top of page


Enterprise Security Tech
A cybersecurity resource for CxOs
Search


NCC Group Warns Ransomware, State Hackers, and AI Fraud Tools Are Colliding
Ransomware activity in May 2026 remained stuck at historically high levels, even as attacks dipped slightly month over month, according to a new cyber threat intelligence report from NCC Group and Fox-IT. The report recorded 749 ransomware victim listings in May, a 4 percent decline from the previous month but still part of an elevated 2026 baseline. Industrial organizations were hit hardest, accounting for 29 percent of ransomware attacks. Qilin remained the most active rans
Jun 24


Malicious AI Coding Plugins Hit JetBrains Marketplace, Stealing API Keys From Developers
A coordinated malware campaign on the JetBrains Marketplace is turning trusted developer tools into a credential theft pipeline, according to new research from Aikido Security. Researchers identified 15 malicious JetBrains plugins posing as AI coding assistants for DeepSeek and other large language models. The plugins advertise common developer features such as chat, code review, commit message generation, bug detection, and unit test creation. The catch: when users enter an
Jun 17


DragonForce Ransomware Is Hiding in Microsoft Teams Traffic
A DragonForce ransomware attack has exposed a new problem for enterprise defenders: attackers are no longer just hiding behind disposable servers and shady domains. They are increasingly blending into the trusted cloud services companies rely on every day. Broadcom’s Symantec and Carbon Black threat hunters say they found a new Go-based backdoor, tracked as Backdoor.Turn, during an investigation into an attack on a U.S. services company. The malware is notable because it rout
Jun 17


Kodak Breach Adds to ShinyHunters’ Growing Data Extortion Wave
Eastman Kodak has confirmed it is investigating a data breach after the ShinyHunters extortion group claimed it stole more than 2.2 million records containing customer personally identifiable information and internal corporate data. Kodak said an unauthorized third party briefly accessed a limited amount of company data and that outside cybersecurity experts are helping determine what was accessed and copied. The company said it is working with law enforcement and does not be
Jun 17


Why Executive Impersonation Is Becoming Harder To Detect - And What To Do About It
This guest post was contributed by Amit Shuster, VP Product, Vetric.io Cybercriminals have always targeted senior executives. What's changed is how effectively they can now impersonate them. Deepfake technology has matured to the point where an AI-generated video of a CEO endorsing a fraudulent investment scheme, or an audio clone directing an employee to wire funds, can be nearly indistinguishable from the real thing. Deloitte estimates deepfake-enabled fraud losses could r
Jun 11


GreatXML Windows Zero-Day Turns Defender Offline Scan Into a BitLocker Backdoor
The post-compromise technique abuses Windows Recovery Environment to create persistent access to BitLocker-encrypted data, with no patch currently available. According to the Cyderes Howler Cell team, a newly disclosed Windows zero-day called GreatXML can turn Microsoft Defender’s offline scanning process into a pathway for accessing BitLocker-encrypted data without a recovery key or user credentials. The technique targets the interaction between Windows Recovery Environment,
Jun 11
bottom of page