Tag: ransomware
-
Ransomware Hackers Can Go From Network Access to Encryption in Less Than 24 Hours
Tags: access, breach, business, credentials, cyber, data-breach, encryption, hacker, infrastructure, network, ransomware, service, threatThe Gentlemen ransomware-as-a-service operation can move from confirmed access inside a victim network to encryption in under 24 hours. Demonstrating how rapidly modern affiliates can turn stolen credentials or exposed infrastructure into a full-scale business disruption. Counter Threat Unit researchers tracking the operation as GOLD SHERWOOD found that the Gentlemen affiliates follow a repeatable post-compromise…
-
Threat Intelligence: Definition, Benefits, and Use Cases
Security teams rarely struggle because they lack data. More often, the challenge is deciding which signals actually deserve attention. Modern security environments generate information about suspicious IP addresses, malicious domains, malware samples, phishing infrastructure, ransomware activity, attacker behavior, and thousands of other indicators. Without context, that volume can quickly become another source of noise. Threat…
-
Berlin Rejects Rhysida Ransomware Blackmail
Extortion Group With Suspected Russian Provenance Imposes Friday Deadline. Berlin officials temporarily canceled remote work and are scouring all their systems, after the notorious Rhysida ransomware gang attacked the German city-state in a double-extortion attempt that will come to some kind of conclusion this Friday. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/berlin-rejects-rhysida-ransomware-blackmail-a-32731
-
New pro-Ukraine hacker group targets Russian companies with custom ransomware
The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week. First seen on therecord.media Jump to article: therecord.media/new-pro-ukraine-hacker-group-custom-ransomware-russia
-
Ransomware protection for MSPs: A 6-point checklist for faster recovery
Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/ransomware-protection-for-msps-a-6-point-checklist-for-faster-recovery/
-
AI-basierte Security-Operations-Center erkennen Ransomware nicht von selbst
Wie viele Analysten braucht das SOC-Team noch angesichts des Einzugs von künstlicher Intelligenz? Die Frage suggeriert die Antwort: Das AI-basierte Security-Operations-Center erfordert weniger Menschen. Leider sind die Unternehmen, die diese Frage stellen, meist genau diejenigen, die ihre Telemetrielücken, ihre ungesicherten Endgeräte oder ihre unzureichende MFA-Abdeckung noch nicht angegangen sind. Sie stellen sich vor, dass künstliche…
-
The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security
Tags: breach, control, credentials, cyber, edr, framework, group, hacker, healthcare, ransomware, technologyThe Gentlemen ransomware operation has been linked to a previously undocumented, cross-platform command-and-control framework named TukTuk, alongside EDR-disabling tooling, DLL sideloading research, and datasets apparently stolen from technology and healthcare organizations. Analysis of a Finland-hosted server identified what researchers assess as the complete TukTuk development project, providing an unusually detailed view into the group’s post-compromise capabilities.…
-
Stronger Security Drives Ransomware Groups to Recruit From Within
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/stronger-security-drives-ransomware-groups-to-recruit-from-within
-
From a Stolen Login to a Ransomware Leak Site: What Our Telemetry Shows About the Path Threat Actors Take
A ransomware disclosure and a credential package we track from an entirely separate source, read side by side, illustrate a pattern our research team sees again and again: the quiet theft of a single login can be the first domino… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/from-a-stolen-login-to-a-ransomware-leak-site-what-our-telemetry-shows-about-the-path-threat-actors-take/
-
Berlin confirms data theft after Rhysida ransomware attack claims
Berlin’s city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/berlin-confirms-data-theft-after-rhysida-ransomware-attack-claims/
-
Aurora Ransomware Hackers Use Cursor AI Agent for Hands-On Exploitation and ESXi Attacks
Aurora ransomware operators have been observed using Cursor Agent, powered by Claude Sonnet, to support hands-on intrusion activity across ten victim organizations, while deploying a purpose-built Linux encryptor designed to disrupt VMware ESXi environments. The findings show how ransomware affiliates are integrating agentic AI into established post-compromise workflows rather than relying on it as a…
-
85 Prozent der identitätsbasierten Ransomware-Angriffe treffen den Bildungssektor
Sophos hat seinen jährlichen Report ‘State of Ransomware in Education 2026>> veröffentlicht. Demnach kamen bei 85 Prozent der Ransomware-Angriffe auf Bildungseinrichtungen identitätsbasierte Angriffstechniken zum Einsatz. Dazu zählen schädliche E-Mails, Phishing, kompromittierte Zugangsdaten und Brute-Force-Angriffe. Mit 85 Prozent lag die Quote über dem branchenübergreifenden Durchschnitt von 79 Prozent und unterstreicht, welche Rolle die Kompromittierung von Identitäten…
-
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Tags: ai, attack, cybercrime, data-breach, group, infrastructure, intelligence, network, ransomware, russia, threatThreat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX’s artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security.The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its First seen on…
-
Rhysida: Ransomware-Gruppe will 2 Millionen in Bitcoin von Berliner Landes-IT
Die Ransomware-Gruppe Rhysida steht offenbar hinter dem Angriff auf die Berliner Landes-IT. Sie haben mehr Daten als bisher eingeräumt. First seen on golem.de Jump to article: www.golem.de/news/rhysida-ransomware-gruppe-will-2-millionen-in-bitcoin-von-berliner-landes-it-2608-212414.html
-
Ehemaliger Medusa-Partner setzt auf neue Ransomware StormEncryptor
Microsoft entdeckte die neue Ransomware StormEncryptor, eingesetzt von der mutmaßlich chinesischen Gruppe Storm-1175, die zuvor auf Medusa setzte. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ransomware-stormencryptor
-
Identity-Based Attacks Drive 85% of Education Ransomware, Sophos Finds
Identity-based cyberattacks accounted for 85% of ransomware attacks experienced by education organizations over the past year, according to a new Sophos survey. The findings show ransomware attackers turning more often to identity abuse for initial access. The State of Ransomware in Education 2026 report draws on responses from 226 IT and cybersecurity leaders at lower..…
-
Cursor: Hacker bei Cyberangriffen mittels KI-Agenten erwischt
Eine russischsprachige Hackergruppe nutzt offenbar Cursor-Agenten für Ransomware-Attacken. Auch ein deutsches Unternehmen soll betroffen sein. First seen on golem.de Jump to article: www.golem.de/news/cursor-hacker-bei-cyberangriffen-mittels-ki-agenten-erwischt-2608-212390.html
-
TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation
A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify stolen corporate data, identify regulatory risk. Founded on April 4, 2026, TITAN has been active since May and has listed 24 alleged victims across 10 countries. Italy accounts for 10 published victims, followed by Czechia with…
-
Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations
Aurora ransomware operators are abusing SpaceX’s Cursor Agent AI tool to conduct tasks such as reconnaissance and exploitation activities First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/abuse-cursor-agent-ransomware/
-
ATF declares ‘major incident’ as ransomware gang claims hack
The ATF is the latest federal government agency in recent years to notify Congress of a “major incident” involving its cybersecurity. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/27/atf-declares-major-incident-as-ransomware-gang-claims-hack/
-
DOJ firearms agency says hackers breached system containing investigation targets
The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed it experienced a cyberattack on a system containing investigation information, as a prolific ransomware gang claimed to have carried out the breach. First seen on therecord.media Jump to article: therecord.media/doj-atf-cyberattack-qilin-ransomware
-
Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations
A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine countries between April and July 2026, using the AI coding assistant Cursor to plan intrusion activity and Active Directory escalation. The exposed server offered an unusually complete view of a ransomware affiliate’s operational workflow. It contained victim-specific directories, shell history,…
-
Ransomware attack volumes hit ‘high-water mark’ in July
The number of ransomware attacks hit the highest level seen so far this year in July, according to a report First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649779/Ransomware-attack-volumes-hit-high-water-mark-in-July
-
ATF confirms “major incident” after recent Qilin breach claims
ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/atf-confirms-major-incident-after-recent-qilin-breach-claims/
-
Ransomware attack volumes hit ‘high-water-mark’ in July
The number of ransomware attacks hit the highest level seen so far this year in July, according to a report. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649779/Ransomware-attack-volumes-hit-high-water-mark-in-July
-
Ransomware attack volumes hit ‘high-water-mark’ in July
The number of ransomware attacks hit the highest level seen so far this year in July, according to a report. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366649779/Ransomware-attack-volumes-hit-high-water-mark-in-July
-
Ransomware surges as criminals deploy AI tools
Research from NCC Group and a partnership between Axis Communications and Palo Alton underline how artificial intelligence is impacting customers First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366649752/Ransomware-surges-as-criminals-deploy-AI-tools
-
SafePay wird zur aktivsten Ransomware-Gruppe in Deutschland – 107 Ransomware-Opfer bringen Deutschland auf Rekordniveau
First seen on security-insider.de Jump to article: www.security-insider.de/ransomware-deutschland-juni-juli-2026-safepay-a-1cb7656e412eea893c5f8d931b2f5394/
-
The cybercrime supply chain has five stages, each with a price
In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/25/cybercrime-supply-chain-video/
-
AnMed Confirms Data Theft, Warns Patients of Criminal Scams
Ransomware Gang Gentlemen Says It Stole 6TB of Sensitive Patient Info. Nonprofit health system AnMed has confirmed cybercriminals stole information in a July cyberattack that disrupted its IT environment and patient services for several weeks. The organization is also warning patients not to fall for potential fraud, payment and other scams by criminals. First seen…

