Tag: ransomware
-
Tricky ‘SynkLoader’ Multitool May Herald Ransomware
An advanced, multilingual malware family brings back a trick from yesteryear, screen hijacking, for effective password theft, along with a slew of novel features. First seen on darkreading.com Jump to article: www.darkreading.com/threat-intelligence/tricky-synkloader-multitool-ransomware
-
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups.According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) First seen…
-
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups.According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) First seen…
-
Wenn Patch-Zyklen zu langsam werden: Rapid7 fordert risikobasiertes Exposure Management
Rapid7 zeigt im Q2 Threat Report 2026: 62 Prozent neuer Exploits benötigen keine Nutzerinteraktion. Deutschland liegt bei Ransomware weltweit auf Platz zwei. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/wenn-patch-zyklen-zu-langsam-werden-rapid7-fordert-risikobasiertes-exposure-management/a46232/
-
Gunra ransomware: what you need to know
The ransomware gang Gunra has been creating havoc – exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. First seen on fortra.com Jump to article: www.fortra.com/blog/gunra-ransomware-what-you-need-know
-
Ransomware attackers are zeroing in on mid-market companies
Mid-sized companies accounted for 73% of publicly disclosed ransomware and data-extortion incidents with known revenue in North America and Europe between January 2023 and … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/24/black-kite-mid-market-ransomware-risk-report/
-
Cybersecurity Newsletter Bulletin Top 50 Biggest Cybersecurity Stories of the Week Shell Azure Mega-Breaches, Salt Typhoon Evicted, Entra ID RCE, Chinese vCenter ESXi Ransomware More
Tags: breach, china, cisa, credentials, cyber, cybersecurity, exploit, flaw, mobile, ransomware, rce, remote-code-execution, theft, vcenterWelcome to this week’s edition of the GBHackers cybersecurity newsletter, your weekly cybersecurity bulletin covering the 50 most important stories from August 1721, 2026. Breaches and exploited flaws dominated: Cl0p claimed 89GB from Shell, a mass Azure credential-theft campaign hit McDonald’s and Vodafone, and T-Mobile physically cut a cable to evict Salt Typhoon. CISA […]…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 111
Tags: banking, botnet, edr, infrastructure, international, linux, malware, ransomware, spyware, windowsSecurity Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Akira Hits Safe Mode: Ransomware Rebooting Around EDR Multi-Functional Linux Botnet “Evooo1Bot” StubMaker RubyGems Campaign Delivers a Windows Infostealer Hunting MacSync Stealer infrastructure through behavioral pivots Manic: Blend between Banking Malware & Spyware […]…
-
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/23/week-in-review-records-allegedly-stolen-from-azure-tenants-medusa-ransomware-hits-500-orgs/
-
US Bank investigates LockBit ransomware claims of data breach
First seen on scworld.com Jump to article: www.scworld.com/brief/us-bank-investigates-lockbit-ransomware-claims-of-data-breach
-
Who Is REvil’s Ransomware Developer Anatoly Sergeevitsch Kravchuk?
Dear blog readers. This is Dancho. A reader recently approached me with a detailed research and analysis for Quake3 a XSS forum moderator where he connected the dots that Quake3 is also the main developer of the REvil ransomware where he asked me to go ahead and publish it. So who’s Anatoly Sergeevitsch Kravchuk? Dark…
-
Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen
The Hospital for Sick Children, which was hit in a ransomware incident in 2022 that disabled some of its systems, released a statement on Thursday warning of a data theft incident they believe is tied to a third-party software application. First seen on therecord.media Jump to article: therecord.media/canada-hospital-for-sick-children-attacked-again-employee-data
-
US Bank Investigates Alleged Data Breach After LockBit Ransomware Extortion Claim
US Bank is currently investigating claims made by the LockBit ransomware group, which alleges that it breached the bank and stole sensitive data. The group has set a deadline of September 3 for the bank to meet an undisclosed extortion demand. As of now, the details of the alleged attack have not been independently verified,…
-
Ransomware-Partner gibt sich als Wiederherstellungsfirma aus
Ein mutmaßlicher Ransomware-Partner gibt sich unter dem Namen Ransom Busters als eigenständige Wiederherstellungsfirma aus. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ransomware-partner
-
Vermuteter Ransomware-Partner gibt sich als Wiederherstellungsfirma aus
Ein mutmaßlicher Ransomware-Partner gibt sich unter dem Namen Ransom Busters als eigenständige Wiederherstellungsfirma aus. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ransomware-partner
-
Medusa Ransomware Hits 500-Plus Victims as Agencies Warn of Rapid Exploitation
Federal agencies warn that Medusa ransomware has hit more than 500 victims and can exploit newly disclosed vulnerabilities within 24 hours of release. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-medusa-ransomware-500-victims-rapid-exploitation/
-
Breach Roundup: Grandoreiro Returns
Also, French Tax Agency Breach and Accused Ransomware Developer in Swiss Court. This week: Grandoreiro returns, Swiss prosecutors sought a 12-year sentence for ransomware developer, a Medusa ransomware warning, Ransom Busters demanded up to $60,000 from victims, French tax agency disclosed a breach, a Fuxa vulnerability, Stripe vendors exposed in 33 gigabytes data leak. First…
-
Medusa ransomware group attacked more than 500 victims since 2021
First seen on scworld.com Jump to article: www.scworld.com/news/medusa-ransomware-group-attacked-more-than-500-victims-since-2021
-
Rogue ransomware affiliate poses as recovery firm to steal payments
A suspected ransomware affiliate is posing as a ransomware recovery service called “Ransom Busters,” contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/
-
Rogue ransomware affiliate poses as data recovery firm to steal payments
A suspected ransomware affiliate is posing as a ransomware recovery service called “Ransom Busters,” contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-data-recovery-firm/
-
Rising Number of Cyberattacks Have AI-Assisted Fingerprints
Claude Code Especially Tied to Semi-Automated Intrusions, Data Theft, Ransomware. Attackers’ operational security fails reveal they’re increasingly wielding artificial intelligence tools in semi-autonomous ways to help them conduct reconnaissance and perpetrate ransomware infections and data exfiltration at greater speed and scale than ever before – albeit with mixed results. First seen on govinfosecurity.com Jump to…
-
Ransomware disproportionately targets medium-sized firms, straining customer relationships
These companies often have the hardest time balancing their roles as suppliers and customers, according to the risk management firm Black Kite. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ransomware-mid-market-firms-black-kite/828257/
-
Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware
The FBI warned that the RaaS operation has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counter First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/critical-infrastructure-medusa/
-
Medusa ransomware gang has hit over 500 organizations, CISA warns
Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/19/medusa-ransomware-cisa-warning/
-
Ransom Busters Ransomware Affiliate Targets Victims With Fake Data Recovery Extortion
A threat actor calling itself “Ransom Busters” is targeting ransomware victims with a deceptive recovery offer, claiming it can restore encrypted files and delete stolen data from ransomware infrastructure. GuidePoint Security’s Research and Intelligence Team (GRIT) assesses with moderate confidence that the purported recovery service is actually a ransomware affiliate attempting to divert extortion payments…
-
Medusa ransomware hit over 500 critical infrastructure orgs
The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-500-critical-infrastructure-orgs/
-
Cl0p Hackers Exploit PTC Windchill Vulnerability to Deploy Custom Web Shell and Steal Data
Tags: credentials, cve, cvss, cyber, data, exploit, extortion, hacker, ransomware, remote-code-execution, vulnerabilityThe Cl0p ransomware and extortion operation is likely exploiting a critical PTC Windchill vulnerability to deploy a purpose-built Java web shell that can harvest credentials, map engineering data vaults, and exfiltrate files without requiring additional attacker tooling. Tracked as CVE-2026-12569, the vulnerability is a CVSS 9.3 remote code execution issue affecting PTC Windchill PDMlink and…
-
Medusa Ransomware Attacks 300+ Critical Infrastructure Organizations Using Double Extortion
Tags: advisory, attack, cisa, cyber, extortion, infrastructure, intelligence, ransomware, service, updateMedusa ransomware operators have compromised over 500 organizations across critical infrastructure sectors, according to a joint advisory issued by the FBI, CISA, and the U.S. Department of Health and Human Services (HHS) as part of their #StopRansomware initiative. An update released on August 18, 2026, provides expanded intelligence based on FBI investigations conducted as recently…
-
Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix
A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files, harvest credentials, and remotely monitor victims through deceptive ClickFix CAPTCHA prompts. Researchers first identified the campaign in mid-May 2026. They discovered that the operation utilizes a broad range of criminal tools rather than relying on a single…
-
Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix
A large-scale malware operation called StopAndProtect is exploiting thousands of compromised WordPress websites to distribute ransomware, steal files, harvest credentials, and remotely monitor victims through deceptive ClickFix CAPTCHA prompts. Researchers first identified the campaign in mid-May 2026. They discovered that the operation utilizes a broad range of criminal tools rather than relying on a single…

