Tag: ransomware
-
AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android
Cybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining “unrealistic browser-malware concepts with a real browser capability” to turn it into a working ransomware technique that runs entirely inside the browser on both Windows and Android devices.”This is the first documented case where a frontier AI…
-
Check Point Research warnt vor browser-nativer Ransomware durch KI-generierte Angriffstechnik
Der Fall ist deshalb relevant, weil die KI offenbar eine Lücke zwischen einem bekannten theoretischen Risiko und einer praktisch funktionierenden Angriffstechnik geschlossen hat. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/check-point-research-warnt-vor-browser-nativer-ransomware-durch-ki-generierte-angriffstechnik/a45644/
-
Ransomware ist kein IT-Problem, sondern eine Krise der Business-Continuity
Zu Beginn des ‘Ransomware Awareness Months” warnt Erich Kron, CISO-Advisor bei KnowBe4, Unternehmen davor, dass Malware-Prävention allein nicht mehr ausreicht, um moderne Angriffe abzuwehren. Die Bedrohungslandschaft im Bereich Ransomware hat sich in den letzten 12 Monaten grundlegend verändert. Cyberkriminelle haben das alte Schema aufgegeben, bei dem es lediglich darum ging, auf einen bösartigen Link zu…
-
CISA Warns BlueHammer Flaw Is Now Exploited in Ransomware Attacks
CISA confirms BlueHammer (CVE-2026-33825) is now used in ransomware attacks to gain SYSTEM privileges through Microsoft Defender. BlueHammer, tracked as CVE-2026-33825, has moved from proof-of-concept noise to real ransomware attacks in the wild, the US CISA confirms. BlueHammer allows attackers to escalate privileges locally in Microsoft Defender. The vulnerability, along with two other zero-days dubbed…
-
So organisieren sich Ransomware-Gruppen heute
Tags: ransomwareDie Strukturen hinter Ransomware-Angriffen verändern sich. Statt unabhängig voneinander zu agieren, arbeiten viele Cyberkriminelle inzwischen enger zusammen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/organisieren-ransomware-gruppen
-
Wenn KI den Angriff erfindet Browser-native Ransomware
Keine App. Kein Exploit. Keine technischen Kenntnisse erforderlich schon ein einziger Klick zur Erteilung einer Browserberechtigung könnte Jahre an Handyfotos, Ausweisdaten und Wiederherstellungscodes gefährden. Die Sicherheitsforscher von Check Point Research haben ein von Deepseek generiertes Malware-Sample aufgedeckt. Dabei hat ein KI-Modell eigenständig ein theoretisches Browser-Risiko mit einer funktionierenden Ransomware-Technik verknüpft. Diese wird vollständig im […]…
-
The Gentlemen Ransomware Targets Large Corporations and Critical Infrastructure Worldwide
The Gentlemen ransomware group has emerged in 2026 as a highly adaptive and technically sophisticated ransomware-as-a-service (RaaS) operation targeting large corporations and critical infrastructure across multiple regions. Public reporting places The Gentlemen among the top 10 ransomware actors by victim announcements on its data leak site during the first half of 2026 (see ransomware.live/stats/2026), and…
-
Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique
Tags: ai, attack, chatgpt, cybercrime, LLM, malicious, malware, programming, ransomware, software, toolesearch by:Alexey Bukhteyev Key Takeaways Introduction Over the past several years, large language models have reshaped software development, and malware development has followed the same path. Check Point Research has documented this trend from early experiments showing that AI systems could generate offensive components, to cases of cybercriminals using ChatGPT to create malicious tools, and…
-
Ransomware Awareness Month: Unternehmen müssen Business Continuity stärker in den Fokus rücken
Ransomware-Abwehr darf nicht allein im Serverraum geplant werden. Sie gehört auf die Agenda von Geschäftsführung, Rechtsabteilung, Kommunikation, Betrieb, IT, Security und externen Dienstleistern. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/ransomware-awareness-month-unternehmen-muessen-business-continuity-staerker-in-den-fokus-ruecken/a45636/
-
Microsoft Defender: Ransomware-Banden nutzen BlueHammer-Lücke aus
Ransomware-Erpresser nutzen die BlueHammer-Schwachstelle (CVE-2026-33825) in Microsoft Defender aus, um SYSTEM-Rechte zu erlangen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/microsoft-defender-ransomware-bande
-
Hackers Use Vulnerable Windows Drivers to Kill EDR in Ransomware Attacks
Hackers increasingly rely on vulnerable, legitimately signed Windows drivers to neutralize endpoint defenses, turning defense evasion into a decisive phase of modern ransomware attacks. Over the past three years the Bring Your Own Vulnerable Driver (BYOVD) technique has migrated from research proof-of-concept into a commoditized, routinely deployed capability in ransomware-as-a-service toolkits. By abusing signed kernel…
-
Allianzen Kartelle: So organisieren sich Ransomware-Gruppen heute
Neue Formen der Zusammenarbeit und zunehmende Professionalisierung setzen Unternehmen und Organisationen unter Druck. Die Zeiten opportunistischer Ransomware-Angriffe sind vorbei. Das zeigt der Threat Status Report 2025/2026 von aDvens, einem führenden, unabhängigen europäischen Unternehmen für Cybersicherheit. Angesichts wachsender Konkurrenz schließen sich Ransomware-Gruppen zusammen, teilen Ressourcen und bündeln operative Fähigkeiten. Dabei setzen die Gruppen auf zwei… First…
-
XSS.is, The Forum That Ran the Ransomware Supply Chain Is Down. The Market Isn’t
Police arrested the alleged admin of XSS.is, a major cybercrime forum whose trusted escrow service helped power the underground economy. On 22 July 2025, French and Ukrainian police arrested a 38-year-old man in Kyiv and shut down XSS.is, the most influential Russian-language cybercrime forum of the past decade. Europol, which coordinated the operation under the…
-
Medtronic Notifying Patients Affected by Data Theft Hack
Ransomware Gang ShinyHunters Gang Claimed It Stole 9M Records From Device Maker. Medical device maker Medtronic has begun notifying a yet undisclosed number of patients that their information, including health records and Social Security numbers – was compromised in an April cyber incident. ShinyHunters had earlier claimed to steal more than 9 million of the…
-
Why Cyber Resilience Must Outpace AI-Driven Threats
Former National Cyber Director Chris Inglis Calls for Coalition Defense Strategy. Cybersecurity leaders must shift from information sharing to true collaboration as AI accelerates ransomware and nation-state threats. Halcyon’s Chris Inglis explains why resilience, coalition defense and human accountability will help security teams outpace increasingly sophisticated attackers. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cyber-resilience-must-outpace-ai-driven-threats-a-32119
-
BumbleBee and AdaptixC2 Deliver Akira Ransomware Through Bing SEO Poisoning
BumbleBee and AdaptixC2 are being used in a highly efficient intrusion chain that starts with Bing SEO poisoning and ends with Akira ransomware deployment, showing how trusted search traffic is now being turned into an enterprise compromise vector. The campaign is notable not for novelty in any single stage, but for how tightly each stage…
-
SystemBC Malware Turns Windows Machines Into SOCKS5 Proxies for Ransomware Attacks
SystemBC (also tracked as Coroxy) remains a versatile and persistent Windows malware family that operators routinely deploy to convert compromised hosts into SOCKS5 proxy gateways and to maintain remote access for follow-on operations. First observed as a payload in exploit kits around 20182019, SystemBC has evolved into a widely traded commodity tool used by multiple…
-
How ransomware syndicates weaponize corporate-style organization
From outsourced labor to tiered pricing models, an inside look at how today’s top ransomware threats operate less like rogue hackers and more like Fortune 500 companies. First seen on cyberscoop.com Jump to article: cyberscoop.com/ransomware-syndicates-corporate-organization-op-ed/
-
Blackfield ransomware asks Nidec Corporation for $2 million ransom
The Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/blackfield-ransomware-asks-nidec-corporation-for-2-million-ransom/
-
Windows BlueHammer flaw now exploited by ransomware gangs
CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-windows-bluehammer-flaw-now-exploited-by-ransomware-gangs/
-
Over 300 UK Firms Hit by Ransomware in a Year
Report Fraud data reveals that more than half of 323 UK ransomware victims last year were SMEs First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/over-300-uk-firms-hit-ransomware/
-
(g+) IKEv1-Altlast: Abgekündigtes Protokoll öffnet Ransomware-Banden das Firmen-VPN
Eine kritische Lücke in Check Points VPN wird aktiv ausgenutzt. Kern ist ein totgesagtes Protokoll. Admins sollten IKEv1 abschalten und sich eine grundsätzliche Frage stellen. First seen on golem.de Jump to article: www.golem.de/news/ikev1-altlast-abgekuendigtes-protokoll-oeffnet-ransomware-banden-das-firmen-vpn-2606-210290.html
-
Russian Hackers Accused of Destructive Cyber-Attack on Jaguar Land Rover
Experts warn the Jaguar Land Rover breach bears hallmarks of Kremlin-backed hackers, citing novel ransomware, strategic timing and efforts to obscure attribution First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/russian-hackers-destructive-jaguar/
-
UK businesses fear stigma of ransomware
Data from the UK’s Report Fraud service reveals the scope of ransomware attacks is going underreported, with few businesses confident enough to identify themselves as victims First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645146/UK-businesses-fear-stigma-of-ransomware
-
Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk
Rising threats from third-party actors are forcing institutions to play defense to protect student data from ransomware and other attacks. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/third-party-breaches-teaches-education-lesson-vendor-risk
-
Woodgnat Hackers Use Mistic RAT to Broker Access for Ransomware Gangs
Woodgnat Hackers use Backdoor.Mistic, a stealthy RAT, to let brokers compromise networks and sell entry points to ransomware groups, putting firms at risk. First seen on hackread.com Jump to article: hackread.com/woodgnat-hackers-mistic-rat-access-ransomware-gangs/
-
Ransomware gangs find Europe’s weakest link in third-party suppliers
Ransomware attacks against European organizations increased during the first months of 2026, with third-party suppliers becoming a major entry point for attackers. Black Kite … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/26/black-kite-european-cyber-threats-report/
-
Doppelschlag auf SharePoint: Zwei Ransomware-Gruppen greifen zeitgleich an
Eine Untersuchung von Microsoft zeigt, dass zwei unterschiedliche Angreifer parallel Schwachstellen in lokalen SharePoint-Servern ausnutzen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/sharepoint-zwei-ransomware-gruppen
-
Neuer Ransomware-Boom: Ein Drittel mehr Vorfälle registriert
Tags: ransomwareFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/neu-ransomware-boom-zunahme-vorfaelle-2025
-
Breach Roundup: How Hackers Exploited a Cisco SD-WAN Flaw
Also, Three Ubiquiti Flaws Under Exploitation. This week, Mandiant detailed a Cisco SD-WAN hack as attackers exploited Ubiquiti flaws. London Hydro disclosed a customer data breach, researchers flagged cross-cloud bucket hijacking risks an INC ransomware leak, Texas and Gravity SMTP incidents. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/breach-roundup-how-hackers-exploited-cisco-sd-wan-flaw-a-32080

