2026-08-27 12:15 UTC
Security Journalism
The Record · indexed 2026-08-27 12:25 UTC
The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed it experienced a cyberattack on a system containing investigation information, as a prolific ransomware gang claimed to have carried out the breach.
P15
2026-08-27 08:13 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-27 08:20 UTC
ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang. [...]
P15
2026-08-26 09:00 UTC
Vendor Research
Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-08-26 13:15 UTC
A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication.It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a n…
P45
2026-08-24 15:02 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-08-24 15:50 UTC
An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.
P15
2026-08-24 12:35 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-24 14:05 UTC
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha)
P15
2026-08-23 17:04 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-23 18:20 UTC
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Akira Hits Safe Mode: Ransomware Rebooting Around EDR Multi-Functional Linux Botnet “Evooo1Bot” StubMaker RubyGems Campaign Delivers a Windows Infostealer Hunting MacSync Stealer infrastructure through behavioral pivots Manic: Blend between Banking Malware & Spyware […]
P15
2026-08-21 15:00 UTC
Security Journalism
The Record · indexed 2026-08-21 15:05 UTC
The Hospital for Sick Children — which was hit in a ransomware incident in 2022 that disabled some of its systems — released a statement on Thursday warning of a data theft incident they believe is tied to a third-party software application.
P15
2026-08-20 07:20 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-20 07:30 UTC
StopAndProtect turned nearly 2,000 hacked WordPress sites into a criminal network for malware delivery, data theft, surveillance and ransomware. Check Point Research uncovered a cybercrime operation, dubbed StopAndProtect, that has turned thousands of hacked WordPress websites into a shared platform for malware delivery, data theft, surveillance and ransomware. The operation is a good reminder that […]
P15
2026-08-19 20:59 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-08-19 22:15 UTC
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
P15
2026-08-19 20:59 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-08-19 21:10 UTC
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
P15
2026-08-19 08:00 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-19 08:10 UTC
The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]
P15
2026-08-18 18:05 UTC
Security Journalism
The Record · indexed 2026-08-18 18:15 UTC
The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.
P15
2026-08-18 17:29 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-08-18 17:30 UTC
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]
P15
2026-08-18 16:58 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-18 18:35 UTC
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. "In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," GuidePoint Research
P15
2026-08-18 13:05 UTC
Other
Check Point Research · pedrod@checkpoint.com · indexed 2026-09-07 17:30 UTC
Research by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts with a ClickFix social-engineering technique, which prompts victims to execute a PowerShell command. This leads to two stages of additional downloaders and […] The post Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect appeared first on…
P15
2026-08-18 13:00 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-08-18 13:10 UTC
A ransomware affiliate appears to be sidling up to victims with offers of aid, masking its true intention of diverting ransom payments.
P15
2026-08-18 12:49 UTC
Vendor Research
Rapid7 · Rapid7 Labs · indexed 2026-08-18 15:35 UTC
You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive program…
P15
2026-08-18 10:32 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-18 10:40 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. [...]
P40
2026-08-17 23:00 UTC
Security Journalism
The Record · indexed 2026-08-18 11:40 UTC
The unnamed 52-year-old is accused of attacking Swiss train manufacturer Stadler Rail alongside other enterprises as part of an international ransomware operation.
P15
2026-08-17 15:15 UTC
Vendor Research
Tenable Blog · Clément Notin · indexed 2026-08-17 15:35 UTC
Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detection alerts.Key takeawaysStorm-0501 demonstrates that cloud-first ransomware groups have shifted from simple endpoint encryption to the total hijacking of cloud tenants.Storm-0501 systematically neutra…
P15
2026-08-17 13:37 UTC
Other
Check Point Research · urias@checkpoint.com · indexed 2026-09-07 17:30 UTC
For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were […] The post 17th August – Threat Intelligence Report appeared first on Check Point Research.
P15
2026-08-17 11:25 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-17 11:30 UTC
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]
P15
2026-08-17 07:36 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-08-17 10:50 UTC
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code
P20
2026-08-17 07:15 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-17 07:40 UTC
Akira attackers used Safe Mode to disable EDR before deploying ransomware, but memory issues caused the encryptor to fail. An Akira ransomware affiliate broke into a company through an MFA-less SonicWall VPN on August 4, stole credentials and file shares, and then rebooted the compromised host into Safe Mode with Networking to kill the security […]
P15
2026-08-14 11:55 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-08-15 14:33 UTC
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...]
P15
2026-08-13 20:47 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-15 14:33 UTC
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...]
P15
2026-08-13 12:54 UTC
Other
Check Point Research · matthewsu@checkpoint.com · indexed 2026-09-07 17:30 UTC
For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The leaders are still winning, but […] The post The State of Ransomware Q2 2026 appeared first on Check Point Research.
P15
2026-08-12 14:00 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-08-15 18:55 UTC
Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.
P15
2026-08-12 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
An Akira affiliate rebooted into Safe Mode to kill EDR and Defender, then Safe Mode broke their own ransomware. Here’s the full attack chain.
P15
2026-08-11 21:16 UTC
Security Journalism
Dark Reading · Rob Wright · indexed 2026-08-15 18:55 UTC
The ransomware-as-a-service operation is finding success against critical infrastructure targets with leaked Conti code and old flaws in firewalls and VPN appliances.
P15