Tag: ransomware
-
North Korea’s APT Capabilities Are No Longer State-Exclusive
Tags: access, apt, cyber, finance, group, hacker, infrastructure, korea, lazarus, malware, military, north-korea, ransomware, skillsAhnLab Found Shared Malware, SSH Keys and Infrastructure Across Two Campaigns. Shared malware, infrastructure and access methods link Lazarus Group to Gunra ransomware activity, while former North Korean military hackers allegedly used state-trained skills to steal bank funds, exposing cyber capability diffusion and blowback inside the regime. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/north-koreas-apt-capabilities-are-no-longer-state-exclusive-a-32392
-
DentaQuest Data Theft Hack Affects 15M Patients
Number of Victims Is 5 Times Higher Than Claims by ShinyHunters Ransomware Gang. Dental and vision benefits administrator DentaQuest is notifying 15 million patients that their information was compromised in a May hack. The reported victim total is significantly higher than the number claimed by extortion gang ShinyHunters, which took credit for the data theft…
-
eSecurityPlanet Podcast: Semperis Global Field CTO Marty Momdjian
Identity systems sit at the center of enterprise security, but they are also one of the first places attackers look when launching ransomware and other disruptive cyberattacks. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/video/esecurityplanet-podcast-semperis-global-field-cto-marty-momdjian/
-
ESET tracks rise in malicious AI skills and adaptable malware
Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET’s new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/eset-tracks-rise-in-malicious-ai-skills-and-adaptable-malware/
-
Ransomware Killers Overwrite Security Process Memory Without Terminating Applications
Ransomware operators are increasingly deploying “ransomware killers” that surgically overwrite the memory of security processes instead of simply terminating them, allowing encryption to proceed. At the same time, endpoint tools appear to run normally but are effectively blind. This evolution marks a shift from crude process-killing to stealthy, in”‘memory tampering that targets EDR/AV telemetry, kernel…
-
Phishing 2026: Warum technische Abwehr nicht mehr reicht
Das größte Einfallstor der Angreifer bleibt Phishing. Der Lagebericht des BSI zur IT-Sicherheit in Deutschland führt seit vielen Jahren Phishing als eines der häufigsten Einfallstore für Ransomware und Datenabfluss an. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/phishing-2026-abwehr
-
Vishing-Kampagne über Microsoft Teams mündet in Chaos-Ransomware
Angreifer geben sich über Microsoft Teams als IT-Support aus, um sich Fernzugriff auf Firmengeräte zu verschaffen. Darauf folgte der Einsatz der Ransomware Chaos. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/microsoft-teams-chaos
-
The Recovery Illusion
When a cyber threat hits the headlines, the instinct is always the same. Organizations like to spend more, add another tool, and tighten the audit schedule so the box stays checked. But when ransomware hits a company that did all of that, the result usually still looks like chaos. Teams scramble and find out the..…
-
Flailing Ransomware Hackers Resorting to Extreme Tactics
Silent Ransom Bucks Trend of Fewer Victims Paying, and Paying Less When They Do. Fewer ransomware victims are choosing to pay a ransom than ever before, bar some big payoffs that largely trace to high-profile law firms that got hit by a group called Silent Ransom, which the FBI says has a penchant for infiltrating…
-
Coca-Cola Confirms Data Theft as Fairlife Ransomware Attack Escalates
Coca-Cola has confirmed data was stolen in the ransomware attack on Fairlife after the Anubis gang published allegedly stolen files, escalating the incident. The post Coca-Cola Confirms Data Theft as Fairlife Ransomware Attack Escalates appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-coca-cola-confirms-data-theft-fairlife-ransomware/
-
Tanaka Dominates Data Leak Landscape With 25 Leak Posts
Ransomware often dominates cybersecurity headlines, but stolen data has become an equally valuable commodity in the cybercrime economy. In the first half of 2026, one threat actor stood out in the data leak ecosystem: Tanaka, a prolific data leak broker responsible for more publicized leak activity than any other actor tracked by Cyble. First seen…
-
Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections
Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations First seen on hackread.com Jump to article: hackread.com/fake-it-calls-microsoft-teams-gogrpc-backdoor/
-
Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
Coca Cola claims data was stolen from its Fairlife business after a recent ransomware attack First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/coca-cola-subsidiary-fairlife-data/
-
Coca-Cola confirms hackers stole data in Fairlife ransomware attack
Coca-Cola has confirmed that the ransomware attack on its dairy subsidiary Fairlife involved the theft of company data, weeks after the incident temporarily halted production … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/28/coca-cola-fairlife-dairy-subsidiary-ransomware-attack/
-
Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy GoGRPC Backdoor
An evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed “GoGRPC.” Active since January 2026, the activity is assessed to be linked to an initial access broker (IAB) operation that likely facilitates downstream ransomware attacks. Aligning with tactics observed…
-
FBI: Breaking Affiliate Trust Sped Along LockBit’s Takedown
An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/fbi-breaking-affiliate-trust-lockbit-takedown
-
Malware Attack Forces AnMed to Close Care Facilities
Nonprofit Health System in SC and Georgia Says Email, Phones and Portal Are Down. AnMed, a nonprofit healthcare system that serves upstate South Carolina and Northeast Georgia, has temporarily closed dozens of its medical offices and other care facilities as the organization responds to a weekend ransomware attack. Email, phones and patient portals are among…
-
Bank of Baroda Breach Tests Disclosure Readiness
Email Compromise Exposes Sensitive Data, Raising DPDP Act Compliance Questions. A Bank of Baroda employee email compromise exposed customer and internal data allegedly leaked by the Triple X ransomware group. The incident shows how India’s new DPDP Act breach notification rules test banks’ readiness to disclose cyber incidents quickly and transparently. First seen on govinfosecurity.com…
-
Coca-Cola restores most production capacity at dairy unit after ransomware attack
The company said it does not expect the Fairlife disruption to have a material impact on financial performance or operations.; First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/coca-cola-restores-most-production-capacity-at-dairy-unit-after-ransomware/826250/
-
27th July Threat Intelligence Report
Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping operations and affected approximately 5,000 customers. KFC Japan warned of possible shortages. Nichirei confirmed personal data theft, […] First seen on research.checkpoint.com Jump to article: research.checkpoint.com/2026/27th-july-threat-intelligence-report/
-
Coca-Cola confirms data theft in Fairlife ransomware attack
The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/coca-cola-confirms-data-theft-in-fairlife-ransomware-attack/
-
Ransomware, die erst Wochen nach dem Phishing zuschlägt
Ransomware und Phishing waren schon immer miteinander verbunden, doch das alte Modell war recht plump. Eine Phishing-E-Mail enthielt die Schadlast, der Empfänger öffnete sie, und innerhalb weniger Stunden erfolgte die Verschlüsselung. Wie die Bedrohung im Jahr 2026 aussieht, ist grundlegend anders. Die E-Mail, die die Kette in Gang setzt, enthält nichts Gefährliches. Stattdessen trifft die…
-
Anubis Warum ein Patch allein nicht ausreicht
Bereits Anfang Juli berichtete das Arctic Wolf Labs-Team von wichtigen Erkenntnissen rund um die Anubis-Ransomware. Und die Gefahr, die durch die Cyberkampagne ausgeht, ist noch lange nicht gebannt. Stefan Hostetler, Staff Threat Intelligence Researcher bei Arctic Wolf, gibt seine Einschätzung zum Risiko, das von der Anubis-Ransomware ausgeht und welche Schritte Unternehmen zur Abwehr ergreifen sollten.…
-
Ransomware Groups Increasingly Deploy EDR Kill Techniques
Halcyon’s latest quarterly ransomware report showed that while ransomware attacks are declining, obfuscation techniques are getting harder to fight against First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ransomware-q2-2026-edr-kill/
-
LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations
A new report links 148 ransomware attacks to Italian organizations in H1 2026, with manufacturing the most targeted sector. Six months, 148 confirmed ransomware claims against Italian targets, and one sector taking the brunt of it. That’s the headline number from a new semi-annual tracker compiled by ransomNews under its RedACT project, which pulls together…
-
How the Gentlemen Ransomware Group Built a Multi-Region Attack Machine in H1 2026
Ransomware’s biggest story in the first half of 2026 was not only about established names maintaining dominance. A newer player, The Gentlemen ransomware group, emerged as one of the most geographically active operators, expanding its reach across Europe, Asia-Pacific, the Middle East & Africa, and the Americas. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/the-gentlemen-ransomware-group/
-
Clop-Erpressergruppe greift PTC Windchill und FlexPLM an
Die Clop-Ransomware-Bande nutzt eine Sicherheitslücke in PTC Windchill und FlexPLM aus, um Daten zu stehlen und Lösegeld zu erpressen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/erpresser-ptc-windchill
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter UAC-0145 Primary Compromise Vectors as of July 2026 SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware Chaos ransomware’s msaRAT: Living…
-
Cybersecurity threats escalate with ransomware, data breaches and online fraud
First seen on scworld.com Jump to article: www.scworld.com/brief/cybersecurity-threats-escalate-with-ransomware-data-breaches-and-online-fraud
-
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Tags: authentication, data, data-breach, endpoint, exploit, extortion, flaw, Internet, login, ransomware, rce, remote-code-execution, threatThreat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.”Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling…

