What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,922 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 3h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 1d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 7h ago
-
Weekly Update 517: Cyber Ransoms
The current ransomware situation is a bit of a kludge (deep breath): a lot of ransomware (which often doesn t even involve ware , it s just extortion) is carried out by kids who successfully make a truckload of money but can t spe…
-
Ukrainian software developer faces 12 years in Swiss ransomware trial
The unnamed 52-year-old is accused of attacking Swiss train manufacturer Stadler Rail alongside other enterprises as part of an international ransomware operation.
-
Details emerge on BlackFile’s recent attacks on financial companies
BlackFile’s four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google. The post Details emerge on BlackFi…
-
17th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected …
-
Researchers confirm breach claims by data-extortion group
The exfiltrated data may be related to misconfiguration of Microsoft Power Page portals, according to a new report.
-
The Good, the Bad and the Ugly in Cybersecurity – Week 33
Courts sentence Com member for sextorting 117 minors, joint advisory warns of Gunra ransomware, and ShieldBreak bypasses MS Defender for SYSTEM access.
-
Shell investigates 'potential incident' after Clop data theft claims
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...]
-
Data analyst sent to prison for stealing data, extorting employer
A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme. [...]
-
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]
-
The State of Ransomware Q2 2026
For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State …
-
Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.
-
Akira Hits Safe Mode: Ransomware Rebooting Around EDR
An Akira affiliate rebooted into Safe Mode to kill EDR and Defender, then Safe Mode broke their own ransomware. Here’s the full attack chain.
-
DeadLock ransomware uses blockchain to resist infrastructure takedown
The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity. [...]
-
Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.
-
Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout
The hackers claimed to have exfiltrated 6 terabytes of data, including highly sensitive health information like records related to sexual assault, mental health, abortions and sexual harassment incidents.
-
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines …
-
Former BlackFile affiliates linked to extortion campaign targeting private equity
Researchers warned that hackers are using voice-phishing attacks to pressure company employees under the guise of providing IT help desk services.
-
US and South Korea warn of Gunra ransomware targeting govt agencies
U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]
-
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and…
-
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.
-
U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang
The ransomware-as-a-service outfit has gone after a range of critical infrastructure sectors across the globe. The post U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang appeared first on Cy…
-
New StormEncryptor ransomware used by former Medusa affiliate
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]
-
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the advers…
-
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operati…
-
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operati…
-
China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns
A China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able.
-
Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed
Plus: A judge rules cell tower dumps unconstitutional, water utility hacks spread to a dozen states, a phishing email opens a missile-parts supplier’s inbox, and a ransomware boss gets 16 years.
-
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
A recent wave of cyber attacks targeting financial services, private equity, and professional services has been attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing (vishing) to targe…
-
Vishing Extortion Group UNC6671 Rebrands After Making Millions
Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands. The post Vishing Extortion Group UNC6671 Rebrands After Making Millions appeared first on SecurityWeek .
-
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors. [...]
-
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021. Between 2021 and 2023, Ransom …
-
Ransom Cartel ransomware creator sentenced to 16 years in prison
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide. [...]
-
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomwar…
-
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomwar…
-
AI Agent Carried Out A Ransomware Attack Without Any Human Oversight
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 4, 2026 – Listen to the podcast This wasn t someone behind the keyboard using AI as a tool to write malware, says Heather Engel, guest exp…
-
Weekly Cyber Update: 31 July 2026
Russian hackers target hotel and conference centre Wi-Fi; Cl0p is back with another extortion campaign; OpenAI and Anthropic models go rogue; and the Health-ISAC warns of intensifying Shiny Hunters campaigns. The Cyber Threat Inte…
-
Toy Ghouls’ new toy: the GenieLocker ransomware
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.
-
AI Autopsy: JadePuffer Claims a First for AI-Driven Ransomware
JadePuffer signals a new era of machine-speed cyberattacks, where AI agents can execute ransomware campaigns with minimal human input JadePuffer, described as the first fully autonomous AI-driven ransomware operation, could usher …
-
FBI: Breaking Affiliate Trust Sped Along LockBit's Takedown
An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time.
-
Security Research Labs reports on a wave of extortion attacks hitting women's shelters. The original report is…
Security Research Labs reports on a wave of extortion attacks hitting women's shelters. The original report is in German, but scroll down for English. https:// srlabs.de/blog/erpressungswell e-auf-frauenhaus
-
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP f…
-
A new extortion cocktail: office printers, small ransoms, and BitLocker
We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.
-
Pay up or not? Ransomware surge has victims facing tough choices.
Governments look at banning ransom payments in face of increasingly sophisticated threats.
-
It’s Not Safe To Pay SafePa
Huntress has observed Akira ransomware affiliates in action, as well as ReadText34 and INC ransomware being deployed.
-
Anubis ransomware: what you need to know
The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard - but they are not the only ones at risk. Read more in my article on the Fortra blog.
-
Every Ransomware Attack Has a Backstory
Ransomware is the final act, not the first move. Learn how attackers use access brokers and trusted tools to infiltrate your environment—and how to stop them early.
-
AI Autopsy: JadePuffer Claims a First for AI-Driven Ransomware
The first autonomous ransomware campaign has arrived. Here s why every CISO should be paying attention. Phil Muncaster examines JadePuffer, the first documented end-to-end autonomous ransomware campaign, and considers what it mean…
-
5 Modern Threats You Need to Watch
Ransomware, BEC, and social engineering attacks increasingly start with a simple login, not malware. See the five threat patterns IT and security teams need to watch for, and how to catch them early.
-
The ransomware negotiator who was working for the other side
When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help. Specialist ransomware negotiation firms handle communications with criminal gangs on a victim's behalf. What victims don't …
-
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42 .
Last fetch 1m ago · 11 new · 2 source error(s)