Gen. partnerAlgotech

Hackers Turn Up the Heat. Companies Face Physical Threats, Police and Kidnappings

Cyberattacks have in recent years become a routine part of life for companies, institutions and ordinary users. But the last few weeks show the situation is moving even further. According to security experts, ransomware gangs are increasingly using physical intimidation, educational platforms are dealing with massive data leaks, and new critical vulnerabilities are appearing even in the Linux kernel. In the new episode of CCTV NEWS #330 we looked at several of the most notable events of the last days.

|
May 18, 2026

Cyberattacks have in recent years become a routine part of life for companies, institutions and ordinary users. But the last few weeks show the situation is moving even further. According to security experts, ransomware gangs are increasingly using physical intimidation, educational platforms are dealing with massive data leaks, and new critical vulnerabilities are appearing even in the Linux kernel. In the new episode of CCTV NEWS #330 we looked at several of the most notable events of the last days.

Hackers are starting to threaten with physical violence as well

Security experts warn of a worrying trend where some ransomware groups are no longer relying solely on encrypting data and threatening to publish it. According to a study by Semperis, approximately 40% of ransomware incidents last year also involved some form of physical intimidation.

The BBC described, for example, cases where attackers contacted employees by phone and knew their home addresses or family details. The FBI has previously warned about groups linked to the “The Com” network, which has been associated not only with cybercrime but also with physical attacks and extortion.

Similar incidents are increasingly appearing around cryptocurrencies as well. In France, for example, police investigated the kidnapping last year of the father of a crypto-millionaire, where the attackers demanded a ransom.

Canvas closed a deal with hackers after the attack

Instructure, the company that operates the Canvas learning platform, confirmed an agreement with attackers associated with the ShinyHunters group after a massive security incident.

According to available information, up to 275 million records from thousands of schools and universities may have been compromised. The attackers then began altering Canvas login pages and published threatening messages demanding ransom negotiations.

The company stated it obtained digital confirmation of data deletion, but at the same time admits that when communicating with cybercriminals there is never complete certainty that the data has truly been removed.

Security experts mainly warn about the risk of very convincing phishing aimed at students, parents and school staff.

Škoda Auto addresses data compromise from the German e-shop

Automaker Škoda Auto confirmed a security incident involving the German online shop shop.skoda-auto.de.

According to the company, attackers exploited a vulnerability in the e‑shop system and gained access to a portion of customer data. Among the compromised information could have been email addresses, phone numbers, addresses or order information.

Škoda also states that the incident did not affect the Škoda Connect platform or the automaker's main systems. Nevertheless, the company warns customers about possible phishing attacks and misuse of the leaked data.

Pwn2Own Berlin 2026 showed the power of modern exploits

The security competition Pwn2Own Berlin 2026 this year produced a total of 47 new zero‑day vulnerabilities and rewards exceeding $1.29 million.

Over three days researchers successfully compromised, for example, Microsoft Exchange, Windows 11, VMware ESXi and Microsoft Edge. The highest reward went to the well-known researcher Orange Tsai from the DEVCORE team for a chain of bugs allowing remote code execution on Microsoft Exchange.

The competition results also serve as a reminder that even fully updated systems can contain critical vulnerabilities waiting to be discovered.

Linux addresses another critical privilege escalation bug

Researchers also warned about a new Linux vulnerability CVE-2026-46300 nicknamed “Fragnesia”. This is the third similar privilege escalation bug discovered in the past two weeks.

The vulnerability allows local attackers to obtain root privileges by manipulating the kernel page cache, and experts say it works very reliably across major Linux distributions.

Security companies recommend installing updates as quickly as possible. A proof-of-concept exploit has already been published publicly, which increases the risk of future abuse, especially in server and cloud environments.

Loading comments...

Stay in the loop

Subscribe to our newsletter and get the latest cybersecurity news delivered straight to your inbox.

Your data is safe. You can unsubscribe from the newsletter at any time.