Back to Feed
RansomwareAug 4, 2026

128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Microsoft Defender stops ransomware attack at QNET in 128 seconds.

Summary

Microsoft Defender successfully detected and isolated a compromised QNET endpoint within 128 seconds, preventing a multi-stage ransomware attack from executing its payload. This incident highlights the effectiveness of automated security solutions in rapidly responding to emerging threats.

Full text

July 31 20 min read CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.

Entities

Microsoft (vendor)Microsoft Defender (product)Midnight Blizzard (threat_actor)CaptiveCrunch (campaign)