The Cactus ransomware gang claims to have stolen 1.5 terabytes of data from Schneider Electric, an OT manufacturer, and posted a sample online as proof. The stolen data reportedly includes US passports and non-disclosure agreements. Shawn Wiora, CEO of Token, warns this could result in a record ransomware payment. He notes that such losses are often due to reliance on outdated MFA technology to counter AI-driven cyberattacks. Schneider Electric confirmed that data from its Sustainability Business Division was compromised during the attack.

Mandiant warns of attacks on newly-disclosed Ivanti remote takeover threat
Google’s Mandiant team has issued an alert about a remote code execution flaw in the Ivanti Connect Secure VPN platform. The vulnerability, designated CVE-2025-22457, is