Tag: ransomware
-
Sisterhood of the Traveling Packets: How 1,300 Practitioners Hacked a Ransomware Gang’s Leak Site (Flare CTF Writeup)
With women comprising approximately 22% of the global cybersecurity workforce, organizations like Women in CyberSecurity (WiCyS) are actively working to close the gender gap. As a proud partner of WiCyS, we joined forces with SANS Institute to bring the “Sisterhood… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/sisterhood-of-the-traveling-packets-how-1300-practitioners-hacked-a-ransomware-gangs-leak-site-flare-ctf-writeup/
-
Most Firms Unable to Recover Quickly from Ransomware
Tags: ransomwareFenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/four-of-800-clients-hit-ransomware/
-
Critical VMware RCE flaw now exploited by ransomware gangs
Tags: attack, cisa, cybersecurity, exploit, flaw, infrastructure, ransomware, rce, remote-code-execution, vcenter, vmware, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/
-
53 Prozent mehr Cyber-Angriffe auf deutsche Unternehmen im August
Der Monthly-Cyber-Threat-Report für August 2026 von Check Point Research (CPR), die Sicherheitsforschungsabteilung von Check Point Software Technologies, zeigt einen Anstieg globaler Cyber-Angriffe um 22 Prozent. Auch Phishing-Mails und Ransomware-Angriffe nehmen weltweit deutlich zu. Im vergangenen Monat verzeichneten Unternehmen Analysen von Check Point Research zufolge weltweit durchschnittlich 2422 Cyber-Angriffe pro Woche. Dies entspricht einem Anstieg von…
-
Ransomware-Angriff auf Berlin Warum nun die Sicherheit der digitalen Belegschaft im Zentrum stehen sollte
Mit ihrem Angriff auf das Netz der Berliner Landesverwaltung hat uns die Erpressergruppe Rhysida mehr als anschaulich die starke Anfälligkeit der IT unserer öffentlichen Verwaltung für Cyberangriffe vor Augen geführt. Über einen Terminalfix-Angriff scheinen die Angreifer in die IT-Bereiche der Senatsverwaltung für Stadtentwicklung, Bauen und Wohnen sowie der Senatsverwaltung für Mobilität, Verkehr, Klimaschutz und Umwelt eingedrungen…
-
Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware
Threat actors are increasingly weaponizing Microsoft’s Volume Shadow Copy Service (VSS) for two distinct objectives: removing recovery options before ransomware deployment and extracting credential material from protected Windows files. The shift means VSS telemetry should no longer be treated as a simple backup or disk-maintenance event, but as behavior requiring process, identity, and endpoint context.…
-
Weshalb guter Ransomware-Schutz für Backups nicht nur Daten schützt, sondern auch das Repository prüft
Unveränderliche Backups gelten als letzte Verteidigungslinie gegen Ransomware. Doch was passiert, wenn Angreifer nicht die Produktivsysteme, sondern das Backup-Repository selbst ins Visier nehmen? Kai Hambrecht von Grau Data geht dieser Frage auf den Grund. Übermäßige Admin-Rechte, Active-Directory-Anbindung, unzureichende Netzwerksegmentierung oder manipulierte Restore-Punkte können dazu führen, dass Backups im Ernstfall nicht mehr verfügbar oder wiederherstellbar sind.…
-
Mantax Otax Targets Android Phones With Spyware and Ransomware
Mantax Otax Android malware steals messages, PINs, and files, monitors screens, and uses ransomware and harassment to pressure victims into paying. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-mantax-otax-android-malware-apac-indonesia/
-
Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence
Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced the 44-year-old to four years in prison this week for conspiracy…
-
From Hacks to Bioweapons, Claude Misuse Is Now Everywhere
Plus: The US disrupts the internet’s biggest black market, a Conti ransomware hacker gets prison time, Meta fails to stop AI-generated videos of child abuse. First seen on wired.com Jump to article: www.wired.com/story/security-news-this-week-from-hacks-to-bioweapons-claude-misuse-is-now-everywhere/
-
Ukrainian Conti Ransomware Developer Gets 4 Years in US Prison
Lytvynenko Admitted Developing Malware and Stealing Data for Conti. A U.S. court sentenced Ukrainian national Oleksii Lytvynenko to four years in prison after he admitted developing malware and stealing data for Conti, the ransomware operation blamed for more than 1,000 victims and $150 million in payments. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/ukrainian-conti-ransomware-developer-gets-4-years-in-us-prison-a-32805
-
Report Surfaces Attacks Are Aimed at Narrow Range of Edge Computing Devices
SentinelOne and Tenable have released a joint report that suggests that both state-sponsored actors and ransomware operators are squarely focused on specific edge computing platforms that have a small set of high-severity vulnerabilities that are being regularly exploited. Luke Tamagna-Darr, vice president of research at Tenable, said that pattern suggests cybersecurity teams should prioritize those..…
-
Ukrainian hacker gets four years in US prison over Conti ransomware attacks
A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022. First seen on therecord.media Jump to article: therecord.media/conti-ransomware-ukraine-hacker
-
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Tags: access, authentication, cisco, control, credentials, cve, exploit, firewall, flaw, group, ransomware, threatThree threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls, run…
-
Wie der Untergrundmarkt für Industrie-Zugänge tickt
Ein TrendAI-Report zeigt, wie Access Broker, Ransomware-Gruppen und Hacktivisten dieselben Zugänge zu Industrie und Energiefirmen nutzen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/industrie-zugaenge
-
12 Best Server Security Solutions Compared (2026): Features Pricing
Quick Answer: CrowdStrike and SentinelOne lead server EDR; Trend Micro Deep Security owns virtual patching for unpatchable estates; Microsoft Defender for Servers is the per-resource anchor for Azure/hybrid; Bitdefender and ESET deliver efficacy at value. Server pricing runs per server/workload always confirm Linux feature parity. Servers are where ransomware crews head after the first phish:…
-
12 Best Ransomware Protection Solutions Compared (2026): Features Pricing
Quick Answer: No single product stops ransomware. The strongest stacks combine EDR prevention (CrowdStrike, SentinelOne, Microsoft Defender, Sophos, Bitdefender), managed eyes-on-glass (Huntress, Sophos MDR), and guaranteed recovery (Rubrik, Acronis). Note: ColorTokens is microsegmentation and Rubrik is cyber resilience containment and recovery layers, not EDR. Ransomware is now a professionalized industry double-extortion ransomware operations, hands-on-keyboard operators,…
-
Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files
Mantax OTAX is aggressive Android malware family combines ransomware, spyware, credential theft, and remote device-control features in a single infection chain. Linked to Indonesian threat actors, the campaign targets users through sideloaded APKs and turns compromised devices into tools for surveillance, financial fraud and real-time extortion. Unlike conventional Android ransomware that focuses primarily on locking…
-
11 Best Device Control USB Security Tools Compared (2026): Features Pricing
Quick Answer: CoSoSys Endpoint Protector leads cross-platform (Windows/macOS/Linux) device control; Safetica and ManageEngine win mid-market value; Symantec (Broadcom), Forcepoint, and Digital Guardian (Fortra) anchor enterprise content-aware DLP; Ivanti DeviceLock offers the deepest Windows peripheral granularity. Pricing is almost always per endpoint. One rogue USB stick can import ransomware or export your customer database which is…
-
12 Best Endpoint Privilege Management (EPM) Tools Compared (2026): Features Pricing
Quick Answer: CyberArk and BeyondTrust lead enterprise EPM; Delinea balances depth with usability; Admin By Request and CyberFOX AutoElevate make local-admin removal painless for SMBs and MSPs; Microsoft Intune EPM is the bundled-adjacent option for Entra estates. Most tools price per endpoint or per user. Standing local-admin rights are the fuel of ransomware and lateral…
-
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Tags: attack, authentication, cisco, credentials, cve, exploit, firewall, flaw, ransomware, software, threat, vulnerabilityCisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass First seen on…
-
Conti ransomware gang member sentenced to 4 years in prison
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/conti-ransomware-gang-member-sentenced-to-four-years-in-prison/
-
Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement
A new Windows remote-access trojan dubbed SloppyRAT, which appears to be positioned as an intrusion-enablement tool for ransomware operations. First observed in June 2026, the malware is delivered through a multi-stage ClickFix chain and combines host reconnaissance, stealthy command execution, reverse proxying, and resilient command-and-control mechanisms to support post-compromise activity and lateral movement. Rather than…
-
Building a ransomware decision tree before the call comes in
In this Help Net Security video, Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walks through the ransomware decision tree in this video. She covers four areas … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/11/ransomware-decision-tree-video/
-
Cisco Firewall Bugs Let in Sandworm, Qilin
Cisco Observed 3 Distinct Intrusion Clusters Exploiting 1 or Both Flaws. Cisco says a nation-state actor and a Qilin ransomware operator are actively exploiting two Secure Firewall Management Center flaws to gain root or credential-based access, steal sensitive data, deploy Sandworm-linked malware and prepare networks for encryption. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cisco-firewall-bugs-let-in-sandworm-qilin-a-32793
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/
-
Conti ransomware crew member sentenced to four years in prison
Oleksii Lytvynenko joined the notorious group in 2021 and was directly involved in attacks on at least 12 companies. First seen on cyberscoop.com Jump to article: cyberscoop.com/conti-ransomware-developer-sentenced/
-
Conti ransomware crew member sentenced to four years in prison
Oleksii Lytvynenko joined the notorious group in 2021 and was directly involved in attacks on at least 12 companies. First seen on cyberscoop.com Jump to article: cyberscoop.com/conti-ransomware-developer-sentenced/

