< ciso
brief />
Tag Banner

All news with #ransomware tag

541 articles · page 2 of 28

ThreatsDay roundup: phishing kits, AI risks, breaches

🛡️ This ThreatsDay bulletin surveys recent campaigns exploiting trusted tools and social engineering, from Microsoft Teams vishing to resilient phishing-as-a-service kits. It highlights ransomware affiliate playbooks, signed-software sideloading, a large ID-theft marketplace, and supply-chain risks tied to llms.txt misconfigurations. The report also notes Dropbox disclosed ~5,000 account compromises linked to legacy Lenovo IDs.
read more →

AI agents compress ransomware intrusion timelines

🛡️ Palo Alto Networks’ Unit 42 found an attacker using AI agents to traverse an enterprise network in under 10 hours, a process that could have taken human operators about two weeks. Agents conducted automated reconnaissance, searched code repositories for credentials, accessed secrets-management systems, and leveraged stolen cloud keys to abuse the victim’s AI services. The intrusion combined familiar MITRE ATT&CK techniques with agentic orchestration, highlighting the need for faster containment and stronger controls over non-human identities.
read more →

AI-Assisted Ransomware: Rapid Agentic Intrusion

🛡️ Unit 42 investigated an incident where a human operator used frontier AI agents to autonomously breach an enterprise network and execute a ransomware-style operation. The attack compressed weeks of tradecraft into under 10 hours by orchestrating >50 MITRE ATT&CK techniques via parallel LLM calls, structured agent communication, and AI-generated scripts. Agents performed reconnaissance, secrets harvesting, privilege takeover, CI/CD abuse, and hijacking of cloud AI endpoints to sustain post-compromise operations.
read more →

Aurora ransomware actors leveraging AI coding tools

🛡️ Threat actors tied to the Aurora (Aur0ra) ransomware have been observed using AI coding assistants like Cursor to plan and execute intrusions, according to CloudSEK and Gambit Security. Exposed infrastructure revealed months of activity targeting organizations across multiple countries between April and July 2026, with both Windows and Linux encryptors written in Zig. The attack chain includes credential theft, lateral movement, AD CS exploitation, and disabling recovery mechanisms before encryption. Investigators also identified affiliate payout splits and evidence of agentic use of Anthropic's Claude Sonnet for hands-on exploitation tasks.
read more →

Berlin Rejects Ransom After Major State Network Breach

🔒 Berlin's state government confirmed an extortion attempt after its state administrative network was compromised in August and said it will not pay the attackers. Forensics found further data exfiltration from the Senate Department for Mobility, Transport, Climate Protection and Environment between August 7 and 12, 2026, and the scope may include personal or non-public records. Authorities, including state police, the public prosecutor and federal security agencies, are investigating while the Senate continues forensic work and coordination with data protection and security bodies.
read more →

ATF Confirms Major Security Incident After Qilin Claim

🔒 The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a breach of a standalone system after the Qilin ransomware gang added the agency to its dark web leak portal. The ATF says the compromised system is separate from its enterprise network and critical systems, and it immediately terminated connections and launched an incident-response and forensic investigation with the Department of Justice. The agency reported no operational impact and requested public tips while the investigation continues.
read more →

Boston Scientific hit by cyberattack disrupting operations

🔒 Boston Scientific reported a cyberattack detected on August 25 that disrupted IT systems and caused global operational impacts, including difficulties processing and shipping customer orders. The company activated its incident response plan and engaged external cybersecurity experts to investigate and contain the intrusion. Boston Scientific said it does not yet know when all affected systems will be fully restored and continues to assess the scope and consequences of the incident. The SEC filing offered no details on the attacker, initial access, or whether data was exposed.
read more →

Ransomware Forces Shift Toward Enterprise Resilience

🔒 Ransomware has evolved from simple encryption schemes into multifaceted campaigns that combine data theft, extortion, and operational disruption. Attackers increasingly leverage AI and target third parties, expanding the attack surface and complicating detection. CISOs must now prioritize business continuity, vendor risk, and AI governance alongside traditional security controls to maintain trust and operational resilience.
read more →

Rogue ransomware affiliate posing as recovery firm

🛡️ GuidePoint Security's GRIT warns that a suspected ransomware affiliate calling itself "Ransom Busters" has been contacting victims before attacks are publicly disclosed, offering decryption keys and data deletion for fees. The group claims to exploit vulnerabilities in RaaS admin panels and demanded $20,000–$60,000 to remove stolen data. Evidence from two incidents suggests the entity is likely the affiliate behind the intrusions, using consistent tools, account patterns, and attacker-controlled hostnames across multiple attacks.
read more →

Medusa Ransomware Hits 500+ Critical Infrastructure

🛡️ The FBI, CISA and HHS issued an updated advisory on August 18, 2026, stating Medusa ransomware has affected over 500 critical infrastructure organizations, with healthcare heavily targeted. The advisory notes the operation has accelerated exploitation of unpatched vulnerabilities—sometimes within 24 hours or before public disclosure—and expanded post-exploitation tooling. Medusa uses stealthy PowerShell techniques, legitimate RMM tools, credential theft methods like Mimikatz, and exfiltration tools such as Bandizip and Rclone to support a double-extortion model.
read more →

CISA: Windows Task Host Flaw Now Exploited by Ransomware

🔒 CISA confirmed ransomware gangs are exploiting a high-severity Windows Task Host privilege escalation flaw, tracked as CVE-2025-60710, which Microsoft patched in November 2025. The vulnerability affects Windows 11 and Windows Server 2025 and allows local attackers with basic permissions to escalate to SYSTEM. Although Microsoft has not detailed active attacks, CISA added the flaw to its Known Exploited Vulnerabilities list and urged federal agencies to apply mitigations promptly.
read more →

Study: Mid‑Market Firms Drive Majority of Ransomware Hits

📊 A Black Kite study finds that 73% of ransomware victims since 2023 were mid‑market firms with $10m–$1bn in revenue. The report analyzed 13,336 disclosed incidents and scanned 120,128 mid‑market companies, revealing that lower mid‑market organizations bore the largest share of attacks. Manufacturing is the sector most targeted, and common security gaps include KEVs, patching failures, high‑severity CVEs and deficient DMARC. Black Kite warns AI will compound the triage burden for small security teams.
read more →

Microsoft removes WMIC from Windows 11 beta builds

🛡️ Microsoft has removed the legacy Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2, 25H2 and recent beta builds as part of its planned deprecation. The company previously converted WMIC to a Feature on Demand and announced its eventual removal; WMI itself remains available. IT administrators are advised to migrate scripts to PowerShell, WMI COM APIs, .NET libraries or other modern tools. The change aims to reduce abuse of WMIC as a LOLBIN used by attackers for ransomware, evasion, and other malicious activities.
read more →

Weekly cyber recap: exploits, ransomware, and browser attacks

⚡ This week’s roundup highlights multiple active exploit chains, supply-chain ripple effects, and opportunistic attacks that abused exposed services and old vulnerabilities. Notable incidents include exploitation of a severe VMware vCenter directory-traversal flaw linked to a suspected China-nexus APT, a macOS Screen Sharing flaw used to drop crypto miners, and a Windows privilege-escalation zero-day deployed by Lazarus. The report emphasizes how access already present and weak assumptions about visibility continue to amplify small gaps into large intrusions.
read more →

Ransomware Q2 2026: Spread and Shifting Threats

🔍 Data leak sites recorded 2,139 ransomware victims in Q2 2026, effectively flat versus Q1 and up 33% year over year. The top 10 groups still accounted for most victims, but active groups rose to a record 93. Leaked chats from The Gentlemen showed a nine-person core using AI coding tools to rapidly build a top-tier operation, highlighting the need to prioritize initial access, exfiltration detection, and exposure reduction.
read more →

July 2026 Cyber Threats: Ransomware and GenAI Risks

🔒 July 2026 saw a marked uptick in cyber incidents, with weekly attacks averaging 2,336 per organization and ransomware victims rising sharply. Education, Latin America, and Business Services were among the most affected, while GenAI use exposed sensitive data through risky prompts. Email remained a primary entry point as organizations confront multi-vector threats and growing operational exposure.
read more →

DeadLock Ransomware Leverages Blockchain to Resist Takedown

🔒 Microsoft researchers detail a new DeadLock ransomware operation that uses blockchain-backed services and decentralized networks to harden its infrastructure. The group, active since mid-2025, employs double-extortion tactics and hosts leak posts and configuration data on the Polygon blockchain. Victims span multiple European industries, while attackers use Session and Wasabi to protect communications and stolen files, complicating takedown efforts.
read more →

DeadLock ransomware leverages blockchain for resilience

🛡️ Microsoft and security vendors observed DeadLock using decentralized services and an interactive HTML recovery chat to maintain extortion and data-leak operations without traditional backend infrastructure. The group, active since July 2025, uses Session messaging, Polygon smart contracts for proxy rotation, and blockchain-hosted leak content while employing selective encryption, hybrid crypto, and anti-forensic measures. Multiple actors have deployed it and it has claimed nearly 100 victims across Europe and the U.S.
read more →

CISA: SharePoint RCE Flaw Now Used in Ransomware

🔒 CISA has confirmed that ransomware groups are actively exploiting a high-severity Microsoft SharePoint remote code execution flaw, tracked as CVE-2026-45659. The vulnerability arises from deserialization of untrusted data and allows low-privilege attackers to execute arbitrary code on unpatched SharePoint servers. Agencies were ordered to patch quickly and monitor for exploitation, while Shadowserver reports thousands of exposed SharePoint instances, some still unpatched.
read more →

Gunra Ransomware Targets Critical Infrastructure Globally

🔒 Cybersecurity agencies in South Korea and the U.S. have warned of Gunra ransomware campaigns targeting critical infrastructure sectors globally, including healthcare, finance, and government. The actors exploit vulnerabilities in Schneider Electric PowerLogic P5 and Fortinet FortiOS/FortiProxy to gain access, then use double extortion tactics combining data theft and encryption. Victims face data leaks within days if ransoms are not paid.
read more →