2026-09-17 08:15 UTC
Vendor Research
ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC
For an MSSP, a quiet month can be a good month. No ransomware outbreak. No major account compromise. No business disruption. But it can also create an awkward conversation with the client: What exactly did we pay for this month? The problem is not that the SOC did nothing. Quite the opposite. Analysts may have […] The post How MSSPs Can Prove Their Value When “Nothing Happened” appeared first on ANY.RUN's Cybersecurity Blog.
P15
2026-09-16 15:27 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 16:25 UTC
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
P15
2026-09-16 14:00 UTC
Security Journalism
BleepingComputer · Sponsored by Datto · indexed 2026-09-16 14:20 UTC
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. [...]
P15
2026-09-15 12:16 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-15 12:30 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...]
P15
2026-09-14 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-14 19:45 UTC
Attackers exploit Volume Shadow Copy for credential theft and ransomware defense evasion. See how Huntress spots the difference from routine IT activity.
P15
2026-09-13 09:19 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-13 10:15 UTC
Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced the 44-year-old to four years in prison this week for conspiracy […]
P15
2026-09-11 12:00 UTC
Security Journalism
The Record · indexed 2026-09-11 12:10 UTC
A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022.
P15
2026-09-11 11:29 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-11 11:35 UTC
Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023. The post Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison appeared first on SecurityWeek.
P15
2026-09-11 10:14 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-11 10:55 UTC
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls, run […]
P30
2026-09-11 06:48 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-11 06:55 UTC
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]
P15
2026-09-11 06:19 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 07:40 UTC
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass
P30
2026-09-10 21:40 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-10 21:45 UTC
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...]
P15
2026-09-10 15:43 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-10 15:55 UTC
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]
P15
2026-09-10 09:10 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-10 09:30 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. [...]
P40
2026-09-09 15:31 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-09 15:35 UTC
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]
P15
2026-09-09 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-11 16:45 UTC
Threat actors are exploiting GTA6 hype with fake leaked downloads spread via SEO poisoning, packed with RATs, infostealers, and wiper ransomware. Here’s what Huntress found.
P15
2026-09-08 21:44 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-09 00:10 UTC
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will e…
P65
2026-09-08 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC
Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…
P35
2026-09-08 03:30 UTC
Other
Group-IB · indexed 2026-09-08 03:50 UTC
Group-IB's 2026 data shows ransomware accelerating across APAC. See where response plans fail, and the 5-pillar framework built to hold under pressure.
P15
2026-09-07 07:19 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-07 08:30 UTC
Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out […]
P15
2026-09-03 21:15 UTC
Vendor Research
AWS Security Blog · Oscar Diaz · indexed 2026-09-03 21:35 UTC
In Part 1 of this guide, we examined two common incident scenarios: cross-account Amazon Simple Storage Service (Amazon S3) data deletion with ransomware implications, and cryptocurrency mining deployed through AWS CloudFormation using exposed AWS Management Console credentials. We also introduced key incident response terminology and investigative frameworks for analyzing AWS CloudTrail events. In this second […]
P15
2026-09-02 15:07 UTC
Security Journalism
The Record · indexed 2026-09-02 15:15 UTC
The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week.
P15
2026-09-02 14:02 UTC
Security Journalism
BleepingComputer · Sponsored by Acronis · indexed 2026-09-02 14:15 UTC
Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]
P15
2026-09-01 21:03 UTC
Security Journalism
Dark Reading · Arielle Waldman · indexed 2026-09-01 21:05 UTC
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.
P15
2026-08-31 13:30 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-31 13:40 UTC
Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. [...]
P15
2026-08-31 11:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-31 12:30 UTC
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its
P15
2026-08-30 08:38 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-30 09:40 UTC
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Hack One Robot, Reach the Next: Unitree G1 Security Flaws Rhysida Ransomware Group Targets Berlin Government Ahead […]
P15
2026-08-29 10:55 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-29 11:35 UTC
Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft. Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group […]
P15
2026-08-28 10:09 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-08-28 10:30 UTC
Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the initial time of disclosure, the vulnerability had not been assigned a CVE identifier, and PaperCut had not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the techni…
P100
2026-08-27 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Protect your Australia- and New Zealand-based retail business from cyber threats. Learn five key decisions to secure identities, manage dependencies and ensure trading continuity against ransomware
P15