Back to Feed

Tag

Ransomware

51 items tagged #ransomware

Articles

‼️ Gunra Ransomware Claims 16 Victims 🇰🇷 KUKJE PHARM CO.,LTD. 🇹🇭 bkksky[.com 🇸🇬 triotech[....

Gunra ransomware gang claims 16 victims across multiple countries.

Massachusetts Hospital Diverts Ambulances as Cyberattack Causes Disruption

Signature Healthcare in Massachusetts diverts ambulances after cyberattack disrupts operations.

New ClickFix Attack Uses Node.js Malware via Tor to Steal Crypto

ClickFix campaign uses fake CAPTCHAs to deploy Node.js RAT malware via Tor to steal crypto.

Medusa Ransomware Fast to Exploit Vulnerabilities, Breached Systems

Medusa ransomware group exploits zero-days and fresh vulnerabilities to breach 300+ organizations within days.

German Police Unmask REvil Ransomware Leader

German police identify Russian national as REvil/GandCrab ransomware leader.

Wynn Resorts Says 21,000 Employees Affected by ShinyHunters Hack

Wynn Resorts confirms 21,000 employees affected by ShinyHunters data breach targeting HR systems.

Iran-Linked Password-Spraying Campaign Targets 300+ Israeli Microsoft 365 Organizations

Iran-linked actor wages password-spraying campaign against 300+ Israeli Microsoft 365 organizations.

Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab

Germany identifies Daniil Maksimovich Shchukin as UNKN, leader of GandCrab and REvil ransomware gangs.

‼️ New Ransomware Group: Krybit krybitxdpxohsmjooeb3gbgpmdddreh6mnflzac6bnezz74b7yje67yd[.]onion...

New ransomware group Krybit emerges with multiple Tor infrastructure.

‼️ New Ransomware Group: Krybit krybitxdpxohsmjooeb3gbgpmdddreh6mnflzac6bnezz74b7yje67yd[.]onion...

New ransomware group Krybit emerges with Tor-based infrastructure.

Latin America and the Caribbean Cybercrime Landscape

Insikt Group report on 2025 LAC cybercrime landscape reveals 452 ransomware incidents targeting Brazil, Mexico,

In Other News: ChatGPT Data Leak, Android Rootkit, Water Facility Hit by Ransomware

SecurityWeek roundup: Android rootkit, ChatGPT data leak, water facility ransomware, FBI breach.

Researchers Uncover Mining Operation Using ISO Lures to Spread RATs and Crypto Miners

REF1695 operation deploys RATs and crypto miners via ISO file lures since November 2023.

‼️🇺🇸 Handala Hack claims St. Joseph County breached with over 2 terabytes of data allegedly sto...

Handala Hack claims breach of St. Joseph County with 2TB of data stolen.

ShadowByt3s Claims Starbucks Breach With 10GB of Proprietary Source Code, Beverage Machine Firmware, and Global Management Tools From Compromised S3 Bucket

ShadowByt3s claims 10GB Starbucks breach via misconfigured S3 bucket with source code, firmware, and management tools.

Google Drive ransomware detection now on by default for paying users

Google Drive ransomware detection now enabled by default for paid workspace users.

Weaponizing the Protectors: TeamPCP’s Multi-Stage Supply Chain Attack on Security Infrastructure

TeamPCP compromises Trivy, KICS, LiteLLM, and Telnyx SDK in multi-stage supply chain attack.

TeamPCP’s supply chain attacks continue, and the group has announced a partnership with BreachFor...

TeamPCP escalates supply chain attacks with BreachForums and Vect ransomware partnership.

Stolen Logins Are Fueling Everything From Ransomware to Nation-State Cyberattacks

Stolen credentials fuel ransomware, SaaS breaches, and state-sponsored attacks at industrial scale.

Iran Deploys 'Pseudo-Ransomware,' Revives Pay2Key Operations

Iranian APTs deploy pseudo-ransomware targeting US orgs via revived Pay2Key operations.

‼️ PLAY Ransomware claims 10 victims 🇬🇧 Witt UK Group 🇺🇸 Valley Plating Inc 🇺🇸 Ampex Data...

PLAY ransomware group claims 10 new victims across UK, US, Germany, and Sweden.

Cat’s Got Your Files: Lynx Ransomware - The DFIR Report

Lynx ransomware campaign exploits internet-exposed RDP with valid credentials starting March 2025.

Critical Fortinet Forticlient EMS flaw now exploited in attacks

Fortinet FortiClient EMS SQL injection flaw CVE-2026-21643 actively exploited in attacks.

Daily Dose of Dark Web Informer - March 27th, 2026

Dark Web Informer daily digest reports Handala Hack breaches at Lockheed Martin and Stryker, FBI Director compromise,

🚨🚦 7 years for a $9M ransomware broker, malware-laden 'Resumes', and a global hijack of npm and...

Ransomware broker sentenced to 7 years; malware in resumes and package repository hijacks reported.

SnowTeam Launches Leak Bazaar, a Corporate Data Exchange With ML-Powered Dump Analysis, DBMS Reverse Engineering, and Ransomware Negotiation Support

SnowTeam launches Leak Bazaar, a dark web marketplace for stolen corporate data with ML analysis and ransomware

‼️SnowTeam Launches Leak Bazaar, a Corporate Data Exchange With ML-Powered Dump Analysis, DBMS Re...

SnowTeam launches Leak Bazaar, a criminal marketplace for stolen corporate data with ML analysis tools.

Daily Dose of Dark Web Informer - March 26th, 2026

Daily dark web threat intelligence digest reporting multiple data breaches, ransomware incidents, and hacktivist claims.

Russian Cybercriminal Gets 2-Year Prison Sentence in US

Russian cybercriminal Ilya Angelov sentenced to 2 years for administering botnet facilitating ransomware attacks.

Russian Hacker Sentenced to 2 Years for TA551 Botnet-Driven Ransomware Attacks

Russian national sentenced to 2 years prison for managing TA551 botnet ransomware attacks.

US Prisons Russian Access Broker for Aiding Ransomware Attacks

Russian access broker sentenced to 81 months for Yanluowang ransomware attacks causing $9M+ losses.

‼️🇪🇹 Alleged Full Infrastructure Compromise of National Oil Ethiopia With 800GB ERP Database Ex...

National Oil Corporation of Ethiopia suffers alleged full infrastructure compromise with 800GB ERP database

Tax Search Ads Deliver ScreenConnect Malware Using Huawei Driver to Disable EDR

Tax-themed malvertising campaign delivers ScreenConnect malware with EDR-killing Huawei driver since January 2026.

Russian access broker sentenced to over 6 years in prison for ransomware schemes

Russian access broker sentenced to 81 months for facilitating ransomware attacks via Yanluowang group.

Yanluowang ransomware access broker gets 81 months in prison

Russian initial access broker sentenced to 81 months for supplying network access to Yanluowang ransomware gang.

U.S. Sentences Russian Hacker to 6.75 Years for Role in $9M Ransomware Damage

U.S. sentences Russian hacker to 6.75 years for facilitating $9M in ransomware attacks.

Mazda discloses security breach exposing employee and partner data

Mazda discloses breach of 692 employee and partner records via warehouse management system vulnerability.

‘CanisterWorm’ Springs Wiper Attack Targeting Iran

TeamPCP deploys CanisterWorm wiper targeting Iran via compromised cloud infrastructure.

Chip Services Firm Trio-Tech Says Subsidiary Hit by Ransomware

Trio-Tech semiconductor subsidiary in Singapore hit by ransomware; data stolen and published.

⚡ Weekly Recap: CI/CD Backdoor, FBI Buys Location Data, WhatsApp Ditches Numbers & More

Weekly security recap covering Trivy scanner backdoor, IoT botnets takedown, and rapid zero-day exploitation.

Cyberattack on a Car Breathalyzer Firm Leaves Drivers Stuck

Intoxalock breathalyzer cyberattack strands 150,000 US drivers unable to start vehicles.

🚦 Interpol Disrupts Malicious Networks Globally, EU Sanctions State-Sponsored Threat Actors, ‘Da...
In Other News: New Android Safeguards, Operation Alice, UK Toughens Cyber Reporting
CISA orders feds to patch max-severity Cisco flaw by Sunday
‼️🇺🇸 World Leaks has allegedly claimed the City of Los Angeles (LA). The listing shows 159.9 G...
54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security
Marquis Data Breach Affects 672,000 Individuals
ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More
Cisco Firewall Vulnerability Exploited as Zero-Day in Interlock Ransomware Attacks
CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks

Events