August 11, 2026
- Microsoft dissected DeadLock, a Rust-based ransomware with decentralized recovery infrastructure. The financially motivated operation runs victim communications, negotiations, and leaks over decentralized infrastructure alongside double extortion (Microsoft).
· Threat Activity
in Metabase Zero-Day Blast Radius Widens to LexisNexis and Framework
July 13, 2026
- DeadLock ransomware is running at a high operational tempo, publishing 10+ new victims in a matter of days including Indonesian plastics maker Vinilon Group (FalconFeeds, DarkFeed).
· Threat Activity
in Russian Intelligence Turns IP Cameras and Routers Into a NATO Surveillance Grid
July 11, 2026
- DeadLock ransomware posted 11 new victims in a single burst, including Finland's Enedo Power and Sweden's Carrier Transport AB, signaling a high operational tempo worth monitoring. FalconFeeds
· Threat Intelligence
in Progress Orders ShareFile Storage Controllers Offline Over Active Zero-Day Threat
June 20, 2026
- DeadLock is expanding its use of Polygon smart contracts — now hosting its leak-site entries on-chain (75 victims since February) in addition to chat-proxy rotation, with notes fetching victim data live from the contracts. ESET
· Ransomware & Extortion
in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token