Tag: ransomware
-
SloppyRAT: A New Tool For Ransomware Attacks
IntroductionIn June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain. The malware supports a variety of features including… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/sloppyrat-a-new-tool-for-ransomware-attacks/
-
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/
-
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/
-
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/
-
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/
-
Why immutable backups are critical for ransomware resilience
For most UK SMEs, the real cost of ransomware is not just the ransom demand. It is the interruption to trading, the pressure on staff, the loss of customer confidence, and the time spent trying to recover systems and data…. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/why-immutable-backups-are-critical-for-ransomware-resilience/
-
MantaxOtax Android Malware Combines Ransomware With Spyware
MantaxOtax Android malware combines ransomware with extensive spyware capabilities First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/mantaxotax-android-malware/
-
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/10/cisco-fmc-exploited-cve-2026-20079-cve-2026-20316/
-
Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
Tags: credentials, crypto, cyber, cybercrime, data, exploit, malware, password, ransomware, theft, threatThreat actors are exploiting anticipation around Grand Theft Auto VI by pushing fraudulent “leaked” game downloads that install a layered malware bundle that steals browser credentials, Discord tokens, gaming-session data, and cryptocurrency-related information. A Chaos ransomware variant used as a wiper, and an unexpected Yandex Browser installer. The campaign demonstrates how cybercriminals are turning one…
-
WatchGuard RCE flaw now exploited in ransomware attacks
Tags: attack, cisa, cybersecurity, exploit, firewall, flaw, infrastructure, ransomware, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/
-
Ransomware-Lösegeld sinkt, doch die Folgen bleiben kostspielig
Ransomware-Angriffe werden für deutsche Unternehmen offenbar etwas weniger teuer, wenn es allein um die Höhe der Lösegeldforderungen geht. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ransomware-loesegeld-sinkt
-
FBI Strategy Calls for More Takedowns, Better Info-Sharing
Bureau Won’t ‘Sit and Wait for the Best Opportunity,’ Says FBI’s Leatherman. The FBI vowed Wednesday to crack down on ransomware gangs and online scammers in a first-ever public cybercrime strategy that also said the bureau will prioritize working with victims and work more with private sector partners to take down criminal computer infrastructure. First…
-
Fake GTA6 ‘Leaked Download’ Caught Spreading RATs, Infostealer and Wiper Ransomware
Cybersecurity firm Huntress has uncovered a malware campaign that preys on excitement for Grand Theft Auto VI (GTA6), packaging remote access trojans, an infostealer, and destructive ransomware inside fake >>leaked<< copies of the hotly anticipated game. GTA6 is not due for release for another three months, but a wave of gameplay footage leaks and an…
-
Hackers Create Domain Admin Account and Disable Security Tools Inside Windows Network
A newly documented ransomware intrusion attributed to The Gentlemen shows how attackers can convert a foothold in a Windows environment into domain-wide control by elevating accounts, turning off endpoint defenses, and abusing trusted Active Directory infrastructure to distribute ransomware. The operation illustrates a recurring enterprise risk: attackers do not need highly customized malware to compromise…
-
Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support
A newly identified ransomware-as-a-service operation, Panzer, has surfaced with advertised payload support for Windows, Linux, VMware ESXi and FreeBSD, positioning it as a cross-platform threat to enterprise and virtualized environments. The group’s rapid victim posting cadence, affiliate-focused infrastructure, and double-extortion model make it a ransomware operation security teams should begin tracking despite the current absence…
-
Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support
A newly identified ransomware-as-a-service operation, Panzer, has surfaced with advertised payload support for Windows, Linux, VMware ESXi and FreeBSD, positioning it as a cross-platform threat to enterprise and virtualized environments. The group’s rapid victim posting cadence, affiliate-focused infrastructure, and double-extortion model make it a ransomware operation security teams should begin tracking despite the current absence…
-
Ransomware negotiation tactics have turned into a business process
In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/ransomware-negotiation-tactics-video/
-
Ransomware negotiation tactics have turned into a business process
In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/ransomware-negotiation-tactics-video/
-
Ransomware negotiation tactics have turned into a business process
In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/ransomware-negotiation-tactics-video/
-
Rhysida Publishes Berlin Government Data After Euro2m Extortion Demand Refused
The ransomware group’s published dataset reportedly includes Berlin state employee data, as well as highly sensitive emergency plans First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/rhysida-berlin-data-extortion/
-
Berlin Ransomware Leak Exposes State Secrets
Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out…
-
KI-gesteuerte Ransomware-Operation aufgedeckt
Cybernews hat einen Server entdeckt, auf dem ein Partner der Ransomware-Gruppe The Gentlemen eine nahezu vollständig KI-gesteuerte Erpressungsoperation betrieb. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ki-gesteuerte-ransomware
-
Mehr als Phishing: Bildungseinrichtungen besonders häufig von schwerwiegenden EAngriffen betroffen
Bildungseinrichtungen stehen im E-Mail-Kanal unter außergewöhnlichem Druck: hohes Phishing-Aufkommen trifft auf knappe Ressourcen, begrenzte Incident-Response-Kompetenz und besonders folgenreiche Angriffe. Die Daten zeigen, warum Entscheider Prävention, Erkennung und Wiederherstellung als durchgängigen Prozess steuern müssen. Management Summary Risikolage: 77 Prozent der Bildungseinrichtungen verzeichneten binnen zwölf Monaten einen E-Mail-Sicherheitsvorfall; Ransomware und Kontoübernahmen liegen deutlich über dem Branchenschnitt. Angriffsvolumen:……
-
»Jede Zahlung finanziert den nächsten Angriff«
Ransomware bleibt ein akutes Geschäftsrisiko: 45 Prozent der Unternehmen waren binnen zwölf Monaten betroffen, jedes fünfte Opfer zahlte bereits Lösegeld. Für das Management folgt daraus eine klare Priorität: nicht die Zahlung vorbereiten, sondern Widerstandsfähigkeit, Wiederanlauf und Krisenführung konsequent organisieren. Management Summary Risiko bleibt hoch: 45 Prozent der Unternehmen waren innerhalb eines Jahres Ziel eines… First…
-
New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption
Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS) operation, publishing 16 alleged victims across 11 countries while combining data theft with file encryption. Documented by CyberXtron, its dedicated leak site was first observed active on August 5, 2026, and its early victim list includes organizations in technology, manufacturing, government, agriculture, energy, education, and retail.…
-
New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption
Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS) operation, publishing 16 alleged victims across 11 countries while combining data theft with file encryption. Documented by CyberXtron, its dedicated leak site was first observed active on August 5, 2026, and its early victim list includes organizations in technology, manufacturing, government, agriculture, energy, education, and retail.…
-
Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors
Tags: backdoor, control, cyber, data-breach, group, hacker, infrastructure, malware, ransomware, threat, tool, windowsThe financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications. The development marks a notable evolution for the group, which previously leaned on publicly available tools and leaked ransomware builders before introducing its…
-
Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors
Tags: backdoor, control, cyber, data-breach, group, hacker, infrastructure, malware, ransomware, threat, tool, windowsThe financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications. The development marks a notable evolution for the group, which previously leaned on publicly available tools and leaked ransomware builders before introducing its…
-
SonicWall urges immediate patching of chained vulnerabilities
Just weeks after a wave of ransomware attacks, new flaws in SMA1000 series appliances are being exploited. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/sonicwall-immediate-patching-chained-vulnerabilities/829567/
-
Ransomware Hackers Can Go From Network Access to Encryption in Less Than 24 Hours
Tags: access, breach, business, credentials, cyber, data-breach, encryption, hacker, infrastructure, network, ransomware, service, threatThe Gentlemen ransomware-as-a-service operation can move from confirmed access inside a victim network to encryption in under 24 hours. Demonstrating how rapidly modern affiliates can turn stolen credentials or exposed infrastructure into a full-scale business disruption. Counter Threat Unit researchers tracking the operation as GOLD SHERWOOD found that the Gentlemen affiliates follow a repeatable post-compromise…

