Skip to main content
LiveListen now5 listening
Live

aired speech / station archive

Identity Overtakes Exploits as Top Ransomware Cause [Prime Cyber Insights]

Spoken by Neural Newscast on Neural Newscast. Aired Jul 16, 01:46 PM / 295s / music_show / audio on file.

Identity Overtakes Exploits as Top Ransomware Cause [Prime Cyber Insights]

Welcome to Prime Cyber Insights. Reporting from the briefing room on July 16th, 2026, we are analyzing a pivotal shift in the ransomware landscape: the decline of vulnerability exploits in favor of identity-driven attacks. <br/><i>acting_description:</i> professional, steady, authoritative <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Our lead story today comes from the Sophos State of Ransomware 2026 report. It confirms that malicious email and phishing now represent 50 percent of all ransomware root causes, finally overtaking software vulnerabilities, which have dropped to just 18 percent. Aaron, the most startling figure for practitioners is the 97 percent MFA deployment rate in credential-based attacks that still resulted in a breach. <br/><i>acting_description:</i> engaged, measured, clear <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Exactly, Lauren. That number suggests two things: either MFA isn't being applied universally across all system access points, or attackers have standardized their bypass techniques. It reinforces why we're seeing such a heavy industry push toward Identity Threat Detection and Response, or I-T-D-R. Patching is no longer enough when the front door is being opened with legitimate, albeit stolen, credentials. <br/><i>acting_description:</i> analytical, direct, firm <i>speed:</i> 0.98 <i>trailing_silence:</i> 0.4 The speed of these attacks is also intensifying. We're tracking a new Rust-based ransomware called Spirals, which recently compromised an IT services firm in South Asia. According to Symantec, the actors moved from initial access via an exposed IIS server to full data encryption in less than 24 hours. They even used bitsadmin.exe to masquerade as legitimate Windows utilities during the payload deployment. <br/><i>acting_description:</i> responsive, focused, precise <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Transitioning to physical supply chain impacts, we're watching a significant incident in Japan. Nichirei Group, a major cold-chain logistics provider, confirmed a cyberattack that has crippled their refrigerated warehouse operations. This has hit K-F-C Japan hard, Lauren. The company has had to suspend online orders and is warning of potential store closures due to ingredient shortages. <br/><i>acting_description:</i> calm, informative, steady <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 It's a textbook example of how a single logistics failure cascades into retail downtime. On the enforcement side, there is finally closure for the 2024 Transport for London hack. Today, two members of the Scattered Spider collective, Thalha Jubair and Owen Flowers, were each sentenced to five years and six months in prison. The UK National Crime Agency noted the hack caused £29 million in direct losses, but could have cost the broader economy billions. <br/><i>acting_description:</i> thoughtful, grounded, evaluative <i>speed:</i> 0.98 <i>trailing_silence:</i> 0.4 The Scattered Spider sentencing coincides with another major disruption in Spain. National police there just broke up a massive cyber fraud ring involving over 70 individuals and 800 bank accounts. They managed to steal €140 million through CEO impersonation and social engineering. It is a reminder of the scale at which these mule herder networks operate to launder illicit funds through shell companies. <br/><i>acting_description:</i> serious, factual, objective <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Let's look at the technical tradecraft being used in Southeast Asia. Kaspersky has released a report on the GoSerpent backdoor targeting government and diplomatic entities. This isn't a single tool, Aaron

Read disclosure