2026-10-02 18:33 UTC
Security Journalism
BleepingComputer · Ionut Ilascu · indexed 2026-10-02 18:35 UTC
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]
P15
2026-10-02 14:06 UTC
Security Journalism
The Record · indexed 2026-10-02 14:20 UTC
Government services were temporarily disrupted by ransomware in Vicksburg, Mississippi. Mayor Willis Thompson said the FBI and other authorities are investigating.
P15
2026-10-02 14:05 UTC
Security Journalism
The Record · indexed 2026-10-02 14:20 UTC
The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.
P15
2026-10-01 21:37 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-10-01 21:50 UTC
Law enforcement from multiple countries collaborated to disrupt a cybercrime operation that has claimed some 500 victims worldwide in the past two years.
P15
2026-10-01 18:08 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-01 19:00 UTC
Operation KillSwitch: Europol says the KillSec ransomware group, allegedly led by a 16-year-old, was dismantled after attacks on about 1,000 victims. Law enforcement seized control of KillSec ‘s dark web leak site, the Tor website the group used to threaten victims with publishing stolen files unless they paid up. That single action locked down more […]
P15
2026-10-01 16:55 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 17:15 UTC
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site. Investigators identified him as KillSec's suspected
P15
2026-10-01 15:55 UTC
Security Journalism
The Record · indexed 2026-10-01 16:15 UTC
European police said raids against the KillSec ransomware-as-a-service operation included the arrest of a high-profile teen suspect.
P15
2026-10-01 14:25 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-01 14:30 UTC
An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]
P15
2026-10-01 14:17 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-01 14:20 UTC
Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims. The post Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader appeared first on SecurityWeek.
P15
2026-10-01 13:00 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-10-01 13:00 UTC
A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.
P15
2026-09-30 14:16 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-30 15:05 UTC
Higher education faces a difficult security equation. Universities hold large volumes of sensitive student, financial, health, and research data while supporting open networks, distributed users, legacy infrastructure, and increasingly complex cloud environments. Attackers have taken notice, and the pressure on security teams continues to grow.In Q2 2025, universities faced an average of 4,388 cyberattacks per organization per week, up 24% from the same period in 2024. Nine in ten universities …
P40
2026-09-30 07:00 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-09-30 07:15 UTC
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network.
P15
2026-09-29 20:54 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-29 21:50 UTC
Keio, a major Japanese railway operator, was hit by ransomware, disrupting business systems and forcing the company to shut down its network. Keio Corporation, one of Japan’s major private railway operators, was hit by a ransomware attack over the weekend, disrupting some of its business systems. The company detected a system failure early Saturday and […]
P15
2026-09-29 12:27 UTC
Security Journalism
The Record · indexed 2026-09-29 12:45 UTC
A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.
P15
2026-09-28 20:56 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-28 21:05 UTC
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]
P15
2026-09-28 15:49 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-28 15:55 UTC
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...]
P15
2026-09-28 15:08 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-09-28 15:15 UTC
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.
P15
2026-09-28 10:46 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-28 11:00 UTC
Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage in minutes and harvest keys. Microsoft just published the first detailed look at what JADEPUFFER does inside Azure. Sysdig first spotted the group’s activity in July 2026 and called it the first documented agentic ransomware operation. Microsoft tracks the same […]
P15
2026-09-27 15:05 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-27 15:35 UTC
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO ChainScript: Tracing a Node.js RAT […]
P15
2026-09-27 13:40 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-27 14:40 UTC
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. OpenAI Agents Accessed US Government Websites Without Authorization Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem […]
P15
2026-09-27 05:35 UTC
Vendor Research
Tenable Blog · Satnam Narang · indexed 2026-09-27 10:00 UTC
CVE-2026-88771 and CVE-2026-88772, two zero-day vulnerabilities in Citrix NetScaler, have been confirmed as exploited in the wild. Citrix released patches on September 27, 2026.Change logUpdate September 27: Citrix published security bulletin CTX697096, confirming CVE-2026-88771 and CVE-2026-88772 as the two zero-day RCE vulnerabilities and releasing patches. Post updated with CVE IDs, CVSS scores, patch versions, and IoC guidance.Click here to review the change log historyUpdate September 27: …
P95
2026-09-26 14:34 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-26 15:40 UTC
Exploit.in data shows how a 2005 cybercrime forum helped shape today’s ransomware ecosystem, with users and practices surviving for decades. Ransomnews researcher Dancho Danchev dug up a database dump of Exploit.in covering its first three years, from February 2005 to May 2008, and the numbers inside it tell a story about Russian cybercrime that enforcement […]
P15
2026-09-25 20:57 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-25 21:00 UTC
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...]
P15
2026-09-24 16:00 UTC
Vendor Research
Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-24 18:00 UTC
Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment. The post Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments appeared first on Microsoft Security Blog.
P15
2026-09-24 14:44 UTC
Security Journalism
Dark Reading · Arielle Waldman · indexed 2026-09-24 15:45 UTC
This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.
P15
2026-09-24 10:42 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-24 10:45 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. [...]
P15
2026-09-24 08:38 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-24 08:45 UTC
Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims. The post US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks appeared first on SecurityWeek.
P15
2026-09-23 15:30 UTC
Security Journalism
The Record · indexed 2026-09-23 16:15 UTC
An Armenian national and member of the Ryuk ransomware gang was sentenced to two years in federal prison for his role in launching attacks.
P15
2026-09-23 15:30 UTC
Security Journalism
The Record · indexed 2026-09-23 15:45 UTC
An Armenian national and member of the Ryuk ransomware gang was sentenced to two years in federal prison for his role in launching attacks.
P15
2026-09-23 08:20 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-23 08:30 UTC
An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. [...]
P15