Threats & incidents
-
Ukraine claims Wildberries cyberattack
Ukraine’s military intelligence says a cyber operation disrupted Wildberries customer service and payment infrastructure, extending pressure on the Russian retailer beyond recent physical strikes.
-
Medusa victim count passes 500
An updated US government advisory says Medusa ransomware actors had affected more than 500 victims by April 2026, while Microsoft documents rapid exploitation of exposed enterprise systems.
-
Windows flaw joins ransomware attack chains
CISA says ransomware operators are exploiting a patched Windows Task Host privilege-escalation flaw, adding another known vulnerability to attack chains against Windows environments.
-
Cyberattack hits Ukraine asset agency
Ukraine’s asset recovery agency says its servers were hit by a cyberattack as it prepared a sensitive management tender involving seized assets linked to a sanctioned Russian businessman.
-
Swiss ransomware trial tests digital evidence
Swiss prosecutors are seeking a 12-year sentence in a ransomware case where the defendant disputes his alleged role and the handling of seized digital evidence.
-
Pokémon joins CEVA breach fallout
Pokémon Center customers in the UK and Germany are the latest downstream victims of CEVA Logistics’ cyberattack, with personal data exposed and some orders disrupted.
-
Berlin breach knocks ministries off network
Two Berlin Senate administrations remain isolated from the state network after a cyberattack disrupted communications and triggered a criminal investigation.
-
European mid-market ransomware victims surge
Mid-market companies accounted for nearly three quarters of tracked ransomware victims across North America and Europe between 2023 and mid-2026, according to new Black Kite research.
-
Hijacked WordPress sites powered malware network
Check Point says thousands of compromised WordPress sites were repurposed as infrastructure for a malware operation combining data theft, encryption, command and control, and stolen-data storage.
-
AmnesiaStealer takes control of browser sessions
A macOS infostealer distributed through fake GitHub pages can progress from password and browser theft to interactive control of authenticated Chromium sessions.










