Category: Security

  • Anubis Ransomware Hit on Adriatic Port Authority Exposes Maritime OT Risk

    Anubis Ransomware Hit on Adriatic Port Authority Exposes Maritime OT Risk

    Cybersecurity firm Resecurity has published research detailing a ransomware attack by the Anubis group against an Adriatic Port Authority, as reported by Industrial Cyber on June 16, 2026. The disclosure is being framed as a detailed look at how ransomware operators are reaching into maritime critical infrastructure — a sector where information technology (IT) systems and operational technology (OT, the systems that control physical processes like cranes, gates, and cargo handling) are increasingly intertwined.

    Executive Summary

    According to the report, threat-intelligence firm Resecurity has documented an intrusion attributed to Anubis — a ransomware-as-a-service operation that surfaced in underground markets in late 2024 and drew attention for pairing conventional encryption with a destructive file-wiping capability — against a port authority on the Adriatic coast. Port authorities are the public bodies that govern harbor operations, vessel traffic, and often the digital systems that commercial terminals depend on, which makes them an unusually consequential ransomware target.

    The significance is less the individual incident than what it illustrates: ports sit at the junction of national logistics, customs, energy imports, and military mobility, and a single compromised authority can ripple across all of them. Vendor research that documents such an attack in technical detail is valuable to defenders — though, as with any single-vendor disclosure, the claims that matter most (scope of access, operational impact, and how the intrusion happened) deserve independent confirmation, and the public reporting available at publication is thin on those specifics.

    Why Ports Are Ransomware’s Ideal Target

    Modern ports run on software to a degree that surprises outsiders. Terminal operating systems schedule every container move; gate systems decide which trucks enter; berth management coordinates vessel arrivals; customs and port-community platforms link the authority to shippers, freight forwarders, and government agencies. When ransomware locks those systems, cargo does not merely slow — it physically stops, because cranes and yard equipment have nowhere to be told to go. That is why the sector’s precedents are so costly: the 2017 NotPetya incident forced Maersk to rebuild its global IT estate at a cost the company put in the hundreds of millions of dollars, and ransomware halted container operations at Japan’s Port of Nagoya in 2023. An Adriatic port authority fits the same profile: high downtime costs, public-sector budget constraints, and a web of third-party connections that widens the attack surface.

    The OT dimension raises the stakes further. Even when attackers only encrypt IT systems, operators frequently shut down OT as a precaution because the boundary between the two is porous. The practical lesson for infrastructure operators of every kind — ports, data centers, utilities — is that segmentation between business networks and control networks is not a compliance checkbox; it is the difference between an expensive IT incident and a physical-operations outage.

    Anubis and the Economics of Destructive Ransomware

    Anubis is a relatively young ransomware-as-a-service brand — a model in which core developers lease their malware and infrastructure to affiliates who conduct the actual intrusions in exchange for a revenue share. What set Anubis apart in earlier security-industry reporting was a so-called wipe mode: the ability to destroy file contents outright rather than merely encrypt them. That capability changes the victim’s calculus. Classic ransomware is, in a grim sense, a negotiation with a counterparty that wants its decryptor to work; a wiper-equipped operator can credibly threaten permanent destruction, which increases pressure to pay quickly and raises the ceiling of potential damage if talks collapse.

    For a critical-infrastructure victim, that threat profile pushes the incident out of the purely financial category and toward something closer to sabotage risk. It also strengthens the case for offline, regularly tested backups — the one control that removes most of a wiper’s leverage — and for incident-response planning that assumes data may be unrecoverable from the attacker regardless of payment.

    What Vendor Research Does — and Doesn’t — Establish

    This disclosure comes from Resecurity, a commercial threat-intelligence firm, relayed through trade press. Vendor research is a legitimate and often essential channel — private firms frequently see intrusion details that victims and governments do not publish — but it also serves a marketing function, and readers should hold it to the same evidentiary standard as any other claim. The fair questions cut in every direction: Has the affected port authority confirmed the incident? Do the technical indicators trace to Anubis with high confidence, or by resemblance to known tooling? Was operational technology actually touched, or is OT exposure an inference from network architecture? The public reporting available at the time of writing — an aggregated headline and summary — does not settle any of these, and it would be a mistake to treat the incident’s most dramatic possible reading as established fact.

    The Regulatory Tide Meets the Waterline

    If the affected authority sits in an EU member state — as most Adriatic port authorities do — the incident lands squarely inside the NIS2 directive’s remit, the EU regime that designates ports as essential entities and imposes incident-reporting deadlines and management-level accountability for cyber risk. The International Maritime Organization has likewise required cyber risk to be addressed in ship and port safety-management systems since 2021. An incident like this one becomes a live test of whether those frameworks produce faster disclosure and better resilience in practice, or whether public understanding of critical-infrastructure attacks continues to depend on third-party security researchers publishing what victims will not.

    Background

    Anubis appeared in cybercrime markets around late 2024 as a ransomware-as-a-service brand and was flagged by multiple security researchers in 2025 for combining data-theft extortion with an optional file-destruction mode — an escalation from the encrypt-and-negotiate model that has dominated ransomware for a decade. Maritime targets have figured in ransomware history since NotPetya crippled Maersk in 2017, and attacks on the ports of Lisbon (2022) and Nagoya (2023) demonstrated that both port authorities and terminal operators are viable victims.

    The Adriatic coastline hosts significant EU trade gateways in Italy, Slovenia, and Croatia, making its port authorities essential entities under the EU’s NIS2 cybersecurity directive. Resecurity, the firm behind this disclosure, is a commercial threat-intelligence company that regularly publishes intrusion research on ransomware groups and critical-infrastructure targeting.

    Source: Resecurity details Anubis ransomware attack on Adriatic Port Authority, exposing maritime infrastructure risks — Industrial Cyber, reporting on Resecurity threat research into a ransomware intrusion at an Adriatic port authority, published June 16, 2026.

  • Oracle-Linked Breach Exposes Higher-Ed Client Data: Third-Party Risk in Focus

    Oracle-Linked Breach Exposes Higher-Ed Client Data: Third-Party Risk in Focus

    On June 15, 2026, GovTech — a publication covering technology in state, local, and education government — reported that a cyber attack on Oracle exposed data belonging to the company’s higher-education clients. Oracle supplies universities with core administrative software, including enterprise resource planning (ERP) and student information systems.

    The syndicated report available to us does not specify which Oracle product was compromised, how many institutions were affected, how many records were exposed, or who carried out the attack. Those details, if published, appear only in the full original article.

    Executive Summary

    The headline fact is narrow but significant: an attack tied to Oracle, one of the largest enterprise software vendors in the world, exposed data belonging to colleges and universities that rely on its platforms. When a breach occurs at a vendor rather than at an individual campus, the exposure fans out across every customer whose data the vendor holds — a dynamic security professionals call third-party or supply-chain risk.

    Higher education is especially sensitive to this failure mode. Universities concentrate decades of student, employee, and financial records inside a small number of enterprise platforms, and most institutions have far smaller security teams than the vendors they depend on. A vendor-side incident therefore turns one intrusion into a sector-wide notification, remediation, and liability event.

    Because the available source material is limited to a headline and publication date, this article treats the incident’s scope, mechanism, and attribution as open questions. What we can analyze with confidence is the structural picture: why attacks on enterprise software platforms keep reaching higher education, and what buyers of critical SaaS infrastructure should take from another entry in that pattern.

    Why Higher Education Sits Downstream of Vendor Risk

    Universities run on a remarkably short list of administrative platforms. Oracle’s PeopleSoft Campus Solutions has for decades been one of the dominant student information systems — the software of record for admissions, enrollment, grades, and financial aid — while Oracle’s ERP and human-capital products handle payroll, procurement, and HR at many institutions. The practical consequence is concentration: a compromise at the vendor or platform layer can touch dozens or hundreds of institutions at once, without any of those campuses making an individual security mistake.

    That concentration is not irrational. Few universities can build or secure such systems themselves, and a major vendor’s security program typically exceeds what any single campus could fund. But it changes the shape of the risk. Instead of many small, independent targets, the sector presents a few large, high-value ones — and when one is breached, the affected institutions are largely passengers: they must notify students and regulators for an incident that occurred on infrastructure they do not control.

    A Recurring Pattern of Pressure on Enterprise Platforms

    The June 2026 report lands against a documented backdrop. In 2025, Oracle dealt with several security events: an incident involving legacy Oracle Health (formerly Cerner) systems that affected healthcare customers, contested claims of a breach of legacy Oracle Cloud authentication servers, and — most consequentially — a large extortion campaign in late 2025 in which the Cl0p ransomware group exploited a vulnerability in Oracle E-Business Suite to steal data from many corporate and institutional customers, universities among them. Whether the incident GovTech reported in June 2026 is connected to any of these is not established by the material available to us, and we do not assume it.

    What the pattern does establish is a strategic shift by attackers: rather than breaching organizations one at a time, sophisticated groups increasingly target the platforms that aggregate many organizations’ data — file-transfer tools, ERP suites, identity systems. Each successful campaign of this kind has produced victim counts in the dozens to hundreds. For defenders, this means the perimeter that matters is increasingly the vendor’s, not their own.

    The Economics and Accountability of SaaS Concentration

    Vendor-side breaches expose an unresolved accountability gap. The institution owns the legal duty to protect student records — under FERPA (the U.S. federal student-privacy law), the Gramm-Leach-Bliley Act’s safeguards rule for financial-aid data, and state breach-notification statutes — but the vendor controls the systems where the failure occurred. Contracts allocate some of this through security addenda, breach-notification clauses, and liability caps, yet those caps are often small relative to the real cost of credit monitoring, legal exposure, and reputational harm across an affected student body.

    For buyers of critical SaaS infrastructure, the practical lesson is not to retreat from cloud platforms — self-hosted systems at under-resourced institutions have historically fared worse — but to price vendor risk explicitly: demand timely breach notification and forensic transparency in contracts, minimize the sensitive data retained in each platform, and maintain an inventory of exactly which records sit with which vendor so that response does not begin with discovery. Incidents like this one tend to strengthen the negotiating position of customers who ask for those terms.

    Background

    Oracle is one of the world’s largest enterprise software companies, and its footprint in higher education runs deep: PeopleSoft, which Oracle acquired in 2005, became the administrative backbone of many universities, and Oracle has since pushed those customers toward its cloud ERP and student-system offerings. That installed base makes Oracle a systemically important vendor to the education sector — and a correspondingly attractive target.

    The broader context is a multi-year surge in attacks on the platform layer of enterprise IT. Campaigns against file-transfer tools and ERP suites — including the late-2025 Cl0p campaign exploiting Oracle E-Business Suite — demonstrated that compromising one vendor’s software can yield data from hundreds of downstream organizations. Higher education, with its rich records and constrained security budgets, has repeatedly appeared on the victim lists of such campaigns.

    Source: Cyber Attack on Oracle Exposes Data of Higher-Ed Clients — GovTech report, June 15, 2026, on an Oracle-linked breach affecting higher-education customers.

  • New National Security Memorandum Orders Hardened Cybersecurity for Military Systems

    New National Security Memorandum Orders Hardened Cybersecurity for Military Systems

    President Trump has signed a National Security Memorandum aimed at strengthening the cybersecurity of U.S. military and intelligence systems, according to a June 14, 2026 report from Homeland Security Today. The directive targets the government’s most sensitive networks — the classified and mission systems that fall outside the rules governing ordinary civilian federal IT.

    Details of the memorandum’s specific requirements, deadlines, and funding were not included in the source report, so the scope of the mandate beyond its stated goal — hardened defenses for military and intelligence systems — remains to be confirmed from the document itself.

    Executive Summary

    A National Security Memorandum (NSM) is a presidential directive used to steer national security policy across the Department of Defense and the intelligence community. This one, per the Homeland Security Today report, orders a strengthening of cybersecurity for military and intelligence systems — the category the government formally calls national security systems, which operate under their own rulebook separate from civilian agency networks.

    The announcement matters for two reasons. First, national security systems carry the country’s most consequential data — weapons control, intelligence collection, command and control — and are the highest-value targets for state-sponsored attackers. Second, presidential directives in this space tend to cascade outward: past directives of this kind translated into binding technical requirements for agencies and, eventually, into procurement obligations for the contractors and infrastructure providers that build and host these systems.

    What is not yet clear is how prescriptive this memorandum is. The public reporting available at publication confirms the signing and the goal, but not the mechanisms — whether it sets new technical baselines, new deadlines, new reporting duties, or new authorities. That distinction will determine whether this is a significant operational shift or a reaffirmation of existing policy.

    What a National Security Memorandum Can Actually Do

    Presidential directives come in different weights. Executive orders on cybersecurity, such as the landmark 2021 order on improving the nation’s cybersecurity, generally bind civilian agencies. National security systems — networks handling classified information or supporting military and intelligence missions — are deliberately carved out and governed through separate instruments, with the National Security Agency serving as the designated national manager for their security. An NSM is the standard vehicle for directing change in that classified domain, which is exactly why this format was used here.

    The practical effect of an NSM depends on its plumbing: whether it directs specific agencies to issue binding operational directives, sets measurable deadlines, and assigns oversight. The 2022 memorandum known as NSM-8, for example, gave national security systems concrete timelines for adopting multifactor authentication and encryption and required agencies to report cross-domain systems to the NSA. If the new memorandum follows that pattern, agencies and their contractors will see enforceable requirements; if it is primarily a statement of priorities, its effect will depend on follow-on implementation guidance.

    Why Military and Intelligence Networks Are a Distinct Problem

    Hardening national security systems is a different engineering challenge from securing ordinary enterprise IT. These environments include air-gapped classified enclaves, decades-old weapons platforms that cannot simply be patched, and cross-domain solutions that move data between networks of different classification levels — each a specialized attack surface. The Department of Defense has been pursuing a zero trust architecture, a security model that assumes no user or device is trusted by default, with a stated target of implementation across the department by fiscal 2027. A new presidential directive landing in mid-2026 arrives squarely in the execution window of that effort.

    The threat context is well established even where this memorandum’s text is not. State-sponsored intrusion campaigns against U.S. defense networks and defense industrial base companies have been publicly documented by U.S. agencies for years, and the compromise of contractors — rather than the classified networks themselves — has repeatedly proven to be the softer entry point. Any serious hardening directive has to reckon with that supply chain reality, which is why observers will look closely at whether this NSM extends obligations to contractors and cleared cloud providers.

    Follow the Procurement: Who Stands to Gain

    Directives of this kind reliably move money, even when they arrive without new appropriations. Requirements for stronger identity controls, encryption modernization, network segmentation, and continuous monitoring translate into demand for the vendors that supply those capabilities — and into compliance burdens for the defense contractors that must meet them. Providers of classified-capable cloud regions, secure colocation, and accredited connectivity sit upstream of all of it: hardened systems still need hardened facilities, power, and network paths to run on.

    The cautionary note is timing. Federal cybersecurity mandates historically outpace the budgets attached to them, and implementation across the intelligence community and military services can stretch years past initial deadlines. Buyers and investors should treat the memorandum as a directional signal about sustained federal demand for defense-grade security infrastructure, not as a near-term revenue event — at least until implementing directives, budget requests, and contract vehicles make the requirements concrete.

    Background

    U.S. federal cybersecurity policy runs on two parallel tracks. Civilian agency networks answer to the Cybersecurity and Infrastructure Security Agency and directives like the 2021 executive order on improving the nation’s cybersecurity, which mandated zero trust adoption and software supply chain standards. National security systems — the classified and mission networks of the military and intelligence community — follow a separate track: the 2022 directive NSM-8 extended equivalent-or-stronger standards to those systems and reinforced the NSA’s role as their national manager.

    The June 2026 memorandum continues a two-decade pattern of successive administrations tightening requirements on this second track as state-sponsored cyber operations against defense targets have escalated. For the infrastructure industry, that pattern has steadily expanded the market for defense-grade security: accredited cloud regions, secure facilities, encrypted connectivity, and the compliance regimes — such as CMMC for defense contractors — that govern who may build and operate systems touching sensitive government data.

    Source: Trump Signs National Security Memorandum to Strengthen Cybersecurity of Military and Intelligence Systems — Homeland Security Today report, June 14, 2026, on a presidential directive ordering hardened cybersecurity for U.S. military and intelligence systems.

  • MS-ISAC Enters Uncertain Era After Funding Cut and Member Exodus

    MS-ISAC Enters Uncertain Era After Funding Cut and Member Exodus

    The Multi-State Information Sharing and Analysis Center (MS-ISAC) — the primary cyber threat-sharing hub for US state, local, tribal, and territorial governments — has entered what Cybersecurity Dive describes as an uncertain new era after losing its federal funding and thousands of member organizations, according to a June 14, 2026 report.

    The organization, operated by the nonprofit Center for Internet Security (CIS), spent roughly two decades as a free, federally supported service before its cooperative-agreement funding through the Cybersecurity and Infrastructure Security Agency (CISA) was cut in 2025, forcing a pivot to a fee-based membership model that many members have evidently declined to join.

    Executive Summary

    For most of its existence, MS-ISAC functioned as something close to a public utility for government cybersecurity: any state agency, county, city, school district, or tribal government could join at no cost and receive threat intelligence, incident-response support, and network monitoring, with the bill largely picked up by the federal government. That arrangement ended when federal support was withdrawn in 2025, and CIS moved the service to paid membership.

    The reported result — thousands of member organizations gone — matters because an information-sharing organization’s value is a function of its network. Every member that drops out is both a blind spot in the collective picture and, potentially, a softer target. State and local governments run elections, water systems, 911 dispatch, courts, and schools; they are also among the most frequent victims of ransomware, precisely because so many of them lack the budget and staff for standalone security programs.

    The open question as of mid-June 2026 is whether a smaller, self-funded MS-ISAC can sustain the same defensive footprint — and what happens to the organizations that used to depend on it and now, apparently, go without.

    From Public Good to Paid Service — and Why That Math Is Hard

    Shared threat intelligence has the economics of a public good: it is expensive to produce, nearly free to distribute, and most valuable when everyone participates. Federal funding solved the free-rider problem by simply paying for universal access. A fee-based model reintroduces it, and with a cruel twist known as adverse selection: the organizations most likely to drop out are the small, resource-poor ones — rural counties, small school districts, modest municipal utilities — which are exactly the entities least able to replace the service on their own and among the most attractive targets for ransomware crews.

    None of this means CIS made the wrong call; a nonprofit cannot indefinitely underwrite a national service out of its own reserves once its primary funder exits. But the reported loss of thousands of members suggests the transition is playing out the way the economics would predict. The membership that remains will skew toward larger, better-funded governments, which changes what the shared data represents.

    The Collective-Defense Network Effect Runs in Reverse

    An ISAC — an Information Sharing and Analysis Center — works because one member’s incident becomes every member’s early warning. A phishing campaign spotted against one county clerk’s office can be blocked at ten thousand others within hours. That flywheel spins both ways: as membership shrinks, the sensor network shrinks, detection gets slower, and the value proposition for remaining members weakens, which can encourage further departures. Managed defensively, a smaller ISAC can still deliver real value to a committed core; managed poorly, shrinkage becomes self-reinforcing.

    There is also a national-visibility cost that lands on the federal government itself. MS-ISAC historically served as the aggregation point through which federal agencies understood what was happening across tens of thousands of state and local networks. Fewer members means a dimmer picture — for everyone, including the agencies that cut the funding.

    Who Fills the Gap

    Three candidates stand out. First, states themselves: the “whole-of-state” model, in which a state CISO extends security services, monitoring, and grant money downward to counties, cities, and schools, has been gaining momentum for years and now has a stronger forcing function. Second, commercial vendors: managed detection and response (MDR) providers, threat-intelligence platforms, and security-focused hosting and connectivity providers will compete for budget that once didn’t need to exist, though public-sector procurement cycles and thin budgets make this a slow, uneven substitution. Third, CISA’s own free services — vulnerability scanning, advisories, regional advisors — which remain available but were never designed to replicate an ISAC’s peer-to-peer sharing fabric.

    For infrastructure and security providers, this is a genuine market signal: the public-sector demand for outsourced security operations just grew, involuntarily. The risk is that the gap gets filled unevenly — well-funded jurisdictions buy their way to coverage while the long tail of small governments simply absorbs more risk.

    Background

    MS-ISAC was established in the early 2000s and grew, under the nonprofit Center for Internet Security, into the designated cyber threat-sharing and defense hub for US state, local, tribal, and territorial (SLTT) governments — a sector spanning tens of thousands of organizations, most of them too small to staff full security teams. Membership was free, underwritten by federal cooperative-agreement funding channeled through the Department of Homeland Security and later CISA, and the center became a fixture of national cyber defense, particularly as ransomware attacks on cities, counties, and school districts escalated through the 2020s.

    That model unraveled in 2025 when federal funding was withdrawn amid broader cuts to CISA programs, pushing CIS to a fee-based membership structure. The June 2026 reporting marks a milestone in that transition: the organization survives, but with thousands fewer members and an open question about who now watches over the jurisdictions that left.

    Source: MS-ISAC enters uncertain new era after losing federal funding and thousands of members — Cybersecurity Dive report, June 14, 2026, on the threat-sharing center’s post-federal-funding transition.

  • ShinyHunters Tied to Oracle PeopleSoft Exploit Wave

    ShinyHunters Tied to Oracle PeopleSoft Exploit Wave

    Cybersecurity Dive reports that the ShinyHunters extortion group has been linked to active exploitation of a critical vulnerability in Oracle PeopleSoft, the widely deployed human-resources, finance, and campus-management enterprise software. The story, published 13 June 2026, connects a named and prolific threat actor to a flaw in one of the most entrenched enterprise resource planning (ERP) platforms in government, higher education, and Fortune 500 back offices.

    Executive Summary

    PeopleSoft is the kind of software that most people never see but that quietly runs payroll, benefits, student records, and procurement at large institutions. A critical, exploitable flaw in that layer is a serious matter regardless of who is using it; the involvement of ShinyHunters, a group best known for bulk data theft and extortion, sharpens the concern because their business model turns vulnerabilities into public breach disclosures within weeks.

    For infrastructure and security teams, the report is a prompt to check patch levels, audit which PeopleSoft components are reachable from the internet, and review credential hygiene on service accounts. For executives, it is a reminder that the ERP suite — often treated as a stable, low-change system — is now firmly on the target list of financially motivated criminal groups.

    Why PeopleSoft Is a High-Value Target

    Oracle PeopleSoft sits at the center of workforce, finance, and student-information workflows at a large fraction of universities, state and local governments, and long-established enterprises. That means the databases behind it typically contain government identifiers, bank details, home addresses, dates of birth, and, in the campus-solutions modules, decades of student records. For an extortion group, that combination is unusually attractive: the data is sensitive enough to coerce a payment, and the victim organizations are often risk-averse public bodies with limited appetite for headlines.

    The platform is also structurally hard to defend. PeopleSoft deployments tend to be long-lived, heavily customized, and integrated with dozens of downstream systems, which makes patching a scheduled event rather than a same-week reflex. Internet-exposed components — application portals, integration brokers, and administrative consoles — often outlive the teams that first stood them up.

    What ‘Linked To’ Does and Does Not Mean

    The Cybersecurity Dive headline attributes exploitation to ShinyHunters, but attribution in this space is a spectrum. Analysts typically infer group involvement from infrastructure reuse, tooling, victim-negotiation patterns, or claims posted on leak sites. Each of those signals can be strong, but none is proof in the courtroom sense, and ShinyHunters itself has functioned at times as a brand adopted by multiple operators. Readers should treat the linkage as a credible working hypothesis rather than a settled fact until incident-response firms or Oracle publish technical indicators.

    The more actionable point is that a critical PeopleSoft flaw is being exploited in the wild. Whether the fingerprints belong to ShinyHunters, an affiliate, or a copycat, the defensive response is the same: assume opportunistic scanning against every exposed PeopleSoft instance and prioritize accordingly.

    The ERP Supply-Chain Angle

    Enterprise software vulnerabilities have a compounding effect that consumer bugs do not. A single PeopleSoft tenant may hold data for tens of thousands of employees, students, or retirees, and those individuals have no direct relationship with the vendor. When the platform is breached, the notification burden and reputational damage land on the customer institution, while the root cause sits upstream. This is the same dynamic that has driven regulator interest in file-transfer, identity, and ERP suites over the past several years.

    For infrastructure providers — data center operators, managed hosting firms, and cloud platforms that run PeopleSoft workloads — the incident is a reminder that shared-responsibility boundaries need to be explicit. Customers frequently assume that a hosted ERP is patched by the provider; providers frequently assume the customer owns the application layer. Exploitation campaigns thrive in that gap.

    What Defenders Should Do This Week

    Without a specific CVE cited in the summary, the durable guidance is procedural. Inventory every PeopleSoft instance, including test and training environments, which are routinely forgotten and rarely patched. Confirm that Oracle Critical Patch Updates are current and that internet-facing components sit behind a web application firewall or reverse proxy with authentication in front of admin paths. Rotate service-account credentials, review recent outbound traffic from PeopleSoft hosts for signs of bulk data egress, and confirm that database backups are both recent and offline-recoverable.

    Longer term, organizations running PeopleSoft should decide whether the application belongs on the public internet at all. Many of the historical breaches of ERP systems have started with a management interface that quietly became reachable during a migration and was never re-fenced.

    Background

    Oracle acquired PeopleSoft in 2005 after a protracted hostile takeover, folding the HR and campus-management pioneer into its enterprise applications portfolio alongside JD Edwards and, later, Siebel and NetSuite. Two decades on, PeopleSoft remains a mainstay in higher education and the public sector, where migration to newer cloud ERP suites is slow because of custom integrations, complex chart-of-accounts structures, and cautious procurement cycles.

    ShinyHunters emerged publicly in 2020 with the sale of stolen databases from a series of consumer web platforms and has since evolved toward extortion campaigns targeting cloud data platforms and enterprise SaaS. The group’s involvement with a core ERP suite would fit a broader industry trend of criminal operators moving from consumer targets toward the back-office systems that hold the most sensitive institutional data.

    Source: ShinyHunters linked to exploitation of critical flaw in Oracle PeopleSoft — Cybersecurity Dive report, 13 June 2026, on active exploitation of a critical PeopleSoft vulnerability attributed to the ShinyHunters extortion group.

  • Anthropic Pledges $15M to Cyber Defense for State and Local Governments

    Anthropic Pledges $15M to Cyber Defense for State and Local Governments

    Anthropic, the AI company behind the Claude family of models, has launched a $15 million cyber defense program aimed at state, local, tribal and territorial (SLTT) governments, as first reported by StateScoop on June 13, 2026. The commitment marks one of the more visible moves by a frontier AI vendor into public-sector cybersecurity, a domain historically served by federal grant programs, information-sharing organizations, and traditional security contractors.

    Executive Summary

    The announcement is straightforward in outline: $15 million, directed at the roughly 90,000 units of government below the federal level in the United States — states, counties, cities, tribal nations, and territories — under the banner of cyber defense. These entities collectively run elections, 911 dispatch, water utilities, courts, and school districts, yet many operate with security budgets that would not cover a single enterprise analyst’s salary.

    Why it matters: SLTT governments are among the most frequently attacked and least defended organizations in the country, and the question of who should fill that gap — federal agencies, states themselves, or private vendors — is unsettled. An AI company stepping in with direct funding reframes that debate. It also positions AI-assisted security tooling in front of a vast, fragmented public-sector market at a moment when both the threat landscape and the defensive toolchain are being reshaped by AI. The reported release, however, is thin on mechanics: the program’s structure, eligibility, and deliverables are not detailed in the source material, so the scale of real-world impact remains to be demonstrated.

    The Soft Underbelly of American Cyber Defense

    SLTT governments occupy an unenviable position: they hold sensitive data (voter rolls, health records, court files) and run critical services (water, dispatch, schools), yet they buy security with some of the smallest IT budgets in the economy. Ransomware crews have long understood this asymmetry — small municipalities and school districts have been recurring victims precisely because a locked-up 911 system or payroll server creates immediate pressure to pay. Any credible new funding source for this tier of government addresses a real, well-documented gap, not a manufactured one.

    The structural problem is fragmentation. Unlike a federal agency, there is no single buyer, no shared baseline, and often no dedicated security staff at all in smaller jurisdictions. Programs that work at this tier tend to deliver shared services — centralized monitoring, common tooling, pooled expertise — rather than writing thousands of small checks. Whether Anthropic’s program takes that shape is not specified in the source reporting, and it is the single biggest determinant of whether $15 million produces measurable defense or diffuse goodwill.

    Why an AI Vendor Is Writing This Check

    There are at least three plausible and non-exclusive readings. First, genuine mission alignment: Anthropic has publicly framed itself around AI safety, and AI is already changing offensive tradecraft — faster phishing, faster vulnerability discovery — so an AI vendor investing in the defensive side of that ledger is coherent. Second, market development: public-sector security is a large, sticky market, and a philanthropic or subsidized entry builds relationships and reference deployments with thousands of potential future customers. Third, policy positioning: frontier AI companies face active regulatory scrutiny, and visible contributions to public cyber defense are a constructive answer to the question of whether AI makes society safer or more exposed.

    None of these motives is disqualifying — corporate programs routinely serve mission and market at once. The fair test is not motive but design: whether aid is delivered without product lock-in, whether recipients are chosen on need, and whether outcomes are reported. The source material does not yet answer any of those questions, so judgment should wait for the program’s actual terms.

    What $15 Million Does — and Does Not — Buy

    Context matters for the number. Fifteen million dollars is meaningful as a corporate program and modest against the scale of the problem: spread evenly across all SLTT entities it would amount to a few hundred dollars each, and federal SLTT-focused cyber grant programs have operated at hundreds of millions per year. That comparison is not a criticism — it is a sizing exercise. Concentrated well (for example, on shared services, incident-response capacity, or training for the smallest jurisdictions), $15 million can move the needle for a defined cohort. Spread thin, it becomes a press release with a long tail of small line items.

    The more durable effect may be signaling. If a frontier AI company treats SLTT cyber defense as a priority worth funding, it invites peers — other AI vendors, cloud providers, security firms — to match or exceed the commitment, and it gives state CISOs a new category of partner to negotiate with. For the infrastructure sector, it is also a reminder that the security perimeter of public services increasingly runs through commercial AI and cloud platforms, and the entities operating those platforms are becoming direct participants in public-sector defense, not just suppliers to it.

    Background

    Anthropic was founded in 2021 and develops the Claude family of AI models, competing with OpenAI, Google, and others at the frontier of the field. The company has made AI safety central to its public identity, and — like its peers — has faced growing questions about how AI reshapes cybersecurity, since the same capabilities that help defenders analyze threats can help attackers craft them.

    Public-sector cyber defense below the federal level has long been a recognized weak point in the United States: thousands of small governments with critical responsibilities, uneven funding, and heavy dependence on federal grants and shared-service organizations. Vendor-funded assistance programs are not new — cloud and security companies have offered discounted or donated services to governments before — but a frontier AI company committing a dedicated eight-figure program to the SLTT tier is a notable extension of that pattern.

    Source: Anthropic launches $15M cyber defense program for state, local, tribal and territorial governments — StateScoop’s June 13, 2026 report on Anthropic’s public-sector cybersecurity funding commitment.

  • Warner Bill Would Force CISA to Refresh Infrastructure Cyber Plans for AI Threats

    Warner Bill Would Force CISA to Refresh Infrastructure Cyber Plans for AI Threats

    Sen. Mark Warner (D-Va.) has introduced legislation that would compel the Cybersecurity and Infrastructure Security Agency (CISA) — the Department of Homeland Security unit responsible for defending U.S. critical infrastructure — to update its critical infrastructure cybersecurity plans to account for threats driven by artificial intelligence, according to a June 12, 2026 report by Industrial Cyber.

    Executive Summary

    The core of the proposal, as reported, is procedural rather than technical: it would use statute to force a planning refresh. CISA maintains national-level plans and guidance that federal agencies and the operators of the 16 designated critical infrastructure sectors — power, water, communications, financial services, and the data centers and networks that underpin them — use to organize their cyber defenses. Warner’s bill would require those plans to be updated with AI-driven threats explicitly in scope.

    That matters because planning documents in this space have historically aged badly. The foundational National Infrastructure Protection Plan dated to 2013 and stood for over a decade before the federal government began modernizing the underlying policy framework in 2024. Meanwhile, the threat landscape has shifted quickly: AI tooling can accelerate phishing, vulnerability discovery, and social engineering at a pace that decade-old planning assumptions never contemplated. A statutory mandate converts “we should update this” into “the agency must update this” — with the congressional oversight hook that implies.

    Why a Planning Mandate Is Bigger Than It Sounds

    National cyber plans can read as bureaucratic paperwork, but they do real work: they set the shared assumptions that sector risk management agencies, regulators, and private operators build their own security programs around. When the top-level plan is stale, everything keyed to it inherits the staleness. By forcing an update through legislation rather than leaving timing to agency discretion, the bill — if enacted — would create an enforceable deadline and a paper trail Congress can audit. The trade-off is familiar from other compliance regimes: mandates guarantee that a document gets refreshed, not that the refresh is good. The substance will depend on CISA’s execution and resourcing, neither of which is described in the source report.

    What “AI-Driven Threats” Could Mean for Operators

    The report does not detail how the bill defines AI-driven threats, so operators should watch the bill text closely. In practice the term usually spans two categories. The first is AI as an attacker’s tool: machine-generated phishing and deepfake-enabled fraud, faster reconnaissance and vulnerability discovery, and malware that adapts to defenses. The second is AI as an attack surface: as utilities, hospitals, and industrial operators embed AI into operations, the models, data pipelines, and inference infrastructure themselves become targets. A credible planning update would need to address both — and clarify which agency guidance applies to each.

    There is also a third dimension of particular interest to infrastructure providers: the facilities running AI are increasingly critical infrastructure in their own right. Data centers, high-capacity fiber routes, and the power systems feeding them now sit underneath much of the AI economy. Whether an updated national plan treats AI infrastructure as a protected asset class, and not just a threat vector, is one of the more consequential open questions.

    The Business Signal for Infrastructure Providers

    For operators of data centers, networks, and cloud platforms, legislation like this is a leading indicator even before it passes. Updated federal plans tend to cascade: sector-specific guidance follows, procurement language follows that, and customers in regulated sectors begin asking vendors to demonstrate alignment. Providers who can already document AI-aware threat modeling, incident response, and supply chain controls will be positioned ahead of any cascade. The cost side is real too — planning refreshes often precede new reporting or assessment expectations — but the source report identifies no specific obligations on private operators, so any compliance impact remains speculative until bill text and subsequent rulemaking are public.

    The Path From Bill to Law Is the Real Test

    A proposal is not a statute. The report available to us covers the introduction of the bill, not co-sponsorship, committee prospects, or companion legislation in the House — and the majority of introduced bills never reach a floor vote. Warner’s long tenure on cybersecurity issues and his seat on the Senate Intelligence Committee give the proposal a credible sponsor, but timing, amendments, and whether the measure moves standalone or gets folded into a larger vehicle such as an annual defense authorization bill will determine whether this becomes binding policy or a marker of congressional intent. Both outcomes carry signal; only one carries force of law.

    Background

    CISA was created by Congress in 2018 to serve as the federal government’s lead civilian agency for cybersecurity and critical infrastructure protection, working with the private owners and operators who control most U.S. infrastructure. The planning framework it inherited was showing its age: the National Infrastructure Protection Plan dated to 2013, and the underlying presidential policy directive from that same year was only replaced by a new national security memorandum in April 2024. Congress has been layering statute onto this space in recent years — most notably the 2022 law requiring critical infrastructure operators to report significant cyber incidents — and Warner, a former telecommunications executive and senior member of the Senate Intelligence Committee, has been a consistent voice in those debates. The rapid mainstreaming of generative AI since 2023 has given both attackers and defenders new tooling, which is the gap this bill reportedly aims to close at the planning level.

    Source: Warner proposes bill to force CISA updates to critical infrastructure cybersecurity plans amid AI-driven threats — Industrial Cyber’s June 12, 2026 report on the senator’s proposed legislation.

  • Warner Pushes Cyber Overhaul for AI-Era Critical Infrastructure

    Warner Pushes Cyber Overhaul for AI-Era Critical Infrastructure

    Sen. Mark Warner, a senior voice on U.S. intelligence and technology policy, is proposing an overhaul of the federal government’s cybersecurity plans for critical infrastructure, arguing that existing frameworks were not designed for threats amplified by artificial intelligence. The proposal, reported by Nextgov/FCW on June 9, 2026, targets the policy scaffolding that governs how sectors such as energy, communications, water, and information technology defend against and report cyber incidents.

    Executive Summary

    The announcement lands at a moment when defenders and attackers are both integrating AI into their toolchains. Warner’s framing — that the current critical-infrastructure cyber posture is a product of a pre-AI era — implies a rethink of risk assessments, sector-specific plans, and coordination between the federal government and private operators who own most of the assets in scope.

    For infrastructure operators, the practical stakes are concrete even if the legislative text is not yet public: any overhaul is likely to touch incident-reporting timelines, minimum security baselines, supply-chain scrutiny, and the interface between operators and agencies such as CISA. Data-center, cloud, telecom, and power companies should expect the conversation about their obligations to intensify.

    Why an AI-Era Rewrite Is Being Argued For

    The core claim behind Warner’s proposal is that AI changes both sides of the cyber ledger. On offense, generative models lower the cost of writing convincing phishing lures, scaling reconnaissance, and probing for vulnerabilities in operational technology. On defense, AI can accelerate detection but also introduces new attack surfaces: model supply chains, training-data poisoning, and automated agents with credentials. Existing sector plans, many rooted in a 2013 presidential directive and refreshed only incrementally, were not written with those dynamics in mind. That is a defensible premise; whether Warner’s specific fix matches the diagnosis is a separate question the public materials do not yet answer.

    Who Feels This First: Grid, Telecom, and Data Centers

    Critical-infrastructure policy is not abstract for infrastructure companies. Electric utilities already live under NERC-CIP standards; pipeline operators absorbed emergency TSA directives after Colonial Pipeline; telecoms answer to the FCC and, increasingly, CISA. Data centers sit at the intersection of the communications and IT sectors and are becoming load-defining customers for the grid — which makes their security posture a shared concern with utilities. An overhaul that raises the floor for any of these sectors will ripple into procurement, insurance, and colocation contracts, particularly around incident notification and third-party risk.

    What the Release Substantiates — and What It Does Not

    Based on the reporting available, Warner is proposing an overhaul; the specifics of scope, statutory vehicle, funding, and enforcement are not yet visible in the excerpt. That distinction matters. A resolution urging the administration to update Presidential Policy Directive 21 is a very different intervention from a bill that expands CISA authorities or mandates AI-specific controls. Readers, and operators building budget cases, should treat the proposal as a policy signal rather than a settled compliance requirement until legislative text or an accompanying framework is published.

    The Political and Industry Cross-Currents

    Cyber policy for critical infrastructure has historically drawn bipartisan support in principle and friction in detail, particularly around reporting timelines, liability protections, and the balance between voluntary and mandatory measures. Industry groups tend to favor harmonization across regulators; civil-liberties groups scrutinize information-sharing provisions; and agencies compete for lead-sector authority. Warner’s proposal will be tested against all three currents. The fair questions to ask are the same on every side: what evidence supports the specific controls being proposed, what is the cost-benefit for smaller operators, and does the mechanism actually reduce risk rather than paperwork?

    Background

    The U.S. approach to critical-infrastructure cybersecurity has evolved through a patchwork of presidential directives, sector-specific regulations, and voluntary frameworks anchored by NIST and CISA. Presidential Policy Directive 21, issued in 2013, established the current sector model; subsequent measures such as the 2015 Cybersecurity Information Sharing Act, the 2018 creation of CISA, and the 2022 CIRCIA reporting law layered on new authorities without a comprehensive rewrite.

    The rapid mainstreaming of generative AI since 2023 has intensified debate over whether that scaffolding is still fit for purpose. Congressional interest, agency guidance, and executive orders have addressed AI safety broadly, but the specific intersection of AI and critical-infrastructure defense has remained a gap that proposals like Warner’s are now attempting to close.

    Source: Warner proposes overhaul of critical infrastructure cyber plans as AI threats rise – Nextgov/FCW — reporting on Sen. Mark Warner’s proposal to modernize U.S. critical-infrastructure cybersecurity policy for AI-era threats.

  • CISA BOD 26-04 Moves Federal Patching Toward Risk-Based Prioritization

    CISA BOD 26-04 Moves Federal Patching Toward Risk-Based Prioritization

    On June 9, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) published Binding Operational Directive (BOD) 26-04, titled “Prioritizing Security Updates Based on Risk.” A Binding Operational Directive is a compulsory order to U.S. federal civilian executive branch agencies, and this one — as its title states — directs agencies to prioritize security updates according to risk rather than treating all patches alike.

    The directive continues an evolution in federal vulnerability management that began with fixed remediation deadlines and moved, over successive directives, toward focusing scarce patching capacity on the vulnerabilities most likely to be exploited.

    Executive Summary

    BOD 26-04 formalizes a shift that vulnerability-management practitioners have argued for over a decade: with tens of thousands of new vulnerabilities disclosed every year, no organization — not even a federal agency under mandate — can patch everything on a uniform clock. The rational alternative is to rank vulnerabilities by actual risk: whether they are being exploited in the wild, whether they sit on internet-facing or mission-critical systems, and what an attacker could reach through them.

    Why it matters beyond Washington: CISA’s directives bind only federal civilian agencies, but they have repeatedly become de facto standards for the private sector. The Known Exploited Vulnerabilities (KEV) catalog, created by BOD 22-01 in 2021, is now baked into commercial security tools, cyber-insurance questionnaires, and contract language far outside government. If BOD 26-04 follows the same path, risk-based patching mandates — with the documentation and telemetry they require — are a preview of what critical-infrastructure operators, federal contractors, and regulated industries should expect to be asked for next.

    A caveat on sourcing: this article is based on CISA’s publication of the directive and its stated title and purpose. The operational specifics — exact timelines, scoring methodology, and reporting requirements — live in the directive text itself, and we flag below what a one-line announcement leaves unanswered.

    From Compliance Clocks to Risk Math

    Federal patching policy has historically run on fixed deadlines. BOD 19-02 (2019) gave agencies 15 days to remediate critical vulnerabilities on internet-facing systems and 30 days for high-severity ones. BOD 22-01 (2021) refined the idea by creating the KEV catalog — a curated list of vulnerabilities with confirmed real-world exploitation, each carrying its own due date. Both approaches share a weakness: they treat severity scores or catalog membership as a proxy for risk, when the risk of any given vulnerability depends heavily on where it sits in a specific network and what it exposes.

    A directive built around risk-based prioritization acknowledges that reality. In plain terms, it means an agency should patch a moderately scored flaw on a crown-jewel system before a critically scored flaw on an isolated test box. That is how mature security teams already operate; the significance here is making it a matter of federal mandate rather than practitioner discretion. Mandating judgment is harder than mandating deadlines — which is precisely why the directive’s implementation details will determine whether it works.

    The Hidden Prerequisite: Knowing What You Own

    Risk-based prioritization has an unglamorous dependency: a complete, current inventory of assets and their exposure. You cannot rank vulnerabilities by risk if you do not know which systems are internet-facing, which hold sensitive data, and which are reachable from which. CISA has been building toward this for years — BOD 23-01 required asset visibility and vulnerability enumeration across federal networks — and BOD 26-04 is the logical next layer on that foundation.

    For infrastructure operators, this is the practical takeaway. Data-center, network, and cloud environments are dense with long-lived systems — hypervisors, building-management controllers, out-of-band management interfaces — where blanket patch deadlines were never realistic because patching means downtime windows and change-control risk. A risk-based regime is genuinely better suited to that world, but only for operators who have done the inventory and exposure-mapping homework first.

    The Template Effect on Critical Infrastructure

    CISA’s binding authority stops at federal civilian agencies; it cannot order a private colocation provider or utility to patch anything. Its influence, however, travels through softer channels: procurement requirements flow from agencies to their contractors and hosting providers, insurers and auditors adopt federal benchmarks because they are free and defensible, and sector regulators borrow CISA’s frameworks rather than inventing their own. KEV remediation status is already a common question in vendor security reviews.

    The likely trajectory is that risk-based patching expectations — documented prioritization decisions, exploitability-aware triage, evidence that high-exposure assets get fixed first — migrate into contracts and compliance frameworks over the next several years. Vulnerability-management and exposure-management vendors are natural beneficiaries, since operationalizing “risk-based” at scale is difficult without tooling that correlates threat intelligence, asset criticality, and network exposure. Organizations still running spreadsheet-driven patch cycles keyed to severity scores alone will find the gap widening.

    Background

    CISA has used Binding Operational Directives to steadily raise the floor of federal cybersecurity since the agency’s creation in 2018. BOD 19-02 imposed fixed remediation deadlines — 15 days for critical vulnerabilities on internet-facing systems — while BOD 22-01 created the Known Exploited Vulnerabilities catalog, shifting attention to flaws with confirmed real-world exploitation, and BOD 23-01 required agencies to build continuous asset and vulnerability visibility. Each directive has tended to ripple outward, shaping commercial security tooling and private-sector practice well beyond its legal reach.

    The broader industry context is a vulnerability-disclosure volume that has grown relentlessly for years, far outpacing any organization’s capacity to patch everything quickly. That arithmetic pushed the security field toward exploitability- and exposure-aware prioritization, and BOD 26-04 represents the federal mandate catching up with that practice.

    Source: BOD 26-04: Prioritizing Security Updates Based on Risk — CISA, the agency’s June 9, 2026 publication of a Binding Operational Directive on risk-based vulnerability prioritization for federal civilian agencies.

  • Ransomware Up 48% Even as Attacks Ease: Reading Check Point’s May 2026 Numbers

    Ransomware Up 48% Even as Attacks Ease: Reading Check Point’s May 2026 Numbers

    Cybersecurity vendor Check Point reported in early June 2026 that overall global cyberattack volume eased in May, even as ransomware activity surged 48%. The company attributes the ransomware spike to a period of reorganization among threat groups — the criminal organizations that develop and deploy extortion malware.

    Executive Summary

    According to Check Point’s May 2026 threat data, the broad tide of cyberattacks receded while the most financially damaging category — ransomware, malicious software that encrypts or steals a victim’s data and demands payment for its return — moved sharply in the opposite direction, up 48%. The headline framing is that threat groups are “reorganizing”: regrouping, rebranding, or consolidating rather than retreating.

    That divergence is the story. Raw attack counts are a crude measure of risk; a decline in commodity attacks paired with a surge in targeted extortion suggests the threat landscape is becoming more concentrated and more severe per incident, not calmer. For operators of data centers, networks, and cloud platforms — the infrastructure ransomware ultimately runs against and is defended from — the signal is to weight resilience investment toward the high-impact tail, not the average.

    Why Fewer Attacks Can Mean More Risk

    Attack-volume statistics count events, not consequences. A phishing email caught by a filter and a ransomware detonation that halts a hospital both register as “an attack,” yet their business impact differs by orders of magnitude. Check Point’s May 2026 picture — volume easing, ransomware up 48% — is therefore best read as a shift in mix rather than a cooling of the threat environment.

    Ransomware is the category most tightly coupled to real-world operational damage: downtime, data exposure, regulatory reporting, and ransom or recovery costs. When it grows while background noise recedes, the expected loss per organization can rise even as the number of alerts falls. Security teams that report success by blocked-event counts may be measuring the wrong curve.

    What “Reorganization” Means in the Ransomware Economy

    Check Point frames the surge as threat groups reorganizing. Ransomware today operates largely as a service economy: core developers lease their malware and infrastructure to affiliates who carry out intrusions and split the proceeds. That structure makes the ecosystem resilient — when one brand is disrupted or dissolves, its developers and affiliates typically disperse into successor operations rather than exiting the business.

    A reorganization phase producing a 48% activity surge is consistent with that pattern: new or restructured groups tend to campaign aggressively to establish reputation and revenue. The release does not name specific groups or attribute the surge to particular takedowns, so the mechanism remains Check Point’s characterization rather than a documented chain of events — but the ecosystem’s history of regenerating after disruption gives the framing plausibility.

    Reading Vendor Telemetry With Appropriate Care

    Figures like these come from a vendor’s own sensor network — the firewalls, endpoints, and email gateways of its customer base. That gives Check Point genuine, large-scale visibility, but it also means the numbers describe what Check Point’s installed base observed, not a census of the internet. Comparison baselines matter too: a 48% surge reads differently measured against April 2026 than against May 2025, and the summary available does not specify which.

    None of that makes the data wrong; independent trackers of extortion-site victim listings have generally corroborated the direction of ransomware trends in recent years. It does mean the precise magnitude should be treated as one vendor’s measurement, useful for direction and rough scale, and ideally cross-checked against incident-response and law-enforcement reporting before it drives budget decisions.

    Implications for Infrastructure Operators and Buyers

    For enterprises and the infrastructure providers that host them, a ransomware-heavy threat mix argues for prioritizing the controls that blunt extortion specifically: immutable and offline backups that attackers cannot encrypt or delete, network segmentation that limits how far an intruder can spread, tested restoration procedures, and identity hardening such as multi-factor authentication on remote access — still among the most common intrusion paths.

    Data center and cloud operators sit on both sides of this equation. They are targets themselves, and they are the recovery substrate their customers depend on when an attack succeeds. Demand for isolated recovery environments, rapid-restore storage, and managed detection services tends to track ransomware severity, so a sustained surge — if it proves durable beyond one month’s data — is a tailwind for resilience-focused infrastructure spending.

    Background

    Check Point Software Technologies, founded in 1993 and among the industry’s oldest firewall makers, publishes recurring threat intelligence drawn from its global sensor network, and its monthly attack statistics are widely cited barometers of the threat landscape. Ransomware itself has evolved over the past decade from opportunistic encryption schemes into a professionalized ransomware-as-a-service economy, in which developers lease malware to affiliates who conduct intrusions and share proceeds. Repeated law-enforcement disruptions of major brands have fragmented rather than eliminated the ecosystem, producing recurring cycles of collapse, rebranding, and resurgence — the backdrop against which Check Point describes the current period of reorganization.

    Source: Global Cyber Attacks Ease in May 2026, But Ransomware Surges 48% As Threats Reorganize — Check Point Blog, reporting the vendor’s May 2026 threat telemetry.