Cyber Weekly: Creds, signed drivers, and shutdowns
July 13, 2026
Three things happened this week that don't normally happen. A vendor told customers to physically shut down their servers. A ransomware strain used a Microsoft-signed driver to kill antivirus before encryption. And researchers confirmed that stolen FortiGate credentials are directly fueling ransomware deployments at industrial scale. That's not a normal Tuesday. Between July 1 and 13, we saw an AI agent run a complete ransomware attack without human help, 7 million driver's license records leak from one phished employee, and attackers calling businesses on Microsoft Teams pretending to be IT support. The credential-to-ransomware pipeline is no longer a theory. It's the operating model. Here's what happened and what you actually need to do about it.
Read more