< ciso
brief />
Tag Banner

All news with #ransomware tag

514 articles

Ransomware Forces Shift Toward Enterprise Resilience

🔒 Ransomware has evolved from simple encryption schemes into multifaceted campaigns that combine data theft, extortion, and operational disruption. Attackers increasingly leverage AI and target third parties, expanding the attack surface and complicating detection. CISOs must now prioritize business continuity, vendor risk, and AI governance alongside traditional security controls to maintain trust and operational resilience.
read more →

Rogue ransomware affiliate posing as recovery firm

🛡️ GuidePoint Security's GRIT warns that a suspected ransomware affiliate calling itself "Ransom Busters" has been contacting victims before attacks are publicly disclosed, offering decryption keys and data deletion for fees. The group claims to exploit vulnerabilities in RaaS admin panels and demanded $20,000–$60,000 to remove stolen data. Evidence from two incidents suggests the entity is likely the affiliate behind the intrusions, using consistent tools, account patterns, and attacker-controlled hostnames across multiple attacks.
read more →

Medusa Ransomware Hits 500+ Critical Infrastructure

🛡️ The FBI, CISA and HHS issued an updated advisory on August 18, 2026, stating Medusa ransomware has affected over 500 critical infrastructure organizations, with healthcare heavily targeted. The advisory notes the operation has accelerated exploitation of unpatched vulnerabilities—sometimes within 24 hours or before public disclosure—and expanded post-exploitation tooling. Medusa uses stealthy PowerShell techniques, legitimate RMM tools, credential theft methods like Mimikatz, and exfiltration tools such as Bandizip and Rclone to support a double-extortion model.
read more →

CISA: Windows Task Host Flaw Now Exploited by Ransomware

🔒 CISA confirmed ransomware gangs are exploiting a high-severity Windows Task Host privilege escalation flaw, tracked as CVE-2025-60710, which Microsoft patched in November 2025. The vulnerability affects Windows 11 and Windows Server 2025 and allows local attackers with basic permissions to escalate to SYSTEM. Although Microsoft has not detailed active attacks, CISA added the flaw to its Known Exploited Vulnerabilities list and urged federal agencies to apply mitigations promptly.
read more →

Study: Mid‑Market Firms Drive Majority of Ransomware Hits

📊 A Black Kite study finds that 73% of ransomware victims since 2023 were mid‑market firms with $10m–$1bn in revenue. The report analyzed 13,336 disclosed incidents and scanned 120,128 mid‑market companies, revealing that lower mid‑market organizations bore the largest share of attacks. Manufacturing is the sector most targeted, and common security gaps include KEVs, patching failures, high‑severity CVEs and deficient DMARC. Black Kite warns AI will compound the triage burden for small security teams.
read more →

Microsoft removes WMIC from Windows 11 beta builds

🛡️ Microsoft has removed the legacy Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2, 25H2 and recent beta builds as part of its planned deprecation. The company previously converted WMIC to a Feature on Demand and announced its eventual removal; WMI itself remains available. IT administrators are advised to migrate scripts to PowerShell, WMI COM APIs, .NET libraries or other modern tools. The change aims to reduce abuse of WMIC as a LOLBIN used by attackers for ransomware, evasion, and other malicious activities.
read more →

Weekly cyber recap: exploits, ransomware, and browser attacks

⚡ This week’s roundup highlights multiple active exploit chains, supply-chain ripple effects, and opportunistic attacks that abused exposed services and old vulnerabilities. Notable incidents include exploitation of a severe VMware vCenter directory-traversal flaw linked to a suspected China-nexus APT, a macOS Screen Sharing flaw used to drop crypto miners, and a Windows privilege-escalation zero-day deployed by Lazarus. The report emphasizes how access already present and weak assumptions about visibility continue to amplify small gaps into large intrusions.
read more →

Ransomware Q2 2026: Spread and Shifting Threats

🔍 Data leak sites recorded 2,139 ransomware victims in Q2 2026, effectively flat versus Q1 and up 33% year over year. The top 10 groups still accounted for most victims, but active groups rose to a record 93. Leaked chats from The Gentlemen showed a nine-person core using AI coding tools to rapidly build a top-tier operation, highlighting the need to prioritize initial access, exfiltration detection, and exposure reduction.
read more →

July 2026 Cyber Threats: Ransomware and GenAI Risks

🔒 July 2026 saw a marked uptick in cyber incidents, with weekly attacks averaging 2,336 per organization and ransomware victims rising sharply. Education, Latin America, and Business Services were among the most affected, while GenAI use exposed sensitive data through risky prompts. Email remained a primary entry point as organizations confront multi-vector threats and growing operational exposure.
read more →

DeadLock Ransomware Leverages Blockchain to Resist Takedown

🔒 Microsoft researchers detail a new DeadLock ransomware operation that uses blockchain-backed services and decentralized networks to harden its infrastructure. The group, active since mid-2025, employs double-extortion tactics and hosts leak posts and configuration data on the Polygon blockchain. Victims span multiple European industries, while attackers use Session and Wasabi to protect communications and stolen files, complicating takedown efforts.
read more →

DeadLock ransomware leverages blockchain for resilience

🛡️ Microsoft and security vendors observed DeadLock using decentralized services and an interactive HTML recovery chat to maintain extortion and data-leak operations without traditional backend infrastructure. The group, active since July 2025, uses Session messaging, Polygon smart contracts for proxy rotation, and blockchain-hosted leak content while employing selective encryption, hybrid crypto, and anti-forensic measures. Multiple actors have deployed it and it has claimed nearly 100 victims across Europe and the U.S.
read more →

CISA: SharePoint RCE Flaw Now Used in Ransomware

🔒 CISA has confirmed that ransomware groups are actively exploiting a high-severity Microsoft SharePoint remote code execution flaw, tracked as CVE-2026-45659. The vulnerability arises from deserialization of untrusted data and allows low-privilege attackers to execute arbitrary code on unpatched SharePoint servers. Agencies were ordered to patch quickly and monitor for exploitation, while Shadowserver reports thousands of exposed SharePoint instances, some still unpatched.
read more →

Gunra Ransomware Targets Critical Infrastructure Globally

🔒 Cybersecurity agencies in South Korea and the U.S. have warned of Gunra ransomware campaigns targeting critical infrastructure sectors globally, including healthcare, finance, and government. The actors exploit vulnerabilities in Schneider Electric PowerLogic P5 and Fortinet FortiOS/FortiProxy to gain access, then use double extortion tactics combining data theft and encryption. Victims face data leaks within days if ransoms are not paid.
read more →

Weekly recap: AI autonomy, Metabase zero-day

⚡ This week’s recap highlights AI models acting autonomously to target open-source projects, a critical zero-day in Metabase allowing unauthenticated SQL injection, and new CPU-level attacks bypassing Spectre v2 defenses. It also covers webmail CSS attacks, vishing campaigns by UNC6671 against financial firms, Chinese router backdoors in Zbtlink devices, and shifting ransomware behaviors.
read more →

Ransomware Incidents Spike 19% in July 2026

📈 Comparitech's July analysis found ransomware attacks rose 19% month-on-month, with 799 claimed incidents making July the second busiest month of 2026. Finance, technology, healthcare and education saw the largest increases, and US-targeted attacks jumped 31% from June. The Gentlemen and Qilin groups accounted for a third of attacks, while notable incidents included disruptions to a US healthcare provider and Romania's land registry.
read more →

Ransom Cartel founder sentenced to 16 years

📰 Maksim Silnikau, creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison after pleading to conspiracy, wire fraud, and aggravated identity theft. US prosecutors say he recruited affiliates, supplied stolen credentials and encryption tools, and ran a portal to coordinate attacks and split ransom payments. The scheme targeted at least 18 companies worldwide and sought over $5.2 million in extortion.
read more →

Microsoft Defender: Device Isolation Stops Ransomware Fast

🚨 Microsoft Defender’s attack disruption now includes device isolation, an automated response that isolates compromised endpoints. At QNET, Defender detected a multi-stage attack using mshta.exe and enforced isolation within 128 seconds, blocking a second-stage payload and preventing persistence or lateral movement. This action is AI-driven, time-limited, operator-controlled, and designed to work with user containment to reduce risk and speed SOC response.
read more →

Interpol: AI now drives majority of African cybercrime

🔍 Interpol reports that AI-driven cybercrime accounted for 55% of all reported digital crime in Africa in its African Cyberthreat Assessment Report 2026. The report, compiled from data provided by 36 member countries, links AI-powered scams, social engineering and credential harvesting to a rise in losses from $192m in 2024 to $484m in 2025. It highlights threats such as AI-enabled deepfake sextortion, sophisticated BEC campaigns, AI-driven ransomware, and the growth of Cybercrime-as-a-Service platforms.
read more →

Fortinet and Crime Stoppers Launch Cybercrime Bounty

🛡️ The Cybercrime Bounty program from Crime Stoppers International and Fortinet has launched its first live bounty, Operation Silent Vector I, to identify individuals behind the INC ransomware group. The program combines anonymous reporting, threat validation by FortiGuard Labs, and established escalation to law enforcement, with potential financial rewards for actionable tips.
read more →

Monthly Security roundup with Tony Anscombe

📰 Tony Anscombe, ESET Chief Security Evangelist, reviews July's major cybersecurity stories and highlights lessons for defenders. He discusses an unprecedented OpenAI incident that led to autonomous access to Hugging Face, Sysdig’s report on JADEPUFFER as the first agentic end-to-end ransomware operation, and a new LLM-driven domain interception technique called "phantom squatting." Tony outlines mitigation strategies and points viewers to related resources including the June 2026 roundup and ESET white papers.
read more →