Tag

Ransomware

All articles tagged with #ransomware

AI-Driven Threats Blur the Line Between Daily Activity and Breach
technology5 hours ago

AI-Driven Threats Blur the Line Between Daily Activity and Breach

ThreatsDay flags AI-enhanced threats accelerating breaches and blurring into everyday activity: Kali Linux now integrates Claude via MCP for natural-language command execution; campaigns include Bitpanda phishing, four-minute lateral movement, and Mac/WinRAR exploits, aided by ad cloaking, typosquatting, and social engineering, as threat actors fragment post-RAMP and increasingly use AI-driven tactics.

BeyondTrust Flaw Sparks Global Web Shell Campaigns and Data Theft
security7 days ago

BeyondTrust Flaw Sparks Global Web Shell Campaigns and Data Theft

Threat actors are exploiting CVE-2026-1731 in BeyondTrust RS/PRA to run OS commands, deploy web shells and backdoors, establish C2, and exfiltrate data across sectors worldwide. Unit 42 reports use of a thin-scc-wrapper via WebSocket to execute commands in the site user context, effectively taking control of appliances and traffic. Campaigns include PHP backdoors, VShell, a bash dropper, and Spark RAT, with staged exfiltration of config files, internal databases, and PostgreSQL dumps. The activity aligns with prior CVE-2024-12356 issues, and CISA KEV confirms exploitation in ransomware operations.

BridgePay ransomware outage cripples payment gateway; no card data exposed
technology19 days ago

BridgePay ransomware outage cripples payment gateway; no card data exposed

BridgePay Network Solutions suffered a ransomware attack that disabled its payment gateway in a nationwide outage; officials say no payment card data was compromised and any accessed files were encrypted, with the FBI and U.S. Secret Service assisting in the investigation as recovery continues, while some merchants report cash-only transactions amid the disruption.

Week in Cybersecurity: Proxy Botnet Disrupted, Office Zero-Day Patched, MongoDB Extortion Surges
cybersecurity25 days ago

Week in Cybersecurity: Proxy Botnet Disrupted, Office Zero-Day Patched, MongoDB Extortion Surges

This weekly cybersecurity digest flags a busy threat landscape: Google disrupted the IPIDEA residential proxy network, shrinking attackers’ exit nodes; Microsoft patched a critical Office zero-day (CVE-2026-21509) and Ivanti fixed EPMM flaws (CVE-2026-1281/1340); CERT Polska linked destructive attacks on wind/solar facilities to Static Tundra; new campaigns include Operation Bizarre Bazaar targeting exposed AI endpoints and a surge of MongoDB extortion against over 1,400 exposed databases; other notes cover Exfil Out&Look via Outlook add-ins, PyRAT’s cross‑platform capabilities, TA584’s evolving attack chain with Tsundere Bot and XWorm, and related cybercrime trends.

WinRAR CVE-2025-8088 Seized by State and Criminal Actors After Patch
technology29 days ago

WinRAR CVE-2025-8088 Seized by State and Criminal Actors After Patch

Google’s Threat Intelligence Group reports active exploitation of WinRAR CVE-2025-8088 by both state-backed and financially motivated actors, even after a patch (WinRAR 7.13, July 30, 2025). The flaw is used for initial access via a path-traversal method that drops a malicious LNK in the Windows Startup folder/ADS, with campaigns tied to RomCom/UNC4895, UNC2596 (Cuba ransomware), Sandworm, Gamaredon, Turla, and a China-based actor delivering Poison Ivy, deploying payloads such as SnipBot, AsyncRAT, and XWorm and even browser extensions for Brazilian banking sites. The widespread activity underscores an active underground market for exploits and persistent defense gaps, with a separate flaw CVE-2025-6218 also being exploited by multiple groups.

AI-Driven Threats Set to Redefine Cybercrime in 2026
technology1 month ago

AI-Driven Threats Set to Redefine Cybercrime in 2026

ZDNET reports that 2026 could see AI weaponization reach a new level, with threat actors deploying AI-enabled malware and agentic AI to automate reconnaissance, phishing, lateral movement, and data theft at machine speed, while prompt injection and misconfigurations expand attack surfaces via APIs and AI-enabled browsers. Attacks will target IT and OT, with ransomware evolving into data extortion across supply chains, insiders and North Korean operators widening campaigns, and nation-states pursuing longer-term strategic objectives. CISOs will be held more accountable and cyber-resilience will become a competitive differentiator, driving upskilling and greater use of managed security services.

US Cybersecurity Experts Admit to Ransomware Crimes and Face Prison
crime1 month ago

US Cybersecurity Experts Admit to Ransomware Crimes and Face Prison

Two cybersecurity professionals pleaded guilty to running ransomware attacks using their skills to extort victims, including a medical device company that paid $1.2 million, with plans for sentencing in March. They were involved with the ALPHV BlackCat ransomware group, known for major attacks like on Change Healthcare, and face potential 20-year sentences.

Holiday Cybersecurity Risks: Protecting Travelers and Shoppers from Cyberattacks
technology2 months ago

Holiday Cybersecurity Risks: Protecting Travelers and Shoppers from Cyberattacks

Hackers exploit the holiday season when security teams are reduced and companies are less vigilant, leading to a spike in cyberattacks like ransomware and phishing, with many high-profile incidents occurring during this period. Security teams prepare months in advance, and AI tools are suggested to help mitigate burnout and improve defenses during this vulnerable time.

Interpol Arrests Nearly 600 Cybercriminals Across Africa in Major Operation
world2 months ago

Interpol Arrests Nearly 600 Cybercriminals Across Africa in Major Operation

INTERPOL's Operation Sentinel led to the arrest of 574 suspects across 19 African countries, recovering $3 million and dismantling cybercrime networks involved in BEC, digital extortion, and ransomware, with estimated losses over $21 million. Additionally, a Ukrainian national pleaded guilty in the U.S. for Nefilim ransomware activities, highlighting ongoing international cybercrime efforts.

Security Risks in VS Code Extensions: Ransomware, Cryptomining, and Supply Chain Threats
cybersecurity3 months ago

Security Risks in VS Code Extensions: Ransomware, Cryptomining, and Supply Chain Threats

Cybersecurity researchers discovered a vibe-coded malicious VS Code extension with built-in ransomware capabilities, which exfiltrates and encrypts files, and uses GitHub as a command-and-control server. Additionally, 17 npm packages disguised as SDKs were found to stealthily deploy Vidar Stealer, highlighting ongoing supply chain threats in open-source ecosystems. Microsoft has removed the malicious extension from the marketplace, emphasizing the importance of vigilance in software development.

AI-Driven Ransomware Threats Emerge in VS Code Extensions
technology3 months ago

AI-Driven Ransomware Threats Emerge in VS Code Extensions

A malicious VS Code extension named susvsex, created with AI assistance and advertising ransomware capabilities, was published on Microsoft's marketplace. Despite being reported for its malicious functions, Microsoft did not remove it. The extension encrypts files and exfiltrates data to a remote server, and uses hardcoded credentials to communicate with a command-and-control server. The incident raises concerns about vetting processes for extensions and the potential misuse of AI in malicious software development.

Volkswagen Faces Ransomware Attack and Data Leak Allegations
technology4 months ago

Volkswagen Faces Ransomware Attack and Data Leak Allegations

Volkswagen is suspected to have been targeted by the ransomware group 8Base, which claims to have stolen and leaked sensitive data, including employee and financial information, though the company states its core IT remains unaffected. The incident highlights ongoing cybersecurity threats to major industries and the importance of third-party risk management.

Asahi Ransomware Attack Threatens Personal Data and Beer Production
technology4 months ago

Asahi Ransomware Attack Threatens Personal Data and Beer Production

Asahi, Japan's largest brewer, was hit by a ransomware attack that disrupted operations and potentially led to the theft of personal data. The company is investigating the extent of the breach, working with cybersecurity experts, and has temporarily delayed its financial reporting. The attack was claimed by the Russia-based group Qilin, highlighting the increasing frequency of major cyber-attacks on global companies.