Colombia’s Ministry of Justice and Law was hit by a ransomware attack only days before the country’s presidential transition, according to Dark Reading. The incident disrupted the ...
The DeadLock ransomware group has adopted a decentralized operational model that combines the Session messaging network with blockchain-backed services to make its extortion infras...
A wave of cyberattacks has struck local governments across four U.S. states over the past week, disrupting 911 services, court operations, and essential public utilities. The most ...
The Gunra ransomware-as-a-service (RaaS) operation has emerged as a significant threat to critical infrastructure organizations, leveraging leaked Conti source code and weaponizing...
Two weeks after a cyberattack disrupted its IT systems, nonprofit medical provider AnMed is still battling fallout after the threat actors behind the breach hijacked the organizati...
The FBI and South Korea's National Policy Agency issued a joint cybersecurity advisory on Monday warning that the Gunra ransomware gang, which emerged in April 2025, is actively ta...
Microsoft Threat Intelligence has revealed that Storm-1175, a China-based financially motivated threat actor, has deployed a previously undocumented ransomware strain called StormE...
A federal judge in Alexandria, Virginia sentenced Belarusian national Maksim Silnikau to 16 years in prison on August 5, 2026, for building and operating Ransom Cartel, a ransomwar...
The INC Ransomware operation has rapidly become the "dominant threat actor" weaponizing recently disclosed flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances....
Threat actors continue refining their tradecraft this week, blending social engineering with multi-stage loaders to compromise organizations across manufacturing, finance, and reta...
Australian energy giant Origin Energy has confirmed a significant data breach affecting approximately 900,000 current and former customers, exposing sensitive personal information ...
In February 2024, the FBI and its international partners executed Operation Cronos, delivering what law enforcement officials called the most decisive blow against ransomware infra...
Coca-Cola has confirmed that the recent ransomware attack on its dairy subsidiary Fairlife resulted in a data breach, with the Anubis ransomware group claiming to have stolen appro...
Atlanta-based medical revenue cycle management company MCBS (Medical Computer Business Services) has disclosed that a September 2025 cyberattack compromised the personal data of mo...
Threat actors affiliated with the Cl0p ransomware operation—tracked under aliases including Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest—are actively exploiting intern...
The operators behind the DevMan ransomware-as-a-service (RaaS) scheme continue to run a dedicated web platform that lets affiliates generate payloads, track earnings, and coordinat...
Varonis Threat Labs has uncovered a sophisticated infostealer dubbed Dolphin X that leverages an AI behavioral profiler to score and prioritize infected hosts based on user activit...
The Chaos ransomware group has adopted a novel technique to conceal its command-and-control communications, routing traffic through the victim's own Chrome or Edge browser using a ...
A ransomware attack on a major Japanese food and logistics provider has disrupted frozen-food deliveries to thousands of restaurants across the country, sending ripples through one...
The ransomware landscape is undergoing a significant transformation driven by ecosystem fragmentation rather than artificial intelligence advancements, according to researchers tra...
Threat actors affiliated with the Qilin (also known as Agenda) ransomware-as-a-service (RaaS) operation have been weaponizing a now-patched high-severity flaw in Palo Alto Networks...
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, an AI-agent-driven operator first documented earlier this month. The same threat actor ...
The Inc Ransomware group has been observed weaponizing two previously undisclosed zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) appliances, chaining the flaws to...
Coca-Cola's premium dairy subsidiary Fairlife has suspended operations at its US processing plants following a ransomware intrusion detected on Thursday. The company confirmed the ...
Armenian border officers at Yerevan's Zvartnots airport pulled Russian tourist Aleksandr Ermakov from the departure hall on June 28, 2026, detaining him on a U.S. extradition reque...
Identity-based attacks have dethroned vulnerability exploits as the leading root cause of ransomware intrusions, marking a significant shift in attacker tradecraft, according to re...
The U.S. Treasury Department's Office of Foreign Assets Control (OFAC) has imposed sanctions on two individuals and a VPN service provider for facilitating ransomware operations an...
Symantec's Threat Hunter Team has identified a new ransomware family, dubbed GodDamn, that leverages a Microsoft-signed kernel driver called PoisonX to neutralize endpoint secur...
Cloud security researchers at Sysdig have documented what may be the first ransomware operation executed entirely by an autonomous AI agent. Dubbed "JadePuffer," the campaign lever...
A U.S. government entity—almost certainly Union County, Ohio—paid roughly $1 million in bitcoin to a group calling itself Kairos to suppress the leak of stolen files, according to ...
Blackpoint Cyber researchers Nevan Beal and Sam Decker have uncovered Avalon, a previously undocumented modular malware framework that consolidates credential harvesting, lateral m...
A threat actor tracked as JadePuffer has executed what cloud security firm Sysdig describes as the first fully agentic AI-driven ransomware campaign, exploiting a critical missing ...
Threat actors tied to the Anubis ransomware-as-a-service (RaaS) operation have been actively exploiting Citrix Bleed 2 (CVE-2025-5777), a critical authentication-bypass flaw in Cit...
A wave of cyber incidents this week underscores how attackers continue to exploit trust in familiar brands and trusted infrastructure. Researchers at Bitdefender uncovered a phishi...
Security firm Sysdig has uncovered what it calls the first ransomware campaign executed end-to-end by an AI agent, tracked as JADEPUFFER. A large language model handled every stage...
The education sector continues to absorb punishing blows from third-party breaches, with ransomware groups like Cl0p exploiting software vulnerabilities in vendors to cascade damag...
Symantec researchers have uncovered a new stealthy backdoor dubbed "Mistic" being deployed by KongTuke (also tracked as Woodgnat), a financially motivated initial access broker act...
Two key members of the prolific cybercrime group Scattered Spider pleaded guilty on the opening day of their six-week trial at a UK court. Thalha Jubair, 20, of East London, and 18...
A newly identified ransomware operation dubbed ‘Prinz Eugen’ is turning heads in the cybersecurity community for an unusual encryption strategy: prioritizing recently modified file...
The Gentlemen ransomware-as-a-service (RaaS) operation has emerged as one of the most technically agile cybercrime crews since launching in March 2025, according to ESET researcher...
The Gentlemen ransomware-as-a-service (RaaS) operation is actively maintaining a sophisticated suite of endpoint detection and response (EDR) killers to help its affiliates evade d...
Nintendo of America has confirmed that threat actors stole internal survey data from TinyPulse, a third-party employee engagement platform owned by WebMD Health Services, but stres...
INC Ransomware has cemented its position as one of the most prolific ransomware-as-a-service (RaaS) operations in 2026, claiming more than 830 victims since its emergence in August...
INC Ransomware has emerged as one of the most operationally disciplined ransomware groups active in 2024-2025, achieving consistent success not through novel exploit chains or zero...
A Ukrainian national extradited from Ireland to the United States has pleaded guilty to conspiracy to commit wire fraud for his role in the Conti ransomware operation, the U.S. Dep...
Europol has announced the takedown of AudiA6, an industrial-scale cryptocurrency laundering service that processed more than €336 million (~$389 million) in illicit funds since lau...
A new deep-dive into The Gentlemen ransomware operation reveals that the financially motivated threat group has claimed 478 victims since emerging in March 2025, and now operates a...
Law enforcement agencies across 11 countries have jointly dismantled "AudiA6," a cryptocurrency laundering service that processed more than $380 million in illicit proceeds for ran...
Veeam has shipped an emergency patch for a critical remote code execution vulnerability in its widely deployed Backup & Replication platform. Tracked as CVE-2026-44963, the flaw ca...
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity denial-of-service vulnerability in SolarWinds Serv-U to its Known Exploited Vulnerabiliti...
GitHub has officially confirmed that a sophisticated supply chain attack compromised its internal repositories, resulting in the exfiltration of approximately 3,800 repositories by...
Authorities in Europe and North America have successfully dismantled First VPN, a criminal VPN service specifically designed to anonymize ransomware operations and other cyberattac...
West Pharmaceutical Services, a $3 billion S&P 500 drug‑packaging firm, disclosed on May 13, 2026 that it was hit by a material cyberattack. The company detected the intrusion on M...
Thousands of schools and universities across the United States and Canada were thrust into disarray this week after the popular learning management system (LMS) Canvas, developed b...
RansomHouse, a known ransomware operation, has claimed responsibility for a breach at Trellix, a prominent cybersecurity vendor. The group posted several screenshots on a dark‑web ...
On Thursday, May 30 2025, a coordinated cyber incident hit Instructure's Canvas learning management system, displaying a ransom note from an unidentified cybercriminal group to stu...
Trellix, a prominent cybersecurity vendor, disclosed on [date] that its internal source‑code repository had been compromised. The intrusion was promptly claimed by the RansomHouse ...
A massive data‑extortion campaign slammed the widely‑used learning‑management platform Canvas on Tuesday, forcing districts and universities across the United States to suspend onl...
Modern cyber‑threats have evolved beyond the initial breach, with adversaries now targeting backup systems, encryption keys, and recovery pipelines to maximize impact. A new webina...
The Iranian state-sponsored threat actor MuddyWater, also tracked as Mango Sandstorm, Seedworm, and Static Kitten, has been linked to a sophisticated cyberattack that leveraged Mic...
Acronis researchers have documented a systematic shift in ransomware operations: before triggering encryption, threat actors now deliberately cripple backup infrastructure. Their 2...
MuddyWater, the Iranian advanced persistent threat (APT) group also tracked as Static Kitten, has been observed disguising its espionage operations behind a non‑functional Chaos ra...
A Latvian national was sentenced on Friday to 8.5 years in a U.S. federal prison after being extradited to face charges related to his work as a "cold case" negotiator for the Russ...
Kaseya announced a live webinar titled “Why MSPs must rethink security and backup strategies” scheduled for June 15, 2026 at 2:00 PM ET. The session, hosted by Kaseya’s Product Mar...
A newly disclosed vulnerability in cPanel, tracked as CVE-2026-41940, is being actively exploited in the wild as part of a coordinated ransomware campaign dubbed "Sorry." Security ...
The U.S. Department of Justice announced that two former cybersecurity professionals have each been sentenced to four years in federal prison for their roles in enabling BlackCat r...
A federal court has sentenced two former cybersecurity incident response professionals to four years in prison each for their roles in conducting BlackCat (ALPHV) ransomware attack...
A newly identified ransomware strain named Vect 2.0 has been observed executing wiper‑style attacks against organizations compromised through the TeamPCP software supply chain. The...
The ransomware ecosystem was rocked in early 2026 when two prominent ransomware‑as‑a‑service (RaaS) operations, 0APT and KryBit, turned on each other, spilling a treasure trove of ...
The cyber‑crime group behind the VECT 2.0 ransomware has been observed deploying a strain that behaves more like a data‑wiper than conventional ransomware. In recent incidents targ...
According to the latest Dark Reading analysis, the weekly number of cyberattacks directed at African organizations dropped by 22 % over the past year, falling from roughly 5,400 in...
Security researchers at multiple threat intelligence firms have observed a significant acceleration in The Gentlemen ransomware group's operational tempo and technical capabilities...
On March 12, 2024, former incident‑response negotiator David Mercer entered a guilty plea in the U.S. District Court for the Eastern District of New York to one count of conspiracy...
Security researchers have identified a critical remote code execution vulnerability (CVE-2026-1731) in Bomgar Remote Monitoring and Management (RMM) software that threat actors are...
German authorities have publicly exposed the identity of the notorious hacker known as "UNKN", linking the alias to 31‑year‑old Russian national Daniil Maksimov. Maksimov is allege...
In the summer of 2024, LockBit solidified its standing as the most prolific ransomware‑as‑a‑service (RaaS) operation, accounting for roughly 35 % of all ransomware incidents tracke...