Hospital ransomware fallout, blockchain botnet C2, and AI agent loose in Thailand's Finance Ministry.
South Carolina's AnMed reopened some physician offices four days into a ransomware attack with phones, internet, and systems still offline, forcing manual processes and in-person medication refills, as broader healthcare ransomware totals hit 410 attacks worldwide in the first half of the year and a HIPAA Security Rule update was delayed to 2027 while class-action efforts began.
Researchers report the Dysphoria IoT botnet moved command-and-control to blockchain name services and victim relays, making takedowns harder, with estimates above 200,000 bots and DDoS offerings up to 4 Tbps.
Shared Claude chats were briefly indexed by Google, exposing sensitive data via public share links, before results stopped appearing. Hunt.io found attackers running a Hermes autonomous AI agent in Thailand's Finance Ministry, plus new "Hades" malware, suggesting reconnaissance.
Stadler Rail refused a 10M CHF extortion demand tied to supplier data theft.
00:00 Introduction and Headlines
00:30 South Carolina Hospital Ransomware Attack
02:07 Healthcare Ransomware Crisis
03:25 IoT Botnet Uses Blockchain
05:40 Shared AI Chats Exposed
08:00 AI Agent Infiltrates Thailand Ministry
10:45 Swiss Train Maker Refuses Ransom
12:31 Closing Remarks