Ransomware · 89 days ago

Port Ransomware Reaches Through Cloud Identity

A port can be forced into disruption without anyone touching cranes or other industrial gear. The weak point here is ordinary IT access: phishing and cloud-admin accounts can give attackers a path into core systems, so restoring files from backup does not erase the leverage they already gained.

Resecurity says Anubis got into the Adriatic Port Authority through staff phishing and then moved through cloud and office accounts tied to Office 365 and Azure. The port authority says the breach dates to December 11, 2025, with about 2% of data lost and most of the rest preserved from backups; Resecurity says the attack still caused vessel rerouting, a $10 million ransom demand, and theft of port safety plans, security details, and employee records.

That shifts the threat from data loss to operational pressure. If identity systems and admin accounts are the doorway, a port can be disrupted, extorted, and mined for sensitive logistics data even when the physical-control systems stay untouched.

CVE-2025-5777

NVD KEV

Known exploited · CISA KEV

CVSS 7.5 HIGH: insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual… Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date Jul 11 · date passed

CVE-2025-26399

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: solarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code… EPSS 89% (100th percentile).

CISA federal remediation date Mar 12 · date passed

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-06-18

Editions