Poche gang dominano il mercato dell’estorsione ransomware
Il cambiamento vero non è un nuovo exploit. È un mercato dell’estorsione più industriale, con poche gang che assorbono gran parte delle richieste e con gli LLM usati per produrre messaggi di pressione più credibili e credibili su misura, senza cambiare il copione tecnico del ransomware. La leva si sposta dalla grammatica pessima alla plausibilità del racconto.
Nel report trimestrale di GuidePoint Security, le vittime rivendicate nel secondo trimestre 2026 sono state 2.279: +7% sul trimestre precedente e +43% su base annua. Qilin ha guidato il periodo con il 13% degli attacchi, The Gentlemen è cresciuto in fretta, e le cinque gang più attive hanno totalizzato oltre il 40% delle rivendicazioni; il quadro resta concentrato anche fuori dagli Stati Uniti, con Germania e altri mercati sempre più esposti.
Per chi gestisce negoziazioni o comunicazioni di estorsione, il segnale è che il criterio di fiducia cambia: il testo può sembrare professionale anche quando l’intrusione è ordinaria. Un piccolo numero di franchise resta abbastanza grande da assorbire affiliati e continuare a fare pressione anche dopo un takedown.
CVSS 9.8 CRITICAL: langflow versions prior to 1.3.0 are susceptible to code injection in
the /api/v1/validate/code endpoint. EPSS 100% (100º percentile).
Data di correzione federale CISA 26 mag · data superata
A 15-year-old boy asked a chatbot for help – and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous…
An AI agent carried out the technical execution of a real-world ransomware attack for the first known time, but new details show a human still chose the victim, set up the infrastructure, and supplied stolen credentials — meaning it wasn't quite the fully autonomous cybercrime debut that last week's headlines suggested.
The AI agent didn’t accomplish every step in the late June 2026 attack, but it allowed the threat actor to significantly reduce complexity, speed up the tempo and gain operational advantages.
Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent.