Threat Brief — 2026-07-22 — Ransomware gets a CRM, AI models in the crosshairs
Executive summary: Ransomware operators are professionalising and widening their target set. Funky Mantis has adopted a customer-relationship portal to streamline extortion of hospitals and factories, while JADEPUFFER's shift to destroying AI model artifacts is now quantified at $500K-plus recovery costs and months of retraining. Separately, a researcher documented 120 Linux security bypass techniques using built-in system components, and Stadler Rail publicly refused a $12.3M Everest ransomware demand after a supplier-platform breach.
Top items
- JADEPUFFER AI-model destruction costs surface — $500K and months of retraining per victim. New reporting quantifies the impact of JADEPUFFER's tactic of destroying AI models rather than encrypting conventional data, giving defenders the first concrete recovery-cost figures. This is a developing story first reported 2026-07-18 by Mandiant; the new development is specific financial and operational impact data. (src: SecurityLab)
- Funky Mantis ransomware gang deploys a CRM-style "customer portal" for extortion. Internal communications reveal the group is using structured victim-management tooling to pressure hospitals and manufacturing firms, signalling further professionalisation of ransomware operations. (src: SecurityLab)
- Researcher demonstrates 120 ways to bypass Linux security using built-in components. The presentation shows how standard OS primitives can be chained into privilege-escalation and persistence chains without exotic exploits — relevant for hardening guidance on Linux server and container estates. (src: SecurityLab)
- Stadler Rail rejects $12.3M Everest ransomware demand after supplier-platform breach. The Swiss rail manufacturer disclosed that the Everest gang breached a shared data-exchange platform used with a supplier, highlighting third-party data-sharing risk in manufacturing supply chains. (src: BleepingComputer)
- Enterprise GenAI identity sprawl can accelerate ransomware, vendor analysis warns. Acronis outlines how AI assistants and agents inheriting over-privileged identities create new ransomware escalation paths, reinforcing the need for least-privilege and governance controls around AI tooling. (src: BleepingComputer)
- Eclypsium launches InfraTrust knowledge base for infrastructure vulnerability prioritisation. The monthly report targets firmware, networking, and edge-device flaws that admins most urgently need to patch, filling a gap in infrastructure-layer threat-prioritisation tooling. (src: BleepingComputer)
- Cisco's Antares lightweight model finds vulnerabilities offline, preserving data confidentiality. The approach lets organisations run AI-assisted vuln discovery without internet connectivity or risking proprietary code leakage — a practical counterpoint to earlier findings on LLM unreliability in vuln hunting. (src: SecurityLab)
- Movement Labs files for Chapter 11 bankruptcy amid insider-trading scandal. The Movement blockchain project's collapse follows a year of internal conflict; while primarily a crypto-business story, it underscores governance and insider-risk failures in Web3 projects. (src: Xakep)
Themes
Ransomware industrialisation and AI-target expansion. Three of today's items — Funky Mantis's CRM portal, JADEPUFFER's AI-model destruction with quantified costs, and the GenAI identity-sprawl analysis — converge on the same trend: ransomware operators are both professionalising their extortion workflow and expanding what they target (AI assets) and what they exploit (AI-agent identities). Defenders should treat AI model repositories and AI-agent permission models as first-class attack surface.
===
