LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations

2026-07-27T08:51:36Z7802e891a06cbd0f14bd330192c41a157f7d021065de85e8c3862d52e4a40e06
CISAFBIHades malwareHermes AI agentIran-linked actorsItalyLockBit5Microsoft 365Notepad++Origin EnergyQilinThailandUAC-0099Ukrainecredential theftcritical infrastructurecyber espionagedata breachenergy sectorhotel Wi-Fimalwaremanufacturingphishingransomwarewater utilities

What happened

Security Affairs RSS coverage from July 2026 highlights ransomware activity against Italian organizations, hotel Wi-Fi gateway compromises used to steal Microsoft 365 credentials, Iran-linked intrusions targeting US water and energy control systems, a breach at Australian energy provider Origin Energy, cyber-espionage against Thailand’s Ministry of Finance, and UAC-0099 phishing campaigns using a fake Notepad++ plugin against Ukrainian organizations. The reporting describes significant operational, credential-theft, espionage, and critical-infrastructure risks, but does not provide enough case

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
7802e891a06cbd0f14bd330192c41a157f7d021065de85e8c3862d52e4a40e06
Enrichment time
2026-07-27T08:51:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.