Tag: ransomware
-
Breach Roundup: DeepSeek Sparks Browser Ransomware
Tags: ai, attack, breach, cisa, data, data-breach, fraud, india, iphone, oracle, penetration-testing, ransomwareAlso, False Negatives Causes Trust in AI Pentest to Drop. This week: a DeepSeek browser-only ransomware path, AI pen testing trust dropped, Mustang Panda targeted India, Tata breach exposed iPhone 18 data, CISA flagged BlueHammer in ransomware attacks, 950 Oracle EBS systems exposed, Amazon to pay U.S. Federal Trade Commission penalty over fraud records. First…
-
FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs
After gaining a foothold in thousands of Fortinet firewalls, the attackers are starting to monetize that access, and are also piling on a Nextcloud zero-day bug. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/fortibleed-actors-inc-lynx-ransomware-gangs
-
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials
Tags: access, citrix, credentials, exploit, group, monitoring, ransomware, supply-chain, tactics, threat, vulnerabilityThreat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access.”Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyboard procedures used for lateral First seen on thehackernews.com Jump to…
-
The Gentlemen ransomware: what you need to know
Tags: ransomwareWho Are The Gentlemen? First seen on fortra.com Jump to article: www.fortra.com/blog/gentlemen-ransomware-what-you-need-know
-
FortiBleed Credential Theft Connected to INC and Lynx Ransomware
FortiBleed, the Fortinet credential theft campaign, is now connected to INC Ransom and Lynx, with a Nextcloud zero-day vulnerability also under investigation. First seen on hackread.com Jump to article: hackread.com/fortibleed-credential-theft-in-lynx-ransomware/
-
FortiBleed campaign traced to INC and Lynx ransomware operations
Researchers are also investigating the role of a suspected zero-day vulnerability. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/fortibleed-campaign-traced-to-inc-and-lynx-ransomware-operations/824348/
-
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
This week’s security news is mostly about weak spots.Browsers, bots, sandboxes, AI systems, and email flows all show the same problem in different ways. Everything looks normal until someone tests a small gap and finds a way through.This is not one big break. It is small permissions, weak checks, open systems, and normal tools doing…
-
Forscher warnen: Ransomware-Befall durch Interpol-Masche mit Fake-Beweisen
Angreifer geben sich bei Unternehmen als Personal von Interpol aus und ködern mit angeblichen Beweismitteln. Doch stattdessen gibt es Ransomware. First seen on golem.de Jump to article: www.golem.de/news/ransomware-im-anmarsch-hacker-greifen-mit-fieser-interpol-masche-an-2607-210436.html
-
Ransomware statt Interpol-Beweisvideo
Im Rahmen einer Malware-Kampagne haben Cyberkriminelle kleine Unternehmen in Europa, Asien, dem Mittleren Osten und den USA angeschrieben. Dabei gaben sie sich laut Analyse der Bitdefender-Experten als Beamte von Interpol aus. Die Betrüger behaupteten, ein passwortgeschütztes Archiv mit Dokumenten und Videomaterial zu verdächtigen Aktivitäten des Opferunternehmens zuzusenden. Dahinter verbarg sich in Wirklichkeit Ransomware. Die Opfer…
-
Analyse der Anubis-Ransomware deckt das Vorgehen der Angreifer auf
Arctic Wolf Labs veröffentlicht neue Forschungsergebnisse, die über die bisherige Berichterstattung zur Anubis-Ransomware hinausgehen und auf Erkenntnissen aus fast sechs Monaten Incident-Response-Untersuchungen basieren. Nun haben Verteidiger zusätzliche Möglichkeiten, Angriffe frühzeitig zu erkennen und zu stoppen noch bevor die Ransomware zum Einsatz kommt. Im Mittelpunkt der Analyse steht nicht die Ransomware selbst, sondern das Vorgehen […]…
-
Cybercriminals Pose as Interpol in Phishing Emails to Infect Victims With Ransomware
Bitdefender researchers warned of curious ransomware campaign which has targeted businesses around the world First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/cybercriminals-pose-interpol/
-
Ransomware im Anmarsch: Hacker greifen mit Interpol-Masche an
Angreifer geben sich bei Unternehmen als Personal von Interpol aus und ködern mit angeblichen Beweismitteln. Doch stattdessen gibt es Ransomware. First seen on golem.de Jump to article: www.golem.de/news/ransomware-im-anmarsch-hacker-greifen-mit-fieser-interpol-masche-an-2607-210436.html
-
430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link
FortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks. SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiGate firewalls worldwide, directly to two active ransomware operations: INC Ransom and Lynx. The link isn’t circumstantial. An operator…
-
430,000 FortiGate Devices Exposed in FortiBleed Ransomware Link
FortiBleed exposed 430,000 FortiGate firewalls, linked to INC Ransom and Lynx, enabling domain compromise and at least 12 ransomware attacks. SOCRadar’s Threat Research Unit has connected FortiBleed, a large-scale campaign that harvested credentials from over 430,000 FortiGate firewalls worldwide, directly to two active ransomware operations: INC Ransom and Lynx. The link isn’t circumstantial. An operator…
-
Ransomware im Anmarsch: Hacker greifen mit fieser Interpol-Masche an
Angreifer geben sich in Phishing-Mails als Personal von Interpol aus und locken mit angeblichen Beweismitteln. Doch stattdessen gibt es Ransomware. First seen on golem.de Jump to article: www.golem.de/news/ransomware-im-anmarsch-hacker-greifen-mit-fieser-interpol-masche-an-2607-210436.html
-
Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation
A new Sysdig report traces how an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data in minutes flat. First seen on hackread.com Jump to article: hackread.com/sysdig-jadepuffer-first-agentic-ransomware-operation/
-
Sysdig Details JADEPUFFER, the First Documented Agentic Ransomware Operation
A new Sysdig report traces how an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data in minutes flat. First seen on hackread.com Jump to article: hackread.com/sysdig-jadepuffer-first-agentic-ransomware-operation/
-
AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack
Tags: ai, attack, credentials, exploit, jobs, network, ransomware, rce, remote-code-execution, threatSecurity firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent.Its Threat Research Team calls the operator JADEPUFFER and says a large language model handled the whole job: breaking in, stealing credentials, moving deeper into the network, then encrypting and wiping a…
-
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions.”An operator tied to FortiBleed’s infrastructure was found actively working negotiation panels for both groups, tying mass FortiGate credential theft directly to ransomware deployment First seen on thehackernews.com Jump to…
-
Ransomware statt Interpol-Beweisvideo
Hacker schreiben kleine Unternehmen an, um diese zum Download von Ransomware zu bewegen. Im Rahmen einer Malware-Kampagne haben Cyberkriminelle kleine Unternehmen in Europa, Asien, dem Mittleren Osten und den USA angeschrieben. Dabei gaben sie sich laut Analyse der Bitdefender-Experten als Beamte von Interpol aus. Die Betrüger behaupteten, ein passwortgeschütztes Archiv mit Dokumenten und Videomaterial… First…
-
JADEPUFFER Agentic Ransomware Uses LLM to Automate Database Extortion
The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing Langflow instance via CVE-2025-3248, used the AI-host environment to harvest cloud and API credentials, and pivoted into a production MySQL/Nacos deployment to carry out a destructive, database-focused extortion playbook without a…
-
AI-Generated Browser Ransomware Abuses Chromium API on Windows, Linux, macOS, Android
Cybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining “unrealistic browser-malware concepts with a real browser capability” to turn it into a working ransomware technique that runs entirely inside the browser on both Windows and Android devices.”This is the first documented case where a frontier AI…
-
Catching ransomware on the wire before it locks the file server
Corporate networks keep sensitive files off individual workstations and store them on shared servers that staff reach through mapped network drives. That arrangement hands … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/02/shared-storage-ransomware-detection-research/
-
FortiBleed Campaign Linked to INC and Lynx Ransomware Operations
A direct operational link between the large-scale FortiBleed credential-harvesting campaign and two active ransomware-as-a-service (RaaS) groups: INC Ransom and Lynx. This finding provides the first confirmed evidence that mass theft of FortiGate credentials is being integrated into ransomware deployment processes, significantly increasing the threat posed by exposed firewall infrastructure. FortiBleed Campaign Linked to INC and…
-
Healthcare Cybersecurity Threats Persist in 2026
SonicWall found healthcare remains the top cybersecurity target, with rising malware, ransomware, and medical IoT threats. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/healthcare-cybersecurity-threats-persist-in-2026/
-
FortiBleed credential-theft campaign linked to Lynx ransomware
The massive FortiBleed credential theft campaign has been linked to the INC and Lynx ransomware operations, suggesting the stolen Fortinet credentials were intended to fuel future network intrusions. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fortibleed-credential-theft-campaign-linked-to-lynx-ransomware/
-
Ransomware-Proof Backup: 7 Strategies for Enterprise IT Teams
Ransomware-proof backup planning helps IT teams protect clean data copies, isolate storage, test recovery, and keep operations running after cyber attacks fast. First seen on hackread.com Jump to article: hackread.com/ransomware-proof-backup-strategies-enterprise-it-teams/
-
Fake Interpol Investigation Emails Push Ransomware at Small Businesses Globally
Fake Interpol investigation emails are targeting small businesses with Proton Drive links that deliver ransomware, encrypt files, and route victims to Tox chat. First seen on hackread.com Jump to article: hackread.com/fake-interpol-investigation-emails-ransomware-small-businesses/

