Rosetta Intel
Briefings/Daily BriefAI FrontierRansomware
Rosetta Lab ↗Blur Horizon LLC
Ransomware2026-07-29
Ransomware·2026-07-29

Ransomware Watch · Jul 29, 2026

⚠️ Data note: this run could reach neither the RansomLook API (/api/posts?days=1) nor the RSS fallback from the execution environment (sandbox network restrictions + web_fetch provenance gate). The items below are compiled from public reporting, not a structured RansomLook pull; the victim list is incomplete and covers only representative victims named on or around the day.

Overview

  • Total new posts: N/A (RansomLook unreachable; the items below are public-reporting hits)
  • Groups involved: ≥2 (Qilin, Anubis) + multiple groups exploiting edge devices at the ecosystem level
  • Watchlist hits: 2 (both matching group:qilin / sector:healthcare|medical / geo:us)

Watchlist Hits (Read First)

GroupVictimSectorGeoHitLink
Qilin ⭐StrykerMedical technology / manufacturingUSgroup:qilin · sector:medical · geo:ussocradar
AnubisEagle Crest Communities (WI)Senior care / healthcareUSsector:healthcare · geo:ustechtimes

Representative Recent Posts (Public Reporting)

GroupVictimSectorGeoDiscoveredLink
QilinStrykerMedical technologyUS2026-07-24socradar
AnubisEagle Crest CommunitiesSenior careUS2026-07-27techtimes
AnubisFairlife (Coca-Cola subsidiary)Food / dairyUS2026-07-20brightdefense

Anomalies / Trend Notes

  • Initial access is concentrating on edge devices: multiple ransomware crews (including Qilinaffiliates) are using Palo Alto, Fortinet, Citrix, and Check Point VPN/firewall appliances as their primary initial-access vector, chaining authentication bypasses, credential theft, and legacy-protocol weaknesses. Patching edge devices is the top priority. cybersecuritynews
  • Anubis + Citrix Bleed 2 (CVE-2025-5777): Anubis gains access before encryption by bypassing MFA, with 91 victims to date; the healthcare/care sector has been hit noticeably hard.
  • Qilin keeps the lead: roughly 1,496 victims listed on its leak site over the past 12 months; Akira around 1,205. The two remain the most active ransomware operations of 2026. infosecurity-magazine

Under normal conditions this page is generated automatically from the RansomLook API with watchlist highlighting; this edition is a public-reporting fallback, and structured pulls should resume tomorrow.

← Prev
Ransomware Watch · Jul 28, 2026
Next →
Ransomware Watch · Jul 30, 2026