Iran-linked Pay2Key re-emerged and used Active Directory-focused evasion and credential harvesting to rapidly encrypt a US healthcare provider's infrastructure. Pro‑Ukraine group Bearlyfy escalated attacks on Russian companies and deployed a new GenieLocker strain to demand larger ransoms.
Part of the PlainSec briefing for 2026-03-29