2026-10-09 18:45 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-09 19:50 UTC
Japan helped extradite a Russian suspect linked to Qilin ransomware to Germany, but the gang continued attacking victims after his arrest. Germany has arrested a Russian national believed to be a leading figure in the Qilin ransomware group, and Japan’s National Police Agency just put its own role in that arrest on the record. The […]
P15
2026-10-09 18:45 UTC
Security Journalism
The Record · indexed 2026-10-09 19:05 UTC
Japan’s National Police Agency confirmed the arrest and extradition to Germany of a Russian national accused of being involved in the Qilin ransomware gang.
P15
2026-10-09 15:38 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-09 15:45 UTC
Germany has arrested a Russian national suspected of being a leading member of the Qilin ransomware group following extradition from Japan earlier this month. [...]
P15
2026-10-08 20:09 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-08 20:20 UTC
IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country. [...]
P15
2026-10-08 17:58 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 18:55 UTC
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence. The rest of the week isn't much more reassuring. Malicious code turned up in developer packages and extensions that
P15
2026-10-08 17:00 UTC
Security Journalism
The Record · indexed 2026-10-08 17:15 UTC
The owner of a ransomware recovery firm was hit with wire fraud charges for allegedly making secret ransom payments while overcharging the victims of attacks.
P15
2026-10-08 13:37 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-08 14:50 UTC
MonsterCloud owner Zohar Pinhasi allegedly paid ransomware demands behind clients’ backs, then charged them millions for the supposed recovery. Zohar Pinhasi, the owner of Florida-based MonsterCloud, was charged this week with wire fraud. Federal prosecutors say his clients were scammed twice during the same ransomware crisis. Pinhasi (50) also used the names “Zack Silver” and […]
P15
2026-10-08 09:27 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-08 09:30 UTC
Zohar Pinhasi was paying ransoms to obtain decryption keys and then charging victims substantially more for remediation. The post Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme appeared first on SecurityWeek.
P15
2026-10-08 07:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 08:10 UTC
The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data. Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of wire fraud and one count of wire
P15
2026-10-07 23:04 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-07 23:15 UTC
The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted data. [...]
P15
2026-10-07 19:29 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-10-07 19:50 UTC
In Part 1 of this series, we looked at the security challenges created by fragmented, campus-by-campus environments. Higher education also faces a second pressure that makes that fragmentation harder to sustain: overlapping compliance obligations across FERPA, GLBA, HIPAA, and CMMC.Each framework brings different requirements, reporting timelines, and consequences for failure. Managing them across one institution is already complex, but across a multi-campus university system with separate tool…
P15
2026-10-07 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by Kaseya · indexed 2026-10-07 14:10 UTC
Ransomware groups are increasingly targeting backup infrastructure to eliminate recovery options and increase pressure on victims to pay. Kaseya explains why organizations need isolated, immutable, and regularly tested backups that attackers cannot easily reach. [...]
P15
2026-10-07 13:47 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-07 13:50 UTC
The individual was detained in May and has been extradited to Germany to face hacking charges. The post Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany appeared first on SecurityWeek.
P15
2026-10-07 12:37 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-07 12:50 UTC
The Japanese chip testing giant said hackers stole personal information from its servers in the February 2026 cyberattack. The post Advantest Discloses Data Breach Months After Ransomware Attack appeared first on SecurityWeek.
P15
2026-10-07 10:27 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-07 10:35 UTC
Advantest Corporation is notifying affected individuals that a ransomware attack earlier this year exposed their personally identifiable data. [...]
P15
2026-10-06 14:52 UTC
Security Journalism
The Record · indexed 2026-10-06 15:05 UTC
Osaka Metropolitan University said on Tuesday that the outage left its internal network, email and a range of administrative and academic systems unavailable.
P15
2026-10-06 13:00 UTC
Security Journalism
Huntress · indexed 2026-10-07 07:50 UTC
How Huntress researchers reconstructed an Akira ransomware attack using Registry artifacts, Akira logs, and other post-compromise evidence.
P15
2026-10-06 11:27 UTC
Vendor Research
ANY.RUN Blog · Himanshu Anand · indexed 2026-10-06 14:56 UTC
Editor’s note: This research was conducted by Himanshu Anand, an independent cybersecurity researcher (follow Himanshu on X). During Cybersecurity Awareness Month, ransomware remains one of the clearest examples of how a cyber incident can become a business continuity issue. IronChain shows why. It puts business-critical data at risk of permanent loss and can bring operations […] The post IronChain Ransomware Threatens Businesses with Permanent Data Loss and Costly Downtime appeared first on AN…
P15
2026-10-06 08:19 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-06 08:20 UTC
A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomware-style attack. [...]
P15
2026-10-05 15:30 UTC
Security Journalism
The Record · indexed 2026-10-05 16:00 UTC
A ransomware attack that affected the University of Illinois Chicago (UIC) College of Medicine resulted in the theft of some information from its servers.
P15
2026-10-05 14:20 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 15:15 UTC
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others
P40
2026-10-04 07:49 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-04 08:00 UTC
Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telecoms, governments, and universities worldwide. Warlock ransomware made headlines back in mid-2025 for exploiting a chain of SharePoint zero-days collectively dubbed ToolShell. More than a year later, the same group is still using that door, and it’s still getting in. Symantec tracks the […]
P40
2026-10-03 14:36 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-03 15:25 UTC
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
P15
2026-10-02 18:33 UTC
Security Journalism
BleepingComputer · Ionut Ilascu · indexed 2026-10-02 18:35 UTC
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]
P15
2026-10-02 16:00 UTC
Security Journalism
Huntress · indexed 2026-10-03 08:00 UTC
Nazar Tymoshyk from UnderDefense shares his thoughts on what ransomware attacks look like during the all-important opening hours.
P15
2026-10-02 14:06 UTC
Security Journalism
The Record · indexed 2026-10-02 14:20 UTC
Government services were temporarily disrupted by ransomware in Vicksburg, Mississippi. Mayor Willis Thompson said the FBI and other authorities are investigating.
P15
2026-10-02 14:05 UTC
Security Journalism
The Record · indexed 2026-10-02 14:20 UTC
The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.
P15
2026-10-01 21:37 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-10-01 21:50 UTC
Law enforcement from multiple countries collaborated to disrupt a cybercrime operation that has claimed some 500 victims worldwide in the past two years.
P15
2026-10-01 18:08 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-01 19:00 UTC
Operation KillSwitch: Europol says the KillSec ransomware group, allegedly led by a 16-year-old, was dismantled after attacks on about 1,000 victims. Law enforcement seized control of KillSec ‘s dark web leak site, the Tor website the group used to threaten victims with publishing stolen files unless they paid up. That single action locked down more […]
P15
2026-10-01 16:55 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 17:15 UTC
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected
P15