchange-spoofingFortinetGhost-SenderHTTP/2-DoSIvantiMiasmaOraclePhantom-stealerRokarollaSprySOCKSWinRARbrowser-credentialscredential-harvestingfileless-malwarehealthcarekernel-driversprompt-injectionransomwaresupply-chainzero-day

What happened

A DarkReading roundup highlights multiple active, high-impact threats and systemic trends: INC ransomware focusing on high-pressure sectors (healthcare); a large credential-harvesting campaign compiling working logins for 30K+ Fortinet devices; active exploitation of multiple zero-days (Ivanti, Check Point VPN, Oracle ERP) and fast weaponization after disclosure; Russia-linked use of a WinRAR flaw (CVE-2025-8088) for espionage; supply-chain compromises (Miasma hitting Microsoft repos, PyPI/NPM campaigns Hades/IronWorm); fileless Phantom stealer targeting browser credentials; SprySOCKS using/ab

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
8454404d66c0990cfd0711ed298d525612c55915ad50da8db0eb75e7446ac05f
Enrichment time
2026-06-18T02:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.