128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
Microsoft Defender stops ransomware attack at QNET in 128 seconds.
Summary
Microsoft Defender successfully detected and isolated a compromised QNET endpoint within 128 seconds, preventing a multi-stage ransomware attack from executing its payload. This incident highlights the effectiveness of automated security solutions in rapidly responding to emerging threats.
Full text
July 31 20 min read CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.