U.S. Government Agency Paid $1M to Data Extortion Group Kairos
2026-07-04T20:51:42Z•9a8c3360410b4be566bd612e3d6a9cb282c1a354d6a3cffddb136eadbfbaf850
AI‑driven attacksCISACVE-2026-45659FortiBleedFortiGateJADEPUFFERKairosLLM abuseNetNutPegasusTeamPCPVercelcloud credentialsdata‑extortiondeveloper‑tool compromiseemail securityknown‑exploited‑vulnerabilityransomwareresidential proxysoftware supply chainspywaresupply‑chain
What happened
Multiple high-impact cyber incidents and trends reported: a U.S. government agency paid $1M to the data‑extortion group Kairos; TeamPCP poisoned developer/security tools to steal cloud credentials and spread malware; Citizen Lab found Pegasus spyware used against an MEP; Sysdig documented JADEPUFFER, an end‑to‑end LLM‑driven ransomware operation; a Vercel breach traced to an unvetted AI tool enabled a $2M extortion; Google and law enforcement disrupted the NetNut residential proxy network; SOCRadar links the FortiBleed campaign (430,000 FortiGate devices) to multiple ransomware operations; CCI
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 9a8c3360410b4be566bd612e3d6a9cb282c1a354d6a3cffddb136eadbfbaf850
- Enrichment time
- 2026-07-04T20:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.