INC Ransomware Thrives by Mastering the Basics
2026-06-18T02:51:47Z•8454404d66c0990cfd0711ed298d525612c55915ad50da8db0eb75e7446ac05f
Android-trojanCVE-2025-8088Check-PointChina-nexus-espionage','threat-actors','patching','CISA','AI-risCopilotExchange-spoofingFortinetGhost-SenderHTTP/2-DoSIvantiMiasmaOraclePhantom-stealerRokarollaSprySOCKSWinRARbrowser-credentialscredential-harvestingfileless-malwarehealthcarekernel-driversprompt-injectionransomwaresupply-chainzero-day
What happened
A DarkReading roundup highlights multiple active, high-impact threats and systemic trends: INC ransomware focusing on high-pressure sectors (healthcare); a large credential-harvesting campaign compiling working logins for 30K+ Fortinet devices; active exploitation of multiple zero-days (Ivanti, Check Point VPN, Oracle ERP) and fast weaponization after disclosure; Russia-linked use of a WinRAR flaw (CVE-2025-8088) for espionage; supply-chain compromises (Miasma hitting Microsoft repos, PyPI/NPM campaigns Hades/IronWorm); fileless Phantom stealer targeting browser credentials; SprySOCKS using/ab
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- 8454404d66c0990cfd0711ed298d525612c55915ad50da8db0eb75e7446ac05f
- Enrichment time
- 2026-06-18T02:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.