Microsoft has released a major security update addressing 570 vulnerabilities (security flaws in software), including 2 zero-day exploits (previously unknown flaws that attackers are already using in active attacks). The company has warned that these zero-days are being actively exploited and urges immediate installation of patches, with some users also finding unofficial patches available for a legacy system flaw called LegacyHive.
Ransomware attacks are changing tactics, and cybersecurity experts say the shift is accelerating in dangerous ways. Instead of focusing on software vulnerabilities, criminal groups are now targeting identity systems as their primary entry point into companies and organizations.
Recent analysis shows that identity attacks have overtaken traditional software exploits as the leading cause of ransomware breaches. This represents a significant change in how hackers operate. Rather than searching for flaws in programs, attackers are going after the usernames, passwords, and digital identities that give them access to networks.
One example of this new approach involves the Inc ransomware group, which has been exploiting zero-day vulnerabilities in SonicWall SMA systems. A zero-day vulnerability is a security flaw that nobody knows about yet, giving hackers a major advantage. By targeting these unknown weaknesses in widely-used security devices, attackers can slip past defenses that companies thought would protect them.
The criminal ransomware group known as "The Gentlemen" operates within this changing landscape, illustrating how organized these cyber criminals have become. Research into their operations shows that ransomware groups have grown more sophisticated and better coordinated than ever before.
While ransomware attacks are accelerating rapidly, security researchers emphasize that artificial intelligence is not the main driver of this growth. Instead, the increase comes from criminals simply switching their methods to exploit what actually works. Identity-based attacks require less technical skill in some ways than finding complex software flaws, making them attractive to a wider range of criminal groups.
This shift presents a serious challenge for businesses and government agencies. Most companies have focused security efforts on protecting their software and systems. Now they must also strengthen protections around user identities, including better password management, multi-factor authentication, and monitoring for suspicious account activity.
The evolution of ransomware tactics shows that cybercriminals adapt quickly when they find new ways to break in. Companies cannot rely solely on traditional cybersecurity approaches anymore. Instead, they need comprehensive defenses that protect identity systems just as carefully as they protect their networks and data. Understanding these changing attack patterns helps organizations stay one step ahead of criminals.