Tag: ransomware
-
Mithilfe alter Sicherheitslücke – Akira-Ransomware greift Sonicwall-Geräte an
First seen on security-insider.de Jump to article: www.security-insider.de/ransomware-akira-sonicwall-firewall-sicherheitsluecke-a-fd3e4dcb10f39e523e9bdb772b67868d/
-
Kampagne mit Ransomware Akira zielt auf Sonicwall-VPNs ab
Ende Juli 2025 hat Arctic Wolf Labs, das Threat-Research-Team von Arctic Wolf, eine Reihe von Angriffen beobachtet, bei denen verdächtige -Aktivitäten aufgetreten sind. Hierbei folgten auf unberechtigte Anmeldungen innerhalb weniger Minuten Port-Scans, Impacket-SMB-Aktivitäten und die schnelle Verbreitung der Akira-Ransomware. Die betroffenen Unternehmen sind aus verschiedenen Branchen und weisen unterschiedliche Größen auf, was auf eine opportunistische Herangehensweise…
-
âš¡ Weekly Recap: Cisco 0-Day, Record DDoS, LockBit 5.0, BMC Bugs, ShadowV2 Botnet & More
Cybersecurity never stops”, and neither do hackers. While you wrapped up last week, new attacks were already underway.From hidden software bugs to massive DDoS attacks and new ransomware tricks, this week’s roundup gives you the biggest security moves to know. Whether you’re protecting key systems or locking down cloud apps, these are the updates you…
-
Cybercriminals Target SonicWall Firewalls to Deploy Akira Ransomware via Malicious Login Attempts
Security teams face a rapidly evolving campaign that abuses compromised SonicWall SSL VPN credentials to deliver Akira ransomware in under four hours”, dwell times among the shortest ever recorded for this type of threat. Within minutes of successful authentication”, often originating from hosting-related ASNs”, threat actors initiated port scans, leveraged Impacket SMB tools for discovery,…
-
Cybercriminals Target SonicWall Firewalls to Deploy Akira Ransomware via Malicious Login Attempts
Security teams face a rapidly evolving campaign that abuses compromised SonicWall SSL VPN credentials to deliver Akira ransomware in under four hours”, dwell times among the shortest ever recorded for this type of threat. Within minutes of successful authentication”, often originating from hosting-related ASNs”, threat actors initiated port scans, leveraged Impacket SMB tools for discovery,…
-
Akira Ransomware bypasses MFA on SonicWall VPNs
Akira ransomware is targeting SonicWall SSL VPNs, bypassing OTP MFA on accounts, likely using stolen OTP seeds. Since July 2025, Akira ransomware has exploited SonicWall SSL VPNs, likely using credentials obtained from the exploitation of the CVE-2024-40766 vulnerability, bypassing OTP MFA. Attacks spread quickly across sectors, with rapid post-login activity and short dwell times, making…
-
SonicWall SSL VPN Attacks Escalate, Bypassing MFA
Akira ransomware attacks on SonicWall SSL VPN appliances are bypassing its MFA for rapid deployment First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/sonicwall-ssl-vpn-attacks-escalate/
-
Lockbit 5.0: Neue Ransomware-Variante für Windows und Linux im Umlauf
Die Cybererpresser verbessern die Verschleierung ihrer Malware und Erschweren die Wiederherstellung verschlüsselter Dateien. First seen on golem.de Jump to article: www.golem.de/news/lockbit-5-0-neue-ransomware-variante-fuer-windows-und-linux-im-umlauf-2509-200598.html
-
Akira hackt SonicWall VPN-Konten (auch mit MFA-Absicherung)
Falls jemand SonicWall VPN als Zugang zu seinen IT-Netzwerken verwendet, aufgepasst. Es gibt Berichte, dass die Ransomware-Gruppe Akira SonicWall VPN-Konten angreift. Und die Gruppe ist wohl in der Lage, auch Konten zu knacken, die per Multifaktor-Authentifizierung (MFA) gesichert sind, wenn … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/09/29/akira-hackt-sonicwall-vpn-konten-auch-mit-mfa-absicherung/
-
Medusa Ransomware Claims Comcast Data Breach, Demands $1.2M
Medusa ransomware group claims 834 GB data theft from Comcast, demanding $1.2M ransom while sharing screenshots and file listings. First seen on hackread.com Jump to article: hackread.com/medusa-ransomware-comcast-data-breach/
-
Akira ransomware breaching MFA-protected SonicWall VPN accounts
Ongoing Akira ransomware attacks targeting SonicWall SSL VPN devices continue to evolve, with the threat actors found to be successfully authenticating despite OTP MFA being enabled on accounts. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/akira-ransomware-breaching-mfa-protected-sonicwall-vpn-accounts/
-
Security Affairs newsletter Round 543 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Ohio’s Union County suffers ransomware attack impacting 45,000 people ForcedLeak flaw in Salesforce Agentforce exposes CRM…
-
Ohio’s Union County suffers ransomware attack impacting 45,000 people
A ransomware attack resulted in the theft of Social Security and financial data from Union County, Ohio, impacting 45,487 people. A ransomware attack hit Union County, Ohio, and crooks stole Social Security and financial data. Officials notified 45,487 residents and staff after the security breach that occurred on May 18, 2025. After discovering the security…
-
Meet LockBit 5.0: Faster ESXi drive encryption, better at evading detection
the Windows binary uses heavy obfuscation and packing: it loads its payload through DLL reflection while implementing anti-analysis techniques like Event Tracing for Windows (ETW) patching and terminating security services;the Linux variant maintains similar functionality with command-line options for targeting specific directories and file types;the ESXi variant specifically targets VMware virtualization environments, and is designed…
-
Volvo Employee SSNs Stolen in Supplier Ransomware Attack
Three international vehicle manufacturers have fallen to supply chain cyberattacks in the past month alone. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/volvo-employee-ssns-stolen-ransomware-attack
-
Ransomware attack on Ohio county impacts over 45,000 residents, employees
The hackers stole documents that had names, Social Security numbers, driver’s license numbers, financial account information, fingerprint data, medical information, passport numbers and more. First seen on therecord.media Jump to article: therecord.media/ohio-ransomware-attack-impacts-45000
-
Cybersecurity Snapshot: CISA Highlights Vulnerability Management Importance in Breach Analysis, as Orgs Are Urged To Patch Cisco Zero-Days
Tags: 2fa, access, advisory, api, attack, authentication, breach, business, cisa, cisco, cloud, control, credentials, crime, cve, cyber, cybersecurity, data, defense, endpoint, exploit, fido, finance, firewall, framework, github, grc, guide, identity, incident response, infrastructure, Internet, ISO-27001, kev, law, lessons-learned, malicious, malware, mfa, mitigation, monitoring, network, open-source, phishing, privacy, ransomware, risk, saas, scam, security-incident, service, soc, software, supply-chain, tactics, threat, update, vpn, vulnerability, vulnerability-management, worm, zero-dayCISA’s takeaways of an agency hack include a call for timely vulnerability patching. Plus, Cisco zero-day bugs are under attack, patch now. Meanwhile, the CSA issued a framework for SaaS security. And get the latest on the npm breach, the ransomware attack that disrupted air travel and more! Here are six things you need to…
-
RTX confirms hack of passenger boarding software involved ransomware
The parent company of Collins Aerospace said the attack is not expected to have a material impact on financial results, according to an SEC filing. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/rtx-hack-passenger-boarding-software-ransomware/761265/
-
2025 Ransomware Trends: How Australia’s Wealth Makes It a Prime Target
Australia’s strong economy and high per-capita wealth have made it a prime target for ransomware groups, with the country facing a disproportionate number of attacks compared to many other nations. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/australia-ransomware-threats-surge/
-
2025 Ransomware Trends: How Australia’s Wealth Makes It a Prime Target
Australia’s strong economy and high per-capita wealth have made it a prime target for ransomware groups, with the country facing a disproportionate number of attacks compared to many other nations. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/australia-ransomware-threats-surge/
-
Volvo North America confirms staff data stolen following ransomware attack on IT supplier
The downstream consequences of Miljödata’s ransomware attack continue to affect major organizations First seen on theregister.com Jump to article: www.theregister.com/2025/09/26/volvo_north_america_confirms_staff/
-
Volvo North America confirms staff data stolen following ransomware attack on IT supplier
The downstream consequences of Miljödata’s ransomware attack continue to affect major organizations First seen on theregister.com Jump to article: www.theregister.com/2025/09/26/volvo_north_america_confirms_staff/
-
KI-gestützte Cyberresilienz-Funktionen für Backup mit Ransomware-Schutz
Arcserve gibt die Vorschau seiner neuen KI-gestützten Cyberresilienz-Funktionen für bestehende Arcserve-UDP-Kunden bekannt. Die KI-Funktionen wurden für IT-Experten im Mid-Market und im KMU-Bereich entwickelt, um Organisationen gegen Ransomware-Angriffe zu schützen. Nahtlos in die Arcserve-Unified-Data-Protection (UDP)-Plattform integriert, fügen sich die KI-gestützten Funktionen in bestehende Backup-Umgebungen ein und bieten eine proaktive Bedrohungsabwehr, operative Effizienz und zukunftssichere Sicherheit. Eine…
-
KI-gestützte Cyberresilienz-Funktionen für Backup mit Ransomware-Schutz
Arcserve gibt die Vorschau seiner neuen KI-gestützten Cyberresilienz-Funktionen für bestehende Arcserve-UDP-Kunden bekannt. Die KI-Funktionen wurden für IT-Experten im Mid-Market und im KMU-Bereich entwickelt, um Organisationen gegen Ransomware-Angriffe zu schützen. Nahtlos in die Arcserve-Unified-Data-Protection (UDP)-Plattform integriert, fügen sich die KI-gestützten Funktionen in bestehende Backup-Umgebungen ein und bieten eine proaktive Bedrohungsabwehr, operative Effizienz und zukunftssichere Sicherheit. Eine…
-
Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure
Cybersecurity company watchTowr Labs has disclosed that it has “credible evidence” of active exploitation of the recently disclosed security flaw in Fortra GoAnywhere Managed File Transfer (MFT) software as early as September 10, 2025, a whole week before it was publicly disclosed.”This is not ‘just’ a CVSS 10.0 flaw in a solution long favored by…
-
Cyberangriffe: Thermofin (Sarcoma) und ZEF der Uni Bonn
Kurze Informationen in Sachen Cyberangriffe und Ransomware. Das Unternehmen Thermofin ist Opfer einer Sarcoma Ransomware-Infektion geworden (am 23.9.2025 bekannt geworden). Zudem ist mir die Information zugegangen, dass es am ZEF der Uni Bonn einen “Sicherheitsvorfall” gegeben hat. Hier einige Kurzinformation, … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/09/26/cyberangriffe-thermofin-sarcoma-und-zef-der-uni-bonn/
-
Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure
Cybersecurity company watchTowr Labs has disclosed that it has “credible evidence” of active exploitation of the recently disclosed security flaw in Fortra GoAnywhere Managed File Transfer (MFT) software as early as September 10, 2025, a whole week before it was publicly disclosed.”This is not ‘just’ a CVSS 10.0 flaw in a solution long favored by…
-
New LockBit Ransomware Variant Emerges as Most Dangerous Yet
Trend Micro highlighted the new LockBit version’s improved technical improvements and cross-platform functionality compared to previous iterations First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/lockbit-ransomware-most-dangerous/
-
New LockBit Ransomware Variant Emerges as Most Dangerous Yet
Trend Micro highlighted the new LockBit version’s improved technical improvements and cross-platform functionality compared to previous iterations First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/lockbit-ransomware-most-dangerous/
-
Ransomware trifft Systeme und Menschen
Viele Mitarbeitende aus Security-Teams berichten von mehr Druck und Burnout nach einem Ransomware-Angriff. Erfahren Sie, welche Auswirkungen Ransomware sowohl auf technische Systeme als auch auf Mitarbeitende hat und wie Sophos MDR helfen und IT-Teams entlasten kann. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/ransomware-trifft-systeme-und-menschen/a42150/

