TRACKING RANSOMWARE : SEPTEMBER 2026

Published On : 2026-10-09
Share :
TRACKING RANSOMWARE : SEPTEMBER 2026

EXECUTIVE SUMMARY

September 2026 recorded 862 publicly disclosed ransomware victims, 26.3% down from August’s 1,170. This is the final September figure in CYFIRMA’s leak-site tracker, captured after full-month collection. Thegentlemen (105) led monthly activity, followed by Qilin (74), Akira (36) and Storm (36). Organizations within Professional Goods & Services, Healthcare, Manufacturing, Real Estate & Construction, Consumer Goods & Services and Information Technology experienced the highest levels of targeting. Data theft, edge/VPN and RMM abuse, identity compromise, and multi-layered extortion continued to shape outcomes. Organizations should strengthen identity security, edge-device hardening, accelerated remediation, visibility, and proactive threat intelligence.

Confidence levels (High / Moderate / Low) used in this report reflect the volume and independence of the source reporting behind each assessment.

Who should read this: organizations in professional services, healthcare, real estate and construction, consumer goods, manufacturing and IT services, particularly in the United States, India, Canada and the United Kingdom, and any organization running internet-exposed Fortinet SSL-VPN, N-able N-central or other RMM consoles, commercial RMM agents (MeshAgent, Atera, ScreenConnect, Splashtop, NinjaRMM, SimpleHelp), Windows endpoints without vulnerable-driver blocking, or Azure tenants with broadly privileged service principals. Each of these technologies appears in September intrusion reporting as an access, control, or impact vector.

INTRODUCTION

This edition of RANSOM WATCH covers ransomware activity observed in September 2026. It delivers a detailed analysis of the ransomware landscape, highlighting the emergence of new ransomware groups, evolving attack techniques, and notable shifts in targeted industries. By examining key trends, tactics, and significant incidents, this report aims to support organizations and security teams in understanding the current threat environment.

KEY POINTS

  • Ransomware operations are increasingly transitioning into specialized service-based ecosystems, where Initial Access Brokers (IABs), ransomware operators, malware developers, and financial facilitators operate as distinct yet interconnected components of the attack lifecycle.
  • Custom malware development is becoming a defining characteristic of mature ransomware groups, with threat actors increasingly deploying proprietary loaders, backdoors, credential stealers, and defense-evasion frameworks instead of relying solely on publicly available tools.
  • Threat actors are increasingly emphasizing stealth and long-term persistence, leveraging fileless execution, memory-resident implants, trusted software abuse, and covert command-and-control channels to maintain access well before ransomware deployment.
  • Modern ransomware campaigns are shifting toward pre-positioned access operations, prioritizing credential harvesting, reconnaissance, privilege escalation, and environment preparation to maximize operational success prior to encryption.
  • Bring Your Own Vulnerable Driver (BYOVD) attacks have become a mainstream defense-evasion technique, allowing ransomware operators to disable endpoint security products and gain kernel-level privileges during post-compromise operations.
  • Ransomware groups are increasingly abusing trusted enterprise infrastructure, including collaboration platforms, legitimate cloud services, signed binaries, and remote administration tools, to blend malicious activity with normal enterprise operations.
  • Affiliate-based ransomware ecosystems continue to mature through standardized offensive toolkits, centralized support services, rapid vulnerability integration, and continuous malware development, lowering the technical barrier for affiliate operators.
  • Data theft continues to evolve into an independent monetization mechanism, with ransomware groups expanding beyond traditional double extortion through flexible negotiation models, direct data sales, and diversified extortion strategies.
  • Credential theft operations are becoming tightly integrated with ransomware campaigns, with attackers systematically targeting VPN infrastructure, enterprise authentication systems, and edge devices to establish scalable access pipelines for future intrusions.
  • Ransomware operators continue to demonstrate increasingly agile development cycles, rapidly incorporating newly disclosed vulnerabilities, adapting delivery mechanisms, and releasing updated tooling in response to defensive actions and law enforcement disruptions.
  • Enterprise-focused ransomware groups are increasingly targeting operational continuity rather than solely encryption, maintaining persistent access after attacks to facilitate future intrusions, repeated extortion, or resale of compromised environments.

MOST ACTIVE RANSOMWARE GROUPS: TOP 10 TREND COMPARISON

Throughout September 2026, there was notable activity from several ransomware groups.

The August–September 2026 data indicates continued redistribution of ransomware activity. Leading operators included Thegentlemen (113 → 105), Qilin (165 → 74), Akira (31 → 36), Storm (40 → 36), Krybit (36 → 34), Safepay (12 → 32), Incransom (44 → 29), AuditTeam (3 → 25), Cl0p (90 → 25), and Settra (23 → 23). Safepay and AuditTeam were the strongest risers inside the top ten; Qilin and Cl0p posted the steepest declines among high-volume August brands. Overall, the RaaS ecosystem remains highly resilient, with operational capacity shifting among leaders and newcomers rather than signaling a collapse in overall ransomware threat.

NEW ENTRANTS AND EXITS

Compared with August, CYFIRMA’s tracker recorded 13 ransomware brands with September leak-site activity that had no August activity, led by Vexy Ransomware (19), N0n (18), Lamashtu (10), EndZone (5), Spirals (4), BlackLocks (3), Fulcrumsec (2) and Netrunner (2). Conversely, 21 August-active brands posted no September victims in the tracker, including L Group (28 in August), Coinbasecartel (24 in August), Helix (8 in August), Xpl0itrs (7 in August), Deadlock (6 in August), AiLock (4 in August), Nasirsecurity (4 in August), and Lynx (3 in August). Brand churn of this kind is expected in a RaaS marketplace and should be read as redistribution of disclosure capacity, not disappearance of shared access and extortion tradecraft.

RANSOMWARE ATTACK VOLUME: MONTHLY TREND

Publicly disclosed incidents totaled 862 in September, compared with 1,170 in August (26.3% down month-on-month). Multi-year volumes continue to show that RaaS operations remain active and adaptable across industries and regions, even when monthly disclosure totals fall back from an exceptional prior-month peak.

VICTIM TRENDS BY INDUSTRY

In September 2026, ransomware activity continued to focus on sectors where operational disruption and data theft maximize extortion. Month-on-month industry counts versus August included Professional Goods & Services (194 → 127), Healthcare (123 → 86), Manufacturing (169 → 84), Real Estate & Construction (128 → 84), Consumer Goods & Services (91 → 76), Information Technology (112 → 72), Finance (62 → 47), Government & Civic (56 → 46), Materials (33 → 42) and Education (29 → 34). Professional Goods & Services remained the most targeted vertical even as overall volume fell back from August’s peak, while Healthcare overtook Manufacturing for second place.

Operators continue to prioritize industries where business disruption and sensitive information exposure increase the likelihood of successful extortion.

VICTIM TRENDS BY GEOGRAPHY: TOP COUNTRIES

Ransomware activity in September 2026 remained geographically concentrated in the United States, which recorded 324 publicly disclosed incidents (38% of the total). Month-on-month country counts versus August included the United States (478 → 324), Canada (42 → 37), India (29 → 28), Germany (54 → 27), France (30 → 25), Spain (20 → 24), and Brazil (23 → 23). In total, 90 identified countries were affected. Operators continue to prioritize digitally mature economies while maintaining a broad international footprint.

VICTIM TRENDS BY ORGANIZATION SIZE

CYFIRMA’s leak-site tracker does not currently record victim organization size, so no breakdown by employee or revenue band can be given for September 2026. Enrichment of the tracker to support this view is being assessed for future editions of RANSOM WATCH.

DATA-LEAK-SITE ACTIVITY

CYFIRMA’s September 2026 leak-site and underground monitoring captured 862 victim postings across tracked data-leak sites, against 1,170 in August. Thegentlemen led disclosure tempo with 105 posts, followed by Qilin (74), Akira (36), and Storm (36). Newly observed or returning leak-site brands included Vexy Ransomware (19), N0n (18), Lamashtu (10), EndZone (5), Spirals (4), and BlackLocks (3). Posting patterns remained batch-oriented: multi-victim dumps from mature RaaS brands ran in parallel with concentrated debut campaigns from newer extortion brands seeking marketplace visibility.

EVOLUTIONS IN THE RANSOMWARE THREAT LANDSCAPE, SEPTEMBER 2026

Cross-RaaS Affiliate Tradecraft Stabilizing Faster Than Ransomware Brand Identity

This activity demonstrates the evolution of ransomware operations toward affiliate-centric consistency that outlasts any single encryptor brand. Microsoft Threat Intelligence reporting published in late September 2026 showed Storm-2570 maintaining largely uniform remote-access, discovery, credential-theft, Defender tampering, and cloud-exfiltration tooling across deployments involving Qilin, DragonForce, Anubis, and BERT. The technical signal is that payload family labels increasingly obscure the durable intrusion behaviors defenders can interrupt, while affiliates treat RaaS brands as interchangeable monetization endpoints rather than distinct technical stacks.

ETLM Assessment:

Ransomware risk programs are expected to keep shifting from brand-first tracking toward affiliate and tooling fingerprinting, because shared post-compromise playbooks will continue spanning multiple encryptor ecosystems (High confidence). Detection engineering that keys only on final ransomware binaries will miss the longer pre-encryption window where MeshAgent, PsExec, ntdsutil, and cloud sync utilities already establish impact conditions. Organizations should prioritize behavioral hunting for recurring affiliate toolchains irrespective of which RaaS name appears on the ransom note.

Commercial RMM Suites Becoming the Default Hands-on-Keyboard Control Plane for Affiliates

This development highlights the maturation of ransomware post-compromise control around legitimate remote monitoring and management platforms rather than custom command-and-control (C2) alone. September 2026 analyses of Storm-2570 and Settra-linked activity repeatedly documented MeshAgent, Atera, ScreenConnect, Splashtop, Remotely_Agent, and NinjaRMM as operational bridges for command execution, account manipulation, and lateral expansion. Actors further tailored MeshAgent deployments with victim-themed binary and service names and Base64-obfuscated command channels, converting enterprise-trusted RMM into stealthy ransomware staging infrastructure.

ETLM Assessment:

Affiliates are expected to deepen RMM portfolio rotation so that blocking one vendor only forces substitution among peer remote-administration products (High confidence). Allowlists that treat MeshAgent or Atera as inherently benign will continue to create blind spots once an adversary can rename and redeploy agents at scale. Defenders should inventory authorized RMM, alert on new agent installs outside change windows, and treat unexpected MeshCentral or multi-RMM coexistence as high-fidelity ransomware staging indicators.

Outbound Tunnel Services Paired with RMM to Convert Perimeter Blocks into Durable Internal Access

This activity highlights an evolution in ransomware persistence where commercial RMM is reinforced by outbound tunnel utilities that defeat inbound firewall assumptions. September 2026 Storm-2570 reporting detailed Cloudflare Tunnel services installed under LocalSystem alongside MeshAgent, plus ngrok exposure of RDP after policy and firewall changes enabled TCP 3389. The combined pattern turns compromised hosts into self-egressing management nodes, preserving hands-on-keyboard reach even when perimeter inbound remote access remains closed.

ETLM Assessment:

Ransomware operators are likely to standardize dual-channel persistence that pairs interactive RMM with always-on encrypted egress tunnels, reducing dependency on any single C2 domain (High confidence). Network controls that only restrict inbound VPN or RDP will remain insufficient against LocalSystem Cloudflare or ngrok services. Detection should correlate new tunnel service creation, unexpected cloudflared binaries, and RDP enablement scripts with unauthorized RMM installs.

Cloud Object-Store Utilities Industrializing Pre-Encryption Double Extortion

This campaign illustrates how ransomware data-theft tradecraft is evolving from ad-hoc archive uploads toward cloud-admin utilities that blend into legitimate transfer workflows. Across September 2026 Storm-2570 investigations, operators staged s5cmd with credential files to copy filtered business file types into attacker-controlled S3 buckets, while also using Rclone for continuous synchronization. By preferring tools designed for high-throughput object storage, affiliates compress the time between privileged access and publishable leak leverage before encryption begins.

ETLM Assessment:

Double-extortion pipelines are expected to keep favoring commodity cloud CLI tools that defenders already allow for backup and DevOps use, making pure malware-hash blocking ineffective (High confidence). Organizations should treat unexpected s5cmd or Rclone installs, new AWS credential files beside temporary binaries, and large outbound object-store transfers as ransomware-stage events even when no encryptor is yet present. Cloud egress monitoring and least-privilege storage credentials will become core ransomware controls rather than niche cloud-security concerns.

Privileged RMM Console Flaws Entering the Ransomware Access Inventory

This activity demonstrates the continued expansion of ransomware initial access from VPN appliances into privileged remote-management consoles that already hold administrative reach into customer estates. September 2026 reporting on Microsoft-tracked Storm-1175 activity (distinct from the Storm ransomware brand in the top-ten chart) highlighted exploitation of N-able N-central authentication bypass flaws in the CVE-2026-18556 / CVE-2026-18577 family, converting unpatched internet-facing RMM admin planes into full administrative footholds. Once console trust is obtained, follow-on use of SimpleHelp, AnyDesk, BYOVD, and NTDS.dit theft shows how RMM compromise collapses multiple later ransomware steps into a single privileged beachhead.

ETLM Assessment:

Access brokers and affiliates are expected to treat exposed RMM and remote-support consoles as durable access inventory comparable to VPN concentrators (Moderate confidence). Patching alone will not suffice if administrative sessions, API tokens, and downstream agent trusts survive after a hotfix. Enterprises and managed service providers (MSPs) should remove public exposure of management consoles, enforce phishing-resistant multi-factor authentication (MFA), and assume that a compromised RMM plane can seed ransomware across many tenants simultaneously.

From Single-Driver Killers to Multi-Kit and Callback-Zeroing BYOVD Tradecraft

This development highlights a technical evolution in ransomware defense evasion where Bring Your Own Vulnerable Driver (BYOVD) abuse is becoming modular, multi-kit, and quieter. September 2026 reporting by Beazley Security Labs (DFIR) described INC Ransom affiliates (tracked above as Incransom) deploying four distinct BYOVD packages in one intrusion, including wrapper utilities that overwrite endpoint detection and response (EDR) driver functions with RET gadgets, while Ontinue’s malware research on Lunex loaders compiled mid-September documented abuse of AMD PDFWKRNL.sys (CVE-2023-20598) to zero kernel notify callbacks after resolving offsets via Microsoft PDB downloads. The shift from terminating security processes toward leaving EDR running but blind raises the bar for integrity-based detection.

ETLM Assessment:

Ransomware and access ecosystems are expected to keep packaging BYOVD kits as reusable affiliate tooling, including help-dialog wrappers that lower skill barriers for operators (Moderate confidence). Vulnerable-driver blocklists that lag signed but abusable I/O drivers will remain a primary gap. Defenders should combine Microsoft vulnerable-driver blocking, Windows Defender Application Control (WDAC), hypervisor-protected code integrity (HVCI) where feasible, and hunts for unexpected driver service installs, PDB symbol downloads from non-debug hosts, and EDR health anomalies that indicate callback neutralization rather than process crash.

Ransomware Binaries Embedding Destructive Recovery-Environment Eviction

This activity demonstrates how ransomware impact capabilities are evolving beyond Volume Shadow Copy deletion into automated destruction of Windows recovery surfaces. Huntress analysis of a September Settra variant showed MeshAgent staging followed by ransomware child processes that invoked reagentc.exe /disable and diskpart scripts assessed to remove recovery partitions, while encrypting files with a .locked_wip extension. Embedding WinRE and recovery-partition eviction inside the encryptor itself shortens the path from privilege to irreversible restoration failure without relying on separate hands-on cleanup scripts.

ETLM Assessment:

Future ransomware builds are likely to standardize recovery-environment sabotage as a built-in impact module rather than an optional affiliate manual step (Moderate confidence). Backup strategies that depend on local WinRE, recovery partitions, or on-host restore media will become less trustworthy after compromise. Organizations should validate offline and immutable backups, monitor reagentc and diskpart abuse from uncommon parents, and treat unexpected recovery disablement as an early ransomware impact signal.

Sustained N-Day Fortinet Authentication Bypass Feeding Gunra Double Extortion

This activity highlights the ongoing industrialization of older Fortinet authentication-bypass flaws into active ransomware access pipelines. The joint #StopRansomware: Gunra advisory AA26-222A issued by the FBI, CISA, DC3, NSA, USSS, and the Republic of Korea’s National Police Agency (KNPA) warned that Gunra operators exploit FortiOS and FortiProxy issues, including CVE-2024-55591 and CVE-2025-24472, to obtain super-admin rights, bypass MFA assumptions on edge appliances, and progress into double-extortion operations. That advisory remained the primary public technical baseline for Gunra/Fortinet risk through September 2026. The evolutionary point is durability: patched-in-theory edge CVEs remain operational capital for RaaS affiliates whenever internet-facing Fortinet estates lag firmware upgrades.

ETLM Assessment:

Ransomware operators will continue harvesting residual exposure on Fortinet and peer edge platforms long after disclosure cycles end, because unpatched concentrators remain easier than developing new zero-days (High confidence). Emergency firmware upgrades without session invalidation and compromise assessment will leave previously established admin footholds intact. Continuous external scanning, MFA-proofing of SSL-VPN estates, and rapid credential rotation after Fortinet incident indicators remain essential ransomware hygiene.

Agentic Cloud Automation Extending Destructive Extortion into Azure Control Planes

This development highlights an emerging evolution of ransomware-adjacent impact from endpoint encryption toward high-speed, agent-driven destruction of cloud control-plane resources. Late-September 2026 reporting on Storm-3168 (JADEPUFFER) described highly automated Azure tenant abuse through compromised service principals, compressing hundreds of reconnaissance and destructive operations into short windows that deleted storage accounts, Key Vault material, and related services while attempting to disable backup and Site Recovery protections. Shared staging infrastructure with earlier large-language-model (LLM) agent campaigns shows how autonomous tooling can accelerate identity-driven cloud extortion without a classic on-prem encryptor.

ETLM Assessment:

Threat actors are expected to expand agentic automation against cloud identity and management APIs, prioritizing service principals and backup-lock bypasses that maximize irreversible business impact (Low-to-Moderate confidence). Cloud ransomware readiness must therefore include service-principal least privilege, continuous Azure Resource Manager (ARM) audit analytics, and immutable backup locks that cannot be disabled by the same compromised identity. Defenders should treat rapid bursts of destructive ARM operations as ransomware-class events even when no Windows encryptor hash is observed.

OVERALL RANSOMWARE TRENDS, SEPTEMBER 2026

  • Cross-ecosystem affiliates are stabilizing shared post-compromise toolchains while rotating ransomware brands for monetization flexibility.
  • Commercial RMM platforms, especially MeshAgent, are consolidating as the preferred hands-on-keyboard control plane for ransomware affiliates.
  • Victim-themed renaming and command obfuscation of legitimate RMM agents continue to erode allowlist-based trust models.
  • Outbound Cloudflare Tunnel and ngrok services are being paired with RMM to preserve access against inbound firewall assumptions.
  • s5cmd and Rclone are industrializing pre-encryption double extortion through cloud object-store workflows.
  • Privileged RMM consoles such as N-able N-central are joining VPN appliances as high-value ransomware access inventory.
  • BYOVD tradecraft is evolving from single-driver killers toward multi-kit deployments and quieter kernel callback zeroing.
  • PDB-guided offset resolution is making vulnerable-driver abuse more portable across Windows builds.
  • Ransomware binaries are embedding WinRE disablement and recovery-partition destruction as built-in anti-recovery modules.
  • Older Fortinet authentication-bypass CVEs remain active Gunra access capital where firmware lag persists.
  • Defender exclusion and real-time monitoring tampering remain a consistent pre-encryption ritual across multiple RaaS payloads.
  • dit and Install-From-Media (IFM) style credential dumping continues to convert domain privilege into durable offline identity capital.
  • Agentic automation against Azure service principals is expanding destructive extortion beyond classic endpoint encryption.
  • Brand-centric ransomware tracking is becoming less predictive than affiliate tooling, RMM abuse, and edge/RMM vulnerability reuse.

BUSINESS IMPACT ANALYSIS

Industry studies of ransomware business impact provide useful context for interpreting the operational risk signaled by September 2026 activity. According to Cybereason’s Ransomware: The True Cost to Business study (2022), approximately 31% of surveyed organizations were forced to temporarily or permanently suspend operations following a ransomware attack. The same Cybereason study reported that nearly 40% of affected organizations laid off staff, and 35% experienced C-level executive resignations in the aftermath of an attack.

The financial and recovery burden is material even when no ransom is paid. Downtime, rebuild effort, legal and notification costs, and business interruption frequently exceed the ransom demand itself, and organizations that refuse to pay still carry the full cost of restoring and securing their systems.

EXTERNAL THREAT LANDSCAPE MANAGEMENT (ETLM) OVERVIEW

Impact Assessment

Ransomware remains a major threat to both organizations and individuals, locking critical data and demanding payment for its release. The consequences extend well beyond the ransom, often leading to costly recovery efforts, extended downtime, reputational harm, and potential regulatory fines. Such disruptions can destabilize operations and erode stakeholder trust. Addressing this growing risk demands a proactive cybersecurity posture and stronger collaboration between public and private sectors to build resilience against future attacks.

Victimology

Cybercriminals are increasingly targeting industries that manage vast amounts of sensitive data ranging from personal and financial information to proprietary assets. Sectors such as professional services, healthcare, real estate and construction, consumer goods and services, manufacturing, information technology, finance, and government remain high on the threat radar due to their complex and extensive digital infrastructures. Adversaries strategically exploit vulnerabilities in economically advanced regions, especially the United States, launching well-planned attacks designed to encrypt critical systems, disrupt production, and extract significant ransom payments.

OUTLOOK

  • Affiliate toolchains (MeshAgent and peer RMM agents, Rclone and s5cmd, Cloudflare Tunnel and ngrok) will persist across ransomware brand changes, so detection keyed to tooling will outperform detection keyed to encryptor family. (High confidence)
  • Exposed RMM and remote-support consoles will join VPN appliances as the primary purchased-access commodity for ransomware affiliates. (Moderate confidence)
  • BYOVD kits will continue to be packaged as reusable affiliate tooling, with callback-neutralization replacing process termination as the preferred evasion. (Moderate confidence)
  • Recovery-environment sabotage will be built into more encryptors, reducing the reliability of on-host restore paths after compromise. (Moderate confidence)
  • Older Fortinet and peer edge-appliance authentication-bypass flaws will remain in active ransomware use wherever firmware lag persists. (High confidence)
  • Agentic automation against cloud identity and management APIs will expand destructive extortion beyond endpoint encryption. (Low-to-Moderate confidence)
  • October victim counts will be measured against September’s final total of 862; monthly volumes are expected to remain within the 2026 range rather than return to August’s peak. (Moderate confidence)

CONCLUSION

Ransomware in September 2026 remains an enduring, multi-stage business threat. Although publicly disclosed incidents fell to 862 from August’s 1,170, the affiliate tradecraft documented this month — shared post-compromise toolchains, RMM and tunnel abuse, cloud-native exfiltration, modular BYOVD and built-in recovery sabotage — indicates, with high confidence, that operator capability has not diminished even where victim counts have. Resilience depends on identity and edge hardening, early lateral-movement detection, governance readiness, and preparation for both encryption and leak-driven outcomes.

RECOMMENDATIONS

STRATEGIC RECOMMENDATIONS:

  1. Strengthen Cybersecurity Measures: Invest in robust cybersecurity solutions, including advanced threat detection and prevention tools, to proactively defend against evolving ransomware threats.
  2. Employee Training and Awareness: Conduct regular cybersecurity training for employees to educate them about phishing, social engineering, and safe online practices to minimize the risk of ransomware infections.
  3. Incident Response Planning: Develop and regularly update a comprehensive incident response plan to ensure a swift and effective response in case of a ransomware attack, reducing the potential impact and downtime.

MANAGEMENT RECOMMENDATIONS:

  1. Cyber Insurance: Evaluate and consider cyber insurance policies that cover ransomware incidents to mitigate financial losses and protect the organization against potential extortion demands.
  2. Security Audits: Conduct periodic security audits and assessments to identify and address potential weaknesses in the organization’s infrastructure and processes.
  3. Security Governance: Establish a strong security governance framework that ensures accountability and clear responsibilities for cybersecurity across the organization.

TACTICAL RECOMMENDATIONS:

  1. Inventory authorized RMM tooling and alert on any new MeshAgent, Atera, ScreenConnect, Splashtop, NinjaRMM, or SimpleHelp installation outside a change window; treat two co-existing RMM products on one host as a ransomware-staging indicator. (Owner: SOC — Priority: Immediate)
  2. Detect and block unauthorized outbound tunnels: New cloudflared or ngrok services, especially running as LocalSystem, and any script that enables TCP 3389 or alters firewall policy. (Owner: SOC / Network — Priority: Immediate)
  3. Alert on s5cmd and Rclone execution, new AWS credential files alongside temporary binaries, and bulk outbound transfers to object storage not on the approved list. (Owner: SOC / Cloud — Priority: Immediate)
  4. Remove public exposure of N-able N-central and other RMM and remote-support consoles; apply the CVE-2026-18556 fix; rotate administrative sessions and API tokens after patching. (Owner: IT / MSP management — Priority: Immediate)
  5. Confirm FortiOS and FortiProxy estates are patched for CVE-2024-55591 and CVE-2025-24472, invalidate existing administrative sessions, and run a compromise assessment on any appliance that was exposed while vulnerable. (Owner: Network — Priority: Immediate)
  6. Enable Microsoft’s vulnerable-driver blocklist, WDAC, and HVCI where feasible; hunt for unexpected driver-service installs, PDB symbol downloads from non-developer hosts, and EDR sensors that are running but silent. (Owner: Endpoint — Priority: High)
  7. Monitor reagentc.exe /disable and diskpart launched from unusual parent processes, and validate that offline or immutable backups exist independently of on-host recovery partitions. (Owner: Endpoint / Backup — Priority: High)
  8.  Apply least privilege to Azure service principals, enable immutable backup locks that the same identity cannot disable, and alert on bursts of destructive Azure Resource Manager operations. (Owner: Cloud — Priority: High