Back to Feed

Tag

Ransomware

50 items tagged #ransomware

Articles

Hackers bypass SonicWall VPN MFA due to incomplete patching

SonicWall Gen6 SSL-VPN devices remain vulnerable to MFA bypass despite patching without manual LDAP reconfiguration.

Banana RAT Malware in Fake Invoices Hits Customers at 16 Brazilian Banks

Banana RAT malware targets 16 Brazilian banks via fake invoices, stealing data with QR code fraud.

7-Eleven confirms data breach claimed by the ShinyHunters gang

7-Eleven confirms cyberattack by ShinyHunters gang that stole 600K+ records from Salesforce systems.

Daily Dose of Dark Web Informer - May 13th, 2026

Dark Web Informer daily digest reports multiple breaches, ransomware hits, and supply chain attacks across global

West Pharmaceutical says hackers stole data, encrypted systems

West Pharmaceutical Services discloses cyberattack with data exfiltration and system encryption.

Instructure Reaches Deal with ShinyHunters to Prevent Canvas Data Leak

Instructure reaches deal with ShinyHunters to prevent Canvas data leak of 275M student records.

US govt seeks Instructure testimony on massive Canvas cyberattack

US House investigates ShinyHunters' dual Canvas breaches affecting millions of students.

"EtherRAT was installed via a malicious MSI [...] then deployed The Gentlemen ransomware" Already...

EtherRAT remote access trojan deployed via malicious MSI installer before delivering The Gentlemen ransomware.

Free OnlyFans Lure Used to Spread Cross-Platform CRPx0 Malware

CRPx0 malware campaign uses free OnlyFans lure to target macOS, Windows, and Linux systems.

Deal Reached With Hackers to Delete Data Stolen From the Canvas Educational Platform

Instructure reaches deal with ShinyHunters to delete Canvas data stolen in breach affecting 9,000 schools.

Instructure reaches 'agreement' with ShinyHunters to stop data leak

Instructure reaches ransom agreement with ShinyHunters over 30M user data breach.

Daily Dose of Dark Web Informer - May 11th, 2026

Daily dark web threat digest covering breaches, ransomware claims, and law enforcement actions.

Instructure confirms hackers used Canvas flaw to deface portals

Instructure confirms XSS vulnerabilities allowed hackers to deface Canvas portals and extort ransom.

Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools

ShinyHunters hacked Canvas learning platform, affecting ~9,000 schools; system restored after brief outage.

‼️🇺🇸 Houghton Mifflin Harcourt Company has been added to the ShinyHunters Pay or Leak portal ht...

Houghton Mifflin Harcourt added to ShinyHunters extortion portal.

Trellix source code breach claimed by RansomHouse hackers

RansomHouse threat group claims responsibility for Trellix source code repository breach.

ShinyHunters Defaces Canvas LMS Portal, Thousands of Universities Affected

ShinyHunters breaches Instructure, defaces Canvas LMS portals affecting thousands of universities worldwide.

MuddyWater hackers use Chaos ransomware as a decoy in attacks

MuddyWater Iranian hackers use Chaos ransomware as cover for cyber-espionage via Teams social engineering.

MuddyWater Uses Microsoft Teams to Steal Credentials in False Flag Ransomware Attack

MuddyWater conducts false flag ransomware attack using Teams social engineering and credential harvesting.

Karakurt Ransomware Negotiator Sentenced to Prison

Latvian Karakurt ransomware negotiator sentenced to 8.5 years in US prison.

Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

Phishing campaign VENOMOUS#HELPER targets 80+ orgs using SimpleHelp and ScreenConnect RMM tools for persistent access.

‼️ 4VPS[.]su a Russian service provider since 2017 used by forums, the com, ransomware groups, an...

Russian VPS provider 4VPS.su allegedly exit-scams after serving cybercrime ecosystem since 2017.

‼️ New Ransomware Group and IP Leak: CMD Organization Clearnet: cmdofficial[.]com IP: 209[.]99[....

New ransomware group CMD Organization surfaces with clearnet and onion infrastructure.

Hackers Use Jenkins Access to Deploy DDoS Botnet Against Gaming Servers

Attackers abuse misconfigured Jenkins servers to deploy DDoS botnet targeting gaming infrastructure.

‼️🇧🇷 Kenlo Imob (formerly inGaia Imob), a leading Brazilian real estate CRM used by brokers and...

Brazilian real estate CRM Kenlo Imob breached; 6M PII records and 10K+ docs under extortion threat.

Former incident responders sentenced to 4 years in prison for committing ransomware attacks

Two former cybersecurity pros sentenced to 4 years for BlackCat ransomware attacks extorting $1.3M.

#ClickFix style campaign operated eight bulk registered 588gj*[.]shop lure domains impersonating...

ClickFix-style campaign uses 588 bulk-registered domains impersonating PureClaw AI software to deliver backdoors and

When the Defenders Become the Attackers: Two U.S. Cybersecurity Pros Sentenced in BlackCat Ransomware Case

Two U.S. cybersecurity professionals sentenced to four years for deploying ALPHV BlackCat ransomware.

Sandhills Medical Says Ransomware Breach Affects 170,000

Sandhills Medical discloses ransomware breach affecting 170,000 after nearly one year delay.

‼️ Aur0ra Ransomware Names Its First Seven Victims http://u6lieui2dakbctcjea2bz4r4q32r7t36nwljov...

Aur0ra ransomware group claims first seven victims across US sectors.

⚠️ A Russian-speaking threat actor group is recruiting an Initial Access Broker (IAB) to supply c...

Russian-speaking threat actor recruits IAB for corporate network access without ransomware deployment.

CISA Adds Actively Exploited ConnectWise and Windows Flaws to KEV

CISA adds ConnectWise ScreenConnect and Windows Shell flaws to KEV catalog due to active exploitation.

Vimeo Confirms User and Customer Data Breach

Vimeo confirms data breach via compromised Anodot vendor; ShinyHunters demands ransom by April 30.

US reportedly charges Scattered Spider hacker arrested in Finland

US charges 19-year-old Scattered Spider member arrested in Finland for extortion breaches.

Medtronic Hack Confirmed After ShinyHunters Threatens Data Leak

Medtronic confirms cyberattack by ShinyHunters claiming 9M records stolen.

Medtronic confirms breach after hackers claim 9 million records theft

Medtronic confirms breach; ShinyHunters claims 9M records theft and ransom demand.

‼️ LAPSUS$ Group claims 3 victims 🇪🇸 MAPFRE 🇬🇧 Vodafone 🇮🇱 Checkmarx https://t.co/2C2SWqZMvU

LAPSUS$ claims breaches of MAPFRE, Vodafone, and Checkmarx.

CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline

CISA adds 4 actively exploited vulnerabilities to KEV catalog with May 2026 federal deadline.

ADT confirms data breach after ShinyHunters leak threat

ADT confirms data breach after ShinyHunters threatens to leak 10M customer records.

Dark Web Informer

Dark Web Informer aggregates breach, ransomware, and vulnerability intelligence from dark web and clearnet sources.

Third US Security Expert Admits Helping Ransomware Gang

Third US security expert pleads guilty to aiding BlackCat ransomware gang while working as negotiator.

Data Breaches at Healthcare Organizations in Illinois and Texas Affect 600,000

Three US healthcare orgs disclose breaches affecting 600K patients in Illinois and Texas.

Former ransomware negotiator pleads guilty to BlackCat attacks

Former ransomware negotiator pleads guilty to BlackCat attacks targeting U.S. companies.

Florida Man Working as a Ransomware Negotiator Pleads Guilty to Conspiracy to Deploy Ransomware and Extort U.S. Victims

Florida ransomware negotiator pleads guilty to aiding BlackCat attacks and extorting U.S. victims.

Daily Dose of Dark Web Informer - April 20th, 2026

Daily dark web threat digest reports multiple breaches, ransomware claims, and law enforcement actions across global

Seiko USA website defaced as hacker claims customer data theft

Seiko USA website defaced; attackers claim Shopify customer database theft and demand ransom.

Hackers Abuse QEMU for Defense Evasion

Threat actors abuse QEMU emulator in ransomware and RAT campaigns for defense evasion.

‼️ Vercel has allegedly been breached by ShinyHunters, with a ransom demand of $2,000,000. http...

Vercel allegedly breached by ShinyHunters with $2M ransom demand.

HACKED

Shopify store targeted by extortion-based data breach threatening customer database release.

Daily Dose of Dark Web Informer - April 14th, 2026

Daily dark web threat digest covering breaches, ransomware, and critical infrastructure incidents across multiple