Ransomware

Alleged Scattered Spider Hacker Extradited to US

Alleged Scattered Spider Hacker Extradited to US 2026-07-03 at 12:30 By Ionut Arghire Prosecutors say 19-year-old Peter Stokes was a member of Scattered Spider, the hacking group linked to more than 100 network intrusions and over $100 million in ransom payments. The post Alleged Scattered Spider Hacker Extradited to US appeared first on SecurityWeek. This […]

Alleged Scattered Spider Hacker Extradited to US Read More »

Scattered Spider suspect extradited over $8 million ransom scheme

Scattered Spider suspect extradited over $8 million ransom scheme 2026-07-02 at 16:43 By Anamarija Pogorelec A suspected Scattered Spider member has been extradited to the United States to face charges linked to cyberattacks against U.S. companies, including the breach of a luxury jewelry retailer that led to an $8 million cryptocurrency ransom demand after attackers

Scattered Spider suspect extradited over $8 million ransom scheme Read More »

Catching ransomware on the wire before it locks the file server

Catching ransomware on the wire before it locks the file server 2026-07-02 at 08:00 By Sinisa Markovic Corporate networks keep sensitive files off individual workstations and store them on shared servers that staff reach through mapped network drives. That arrangement hands ransomware operators a target worth chasing. A single compromised laptop can begin encrypting files

Catching ransomware on the wire before it locks the file server Read More »

BlueHammer Vulnerability Exploited in Ransomware Attacks

BlueHammer Vulnerability Exploited in Ransomware Attacks 2026-06-30 at 16:56 By Eduard Kovacs The Microsoft Defender vulnerability CVE-2026-33825 was exploited in the wild as a zero-day before patches were released. The post BlueHammer Vulnerability Exploited in Ransomware Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

BlueHammer Vulnerability Exploited in Ransomware Attacks Read More »

More Klue Breach Victims Identified as Hackers Get Hacked

More Klue Breach Victims Identified as Hackers Get Hacked 2026-06-26 at 18:01 By Ionut Arghire Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact. The post More Klue Breach Victims Identified as Hackers Get Hacked appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

More Klue Breach Victims Identified as Hackers Get Hacked Read More »

Ransomware gangs find Europe’s weakest link in third-party suppliers

Ransomware gangs find Europe’s weakest link in third-party suppliers 2026-06-26 at 12:49 By Anamarija Pogorelec Ransomware attacks against European organizations increased during the first months of 2026, with third-party suppliers becoming a major entry point for attackers. Black Kite examined 2,066 ransomware incidents across 31 countries between January 2025 and April 2026 in its 2026

Ransomware gangs find Europe’s weakest link in third-party suppliers Read More »

Stealthy new backdoor surfaces in attacks on multiple sectors

Stealthy new backdoor surfaces in attacks on multiple sectors 2026-06-25 at 17:07 By Sinisa Markovic A relatively new backdoor called Mistic has been deployed in multiple attacks since April 2026 targeting organizations in the insurance, education, IT, and professional services sectors, according to Symantec. The malware appears to be associated with Woodgnat, also known as

Stealthy new backdoor surfaces in attacks on multiple sectors Read More »

GentleKiller targets more than 400 security processes across 48 products

GentleKiller targets more than 400 security processes across 48 products 2026-06-18 at 12:00 By Anamarija Pogorelec Most ransomware operations leave the work of disabling endpoint security software to their affiliates. The ransomware-as-a-service gang Gentlemen runs a different model. Its operators develop and maintain a set of tools for shutting down endpoint detection and response (EDR)

GentleKiller targets more than 400 security processes across 48 products Read More »

Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack

Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack 2026-06-17 at 13:38 By Ionut Arghire The attackers deployed a new Go-based backdoor that uses Microsoft Teams servers for command-and-control. The post Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Teams Relay Servers Abused in DragonForce Ransomware Attack Read More »

Cybercriminals mask malicious communications through Microsoft Teams relays

Cybercriminals mask malicious communications through Microsoft Teams relays 2026-06-16 at 17:22 By Sinisa Markovic The DragonForce ransomware group used a custom malware called Backdoor.Turn to hide command-and-control traffic inside Microsoft Teams relay infrastructure during an intrusion at a U.S. services company, according to Symantec. DragonForce is a ransomware-as-a-service operation that has been active since 2023.

Cybercriminals mask malicious communications through Microsoft Teams relays Read More »

Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer

Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer 2026-06-15 at 18:15 By Eduard Kovacs Mackay Sugar was targeted in a cyberattack carried out by a threat group known as The Gentlemen. The post Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer appeared first on SecurityWeek. This article is an excerpt from

Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer Read More »

Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges

Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges 2026-06-15 at 14:33 By Ionut Arghire Oleksii Oleksiyovych Lytvynenko admitted to working on the development of a loader for the Conti gang. The post Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges Read More »

Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks

Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks 2026-06-09 at 13:39 By Ionut Arghire The authentication bypass vulnerability allows attackers to establish VPN connections without a valid password. The post Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks Read More »

Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751)

Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751) 2026-06-08 at 16:16 By Zeljka Zorz A Qilin ransomware affiliate is believed to be exploiting CVE-2026-50751, an authentication bypass vulnerability in Check Point VPN Remote Access and Mobile Access, the company announced on Monday. About CVE-2026-50751 Check Point Remote Access VPN enables and secures connections between

Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751) Read More »

Sophos uncovers AI-powered malware lab built for EDR evasion

Sophos uncovers AI-powered malware lab built for EDR evasion 2026-06-02 at 15:47 By Sinisa Markovic A threat actor used AI technologies to build a malware-testing framework for developing and refining endpoint detection and response (EDR) evasion techniques, according to Sophos. The investigation began after an anomalous endpoint in a customer environment triggered alerts tied to

Sophos uncovers AI-powered malware lab built for EDR evasion Read More »

FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data

FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data 2026-05-27 at 11:46 By Ionut Arghire The FBI has issued an alert warning of Silent Ransom Group attacks targeting law firms. The post FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data appeared first on SecurityWeek. This article

FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data Read More »

Lessons for organizations from the Verizon 2026 Data Breach Investigations Report

Lessons for organizations from the Verizon 2026 Data Breach Investigations Report 2026-05-25 at 08:59 By Help Net Security This is my favourite time of the year, not just because spring is here and the promise of summer is on the way. But also, because one of my must reads each year gets published. There are

Lessons for organizations from the Verizon 2026 Data Breach Investigations Report Read More »

Downtime has become a $600 billion business problem

Downtime has become a $600 billion business problem 2026-05-22 at 11:53 By Anamarija Pogorelec The average cost of downtime has reached $600 billion for the Global 2000, a 50% increase in two years. According to Splunk’s The Hidden Costs of Downtime report, unplanned outages and service degradation cost each company an average of $300 million.

Downtime has become a $600 billion business problem Read More »

The new economics of fraud: Cheaper, faster, more convincing

The new economics of fraud: Cheaper, faster, more convincing 2026-05-22 at 08:29 By Anamarija Pogorelec Scams have become one of the fastest-growing consumer risks, driven by AI-enabled impersonation, social engineering, and sophisticated attack methods, according to Visa’s Spring 2026 Biannual Threats Report. Criminals redirect efforts toward trust and third parties Fraud involves behavioral manipulation, fragmented

The new economics of fraud: Cheaper, faster, more convincing Read More »

Scroll to Top