Tag: ransomware
-
Ransomware attack halts Coca-Cola’s Fairlife US milk production
A ransomware attack has stopped milk production at Fairlife, the Coca-Cola dairy brand known for its high-protein milk, protein shakes, and nutrition drinks. Coca-Cola … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/17/coca-cola-fairlife-ransomware-attack/
-
Anubis ransomware: what you need to know
The Anubis ransomware-as-a-service (RaaS) operation has hit some healthcare organisations hard – but they are not the only ones at risk. First seen on fortra.com Jump to article: www.fortra.com/blog/anubis-ransomware
-
Coca-Cola suspended production at its Fairlife dairy after a ransomware attack
Coca Cola said dairy production at its Fairlife unit will “remain suspended” in the United States following a hack. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/16/coca-cola-suspended-production-at-its-fairlife-dairy-after-a-ransomware-attack/
-
Breach Roundup: Extortionists Annoyed by Waning Ransomware
Also, US Sanction Cybercrime Enablers, Celine Dion Ticket Scam. This week, ransomware victims paying less, cybercrime sanctions, Celine Dion ticket scams, 23andMe to pay $18 million, a 13-year old Daixin infection, Spiral ransomware, Patch Tuesday, CISA ordered rapid SharePoint patching and Spanish police busted a cybercrime ring. Sore Egyptian World Cup losers. First seen on…
-
Coca-Cola says Fairlife ransomware attack halts US dairy production
The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/coca-cola-says-fairlife-ransomware-attack-halts-us-dairy-production/
-
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories
A lot of this week’s trouble starts with something that looks close enough.A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than the explanation.Old bugs are back, weak defaults are earning their keep, and some attack paths…
-
Sicherheitslücken für Backups in nur 15 Minuten aufgedeckt
Grau Data ergänzt sein Angebot für Ransomware-Schutz für Backups um den neuen Service ‘Repository Security Check für Windows”. Dieser kann unabhängig vom Einsatz von <> genutzt werden und identifiziert potenzielle Schwachstellen, über die Angreifer auf lebenswichtige Backups zugreifen könnten. In durchschnittlich nur 15 Minuten erhalten Unternehmen Klarheit darüber, wie sicher ihre Backup-Repositories sind. […] First…
-
New Spirals ransomware encrypts victim network in under 24 hours
A new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-spirals-ransomware-encrypts-victim-network-in-under-24-hours/
-
U.S. Treasury Sanctions VPN Provider and Cryptor Seller Behind Billions in Ransomware Losses
U.S. sanctions hit VPN provider 1VPNS and a cryptor seller for enabling ransomware gangs behind billions in losses to critical infrastructure. The U.S. Treasury’s Office of Foreign Assets Control sanctioned two individuals and one entity on July 13 for supplying tools and infrastructure to ransomware groups that have caused billions of dollars in losses to…
-
Treasury sanctions First VPN Service, others for abetting ransomware gangs
The designations hit 1VPNS, its alleged Ukrainian administrator and a Belarusian who allegedly sold “cryptors” to disguise ransomware and other malware. First seen on cyberscoop.com Jump to article: cyberscoop.com/us-sanctions-first-vpn-ransomware/
-
Ransomware-Analyse von Arctic Wolf – Anubis-Angriffskette erkennen, Angriff verhindern
First seen on security-insider.de Jump to article: www.security-insider.de/anubis-ransomware-erstzugriff-citrixbleed2-vpn-remote-tools-a-dcb86e3683a0576cc0af240018e346b0/
-
US sanctions VPN, malware providers for enabling ransomware attacks
The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned two individuals and one entity for enabling ransomware attacks against U.S. organizations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-sanctions-vpn-malware-providers-linked-to-ransomware-gangs/
-
The ransomware negotiator who was working for the other side
When a company falls victim to a ransomware attack, it is not uncommon for it to turn to experts for help. First seen on bitdefender.com Jump to article: www.bitdefender.com/en-us/blog/hotforsecurity/ransomware-negotiator-working-other-side
-
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) has designated two individuals and a VPN service provider for enabling ransomware actors’ and other cybercriminals’ malicious activities, including ransomware attacks against Americans.The VPN, named First VPN Service (1VPNS), has been accused of offering its tools to ransomware groups, along with its 45-year-old Ukrainian First…
-
VPN service favored by ransomware groups is sanctioned by US
The U.S. Treasury Department announced sanctions against First VPN Service (1VPNS) and its Ukrainian administrator for aiding ransomware groups. Separately, a Belarusian man was sanctioned for malware “cryptors.” First seen on therecord.media Jump to article: therecord.media/first-vpn-administrator-us-sanctions-ransomware-groups
-
Ransomware-Recovery: Warum sich die Wiederherstellung lange vor dem Angriff entscheidet
Gleichzeitig speichern lediglich 41 Prozent ihre Backups in einer isolierten Umgebung. Nur 47 Prozent testen regelmäßig, ob sich die Daten tatsächlich wiederherstellen lassen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/ransomware-recovery-warum-sich-die-wiederherstellung-lange-vor-dem-angriff-entscheidet/a45729/
-
âš¡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That’s supposed to be the good news. The catch is that the attackers have the same tools, pointed the other way, and they don’t file tickets.That’s the shape of this week. Trusted code turns on the people who…
-
Ransomware negotiator who betrayed clients sentenced to 70 months in prison
A former ransomware negotiator at incident response firm DigitalMint has been sentenced to 70 months in prison after admitting he shared confidential client information with … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/ransomware-negotiator-blackcat-sentence/
-
Hacker Extradited from Ukraine Pleads Guilty to Ryuk Ransomware Charges
An Armenian man has pleaded guilty to his role in the infamous Ryuk ransomware operation First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hacker-extradited-ukraine-guilty/
-
Armenian man pleads guilty to deploying Ryuk ransomware
Tags: ransomwareFirst seen on scworld.com Jump to article: www.scworld.com/brief/armenian-man-pleads-guilty-to-deploying-ryuk-ransomware
-
Ryuk Ransomware Member Pleads Guilty Over Attacks on U.S. Organizations
An alleged Ryuk ransomware member pleaded guilty in the U.S. for helping deploy attacks on American companies and faces up to 15 years in prison. Armenian national Karen Serobovich Vardanyan (34) pleaded guilty in the U.S. for his role in Ryuk ransomware attacks targeting American organizations between 2019 and 2020. Extradited from Ukraine after his…
-
Ransomware ecosystem grows, but ‘four-headed monster’ dominates
AI is helping hackers, a new report finds, but mostly by automating very human behaviors. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ransomware-concentrated-ai-guidepoint/824828/
-
Latvian forestry company still restoring systems weeks after ransomware attack
A foreign, financially motivated group was responsible for a cyberattack on state-owned forestry company Latvijas Valsts Mezi (LVM), officials said. First seen on therecord.media Jump to article: therecord.media/latvia-state-owned-foresty-company-lvm-ransomware
-
Advens Threat Status Report 2025/2026 – So organisieren sich Ransomware-Gruppen
First seen on security-insider.de Jump to article: www.security-insider.de/ransomware-gruppen-allianzen-advens-report-2025-2026-a-87658a8cd400e3b7102f7f489fedf60d/
-
GodDamn Ransomware Attack Uses PsExec Lateral Movement and NirSoft Toolkit for Credential Theft
A targeted GodDamn ransomware incident shows the payload is not entirely new but the latest rebrand of a long-running family. Analysis reveals strong code overlap with Beast (the 2024 rebrand of Monster), and the operational playbook mirrors earlier Hyadina campaigns. Stealthy foothold, credential harvesting using NirSoft utilities, kernel-level defense subversion, remote-access tooling, and PsExec-driven lateral…
-
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy.According to a new report published by the Threat Hunter Team from Symantec, the ransomware was first publicly spotted in the wild on May 21, 2026. It’s assessed to…
-
‘GodDamn’ Ransomware Uses BYOVD to Smite US Companies
Microsoft co-signed a malicious kernel driver, and now it’s being used to kill security software in ransomware attacks. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/goddamn-ransomware-byovd-smite-companies
-
Endgeräte als Einfallstor – Recovery nach Ransomware gelang keinem Unternehmen in 24 Stunden
Tags: ransomwareFirst seen on security-insider.de Jump to article: www.security-insider.de/ransomware-endpunkt-recovery-24-stunden-absolute-security-a-83dde55d7c3fe6a7222619b1681a91d0/
-
Everest Ransomware Encryptor Uses ConfuserEx-Protected .NET Binary With Wake-on-LAN Capability
A recent technical analysis of an Everest ransomware encryptor reveals a purpose-built, ConfuserEx-protected .NET 4.0 binary that combines heavy obfuscation, misleading cryptographic declarations, and uncommon network tactics to maximize impact and impede response. The analyzed sample (hlntqyun.exe, SHA-256 1df92b…) is a 114 KB C# assembly compiled for .NET Framework 4.0 and protected with ConfuserEx anti-tamper,…
-
Smashing Security podcast #475: JadePuffer the AI that ran a ransomware attack all by itself
A 15-year-old boy asked a chatbot for help – and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous, agentic AI-driven ransomware attack, “JadePuffer”. What does this tell us about the future of cybersecurity? First seen on grahamcluley.com Jump to article: grahamcluley.com/smashing-security-podcast-475/

