Tag: ransomware
-
CISA confirms 2025 Windows Task Host flaw exploited by ransomware groups
First seen on scworld.com Jump to article: www.scworld.com/news/cisa-confirms-2025-windows-task-host-flaw-exploited-by-ransomware-groups
-
More than 200 victims of Medusa ransomware identified over the last year, CISA says
The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025, writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025. First seen on…
-
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups’ servers in exchange for a fee ranging from $20,000 to $60,000.”In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous,”…
-
Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
The updated warning from the FBI, CISA and HHS draws on a year’s worth of investigations to detail how the group gains initial access and what it does afterward. First seen on cyberscoop.com Jump to article: cyberscoop.com/medusa-ransomware-tactics-cisa-advisory/
-
Clop created custom web shell for Windchill data theft attacks
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/clop-created-custom-web-shell-for-windchill-data-theft-attacks/
-
Ransomware-Angriff – Cyberattacke legt IT von sieben Gedenkstätten in Brandenburg lahm
First seen on security-insider.de Jump to article: www.security-insider.de/ransomware-angriff-stiftung-brandenburgische-gedenkstaetten-a-86361274d190742c8d6edc4ffb6d1309/
-
Law Firms Increasingly Targeted By Ransomware/Vishing Attacks
Law firms face growing ransomware and data-theft threats as attackers target privileged client information, exposing firms to cybersecurity, ethical and legal risks. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/law-firms-increasingly-targeted-by-ransomware-vishing-attacks/
-
‘Ransom Busters’: Ransomware Actor Poses as Incident-Recovery Service
A ransomware affiliate appears to be sidling up to victims with offers of aid, masking its true intention of diverting ransom payments. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ransom-busters-ransomware-actor-incident-recovery-service
-
Windows Task Host flaw now exploited by ransomware gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/
-
Ukrainian software developer faces 12 years in Swiss ransomware trial
The unnamed 52-year-old is accused of attacking Swiss train manufacturer Stadler Rail alongside other enterprises as part of an international ransomware operation. First seen on therecord.media Jump to article: therecord.media/ukrainian-software-developer-court-switzerland
-
Three-quarters of Ransomware Attacks Target Mid-Market Firms
Black Kite finds mid-market is the sweet spot for ransomware as manufacturers are most likely to be hit First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/threequarters-ransomware-attacks/
-
C2Looper v2 Uses GitHub Repositories as Full CommandControl Infrastructure.
C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces conventional command-and-control infrastructure with GitHub repositories used to deliver tasks, receive results, maintain beacon records, and host payloads. ThreatLabz identified the malware in July 2026 and assesses, with low-to-medium confidence, that it is delivered through…
-
Hackers Turn Claude Code and Codex Into AI-Powered Tools for Credential Theft and Cloud Attacks
Threat actors are increasingly using coding assistants as operational tools. Detailed research from Gambit Security highlights three campaigns where Claude Code, OpenAI Codex, and large language models facilitated activities ranging from ransomware preparation to the harvesting of secrets on a large scale and exploiting cloud accounts. These cases demonstrate how AI can speed up attackers’…

