Tag: infrastructure
-
Hacker claims 3.6 million Azure account records stolen from major companies
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/
-
Iran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama
Iran-linked hackers targeted Water Infrastructure in New Jersey and Alabama, bringing confirmed attacks to at least 12 states, with limited disruption. The wave of cyberattacks targeting US water infrastructure has reached New Jersey and Alabama, bringing the confirmed count to at least 12 states since late July. The attacks are linked to Iranian hackers targeting…
-
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
Tags: blockchain, communications, data, extortion, group, infrastructure, leak, microsoft, network, ransomware, service, threatThe ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.”Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,” the Microsoft Threat First seen on thehackernews.com Jump…
-
Alert: Unpatched Fortinet Devices Fall to Gunra Ransomware
Tags: access, cybersecurity, firewall, fortinet, government, group, infrastructure, korea, north-korea, ransomware, vpnUS and South Korea Tie Initial Access to Unpatched Firewalls and VPN Gateways. Critical infrastructure organizations running unpatched firewalls and VPN gateways – including Fortinet gear not updated since early 2025 – and getting hit hard by a ransomware group with possible ties to the North Korean government, warns a joint U.S.-South Korean cybersecurity alert.…
-
Six npm Packages Read C2 Addresses From Ethereum Wallet
Tags: infrastructureSix npm packages queried an Ethereum wallet to locate C2 infrastructure First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/npm-packages-ethereum-wallet-c2/
-
LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target
Tags: ai, attack, breach, cloud, credentials, cyber, infrastructure, malicious, pypi, software, supply-chain, theftThe March 2026 compromise of LiteLLM was more than a short-lived malicious PyPI upload. It demonstrated how an upstream breach in developer tooling can turn AI infrastructure into a high-value conduit for credential theft, cloud intrusion, and downstream software supply chain abuse. The packages were available for roughly 40 minutes before quarantine, but their brief…
-
Water Water Everywhere Possible Iranian Attack to Water Infrastructure
In recent days, a multistate cyber campaign has reached the programmable controllers that run American water and wastewater systems, depriving operators of monitoring and control and, in some cases, contributing to loss of pressure and flooding. Beginning July 27, the FBI and Environmental Protection Agency said, utilities in at least seven states reported intrusions into..…
-
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Tags: attack, breach, cybersecurity, exploit, finance, flaw, fortinet, government, healthcare, infrastructure, intelligence, korea, network, ransomware, serviceCybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world.Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services.”Gunra is another variant in the ongoing trend of First seen on thehackernews.com…
-
Mozilla Rotates Firefox and Thunderbird GPG Signing Key After Private GitHub Exposure
Mozilla has rotated a GPG signing subkey used to authenticate release artifacts for Firefox and Thunderbird after an unencrypted copy of the previous subkey was unintentionally committed to a private GitHub repository. The affected signing infrastructure includes selected release files, such as Linux tarballs, RPM packages, and checksum files. Mozilla’s investigation into available audit logs…
-
US and South Korea warn of Gunra ransomware targeting govt agencies
U.S. federal agencies and South Korea’s National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attacks-against-government-critical-infrastructure/
-
CISA Warns SonicWall SMA1000 Flaws Are Exploited in Ransomware Attacks
Tags: attack, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, ransomware, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in SonicWall SMA1000 to its Known Exploited Vulnerabilities catalog, noting that the flaw has been used in ransomware campaigns. This vulnerability, tracked as CVE-2026-15409, is a server-side request forgery (SSRF) issue found in the Workplace interface of SonicWall SMA1000 appliances. It has…
-
DeadLock Ransomware Disables Windows Defender, Backups and Event Logs Before Encrypting Files
DeadLock, an emerging financially motivated ransomware operation that couples conventional intrusion tradecraft with decentralized infrastructure engineered to survive disruption. First observed in July 2025, the operation uses double extortion: encrypting enterprise data while threatening publication of stolen material. The encryptor’s pre-encryption routine is built to degrade both prevention and recovery. After XOR-decoding an embedded configuration,…
-
CISA Urges Organizations to Patch Exposed VPNs and Segment Networks Against Gunra Ransomware
Tags: advisory, breach, cisa, credentials, cyber, data, data-breach, encryption, exploit, firewall, infrastructure, international, law, network, organized, ransomware, service, theft, update, vpnCISA and international law-enforcement partners have issued a joint #StopRansomware advisory warning that Gunra ransomware affiliates are exploiting exposed edge infrastructure, including VPN gateways, firewall appliances and RDP-accessible systems, to breach enterprise networks. The advisory positions Gunra as an increasingly organized ransomware-as-a-service operation whose affiliates combine data theft, credential compromise and rapid encryption to pressure…
-
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators’ browsers to create rogue admin accounts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/
-
The Art of Detonating Malware: Lessons from a Research Lab
Modern ransomware operators are no longer content to simply encrypt data and hope for a payout. They are actively working to evade every layer of enterprise defense, from sandboxes and EDR to backup infrastructure itself, using techniques observed in Cohesity’s in-house REDLab malware research environment. For security leaders, backup and recovery systems can no longer..…
-
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned. First seen on therecord.media Jump to article: therecord.media/ransomware-south-korea-fbi-gunra
-
U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang
The ransomware-as-a-service outfit has gone after a range of critical infrastructure sectors across the globe. First seen on cyberscoop.com Jump to article: cyberscoop.com/us-south-korea-gunra-ransomware-warning/

