2026-09-21 14:00 UTC
Security Journalism
The Record · indexed 2026-09-21 14:15 UTC
The ShinyHunters extortion group hijacked the dark web leak site of the prolific Cl0p ransomware gang, according to material posted on the site over the weekend.
P15
2026-09-21 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-22 07:50 UTC
Huntress analysts reconstructed a three-week INC ransomware attack from endpoint data, uncovering a 17-day lull despite missing process telemetry.
P15
2026-09-19 13:48 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-19 14:00 UTC
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]
P15
2026-09-18 14:25 UTC
Security Journalism
Security Week · SecurityWeek News · indexed 2026-09-18 14:30 UTC
Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek.
P15
2026-09-17 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-22 07:50 UTC
Huntress has recently seen two incidents involving Settra, a ransomware variant that was first publicly reported in June 2026.
P15
2026-09-17 12:29 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-17 12:30 UTC
Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek.
P15
2026-09-17 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Takahiro Takeda · indexed 2026-09-17 10:15 UTC
Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.
P15
2026-09-16 15:27 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 16:25 UTC
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
P15
2026-09-16 14:00 UTC
Security Journalism
BleepingComputer · Sponsored by Datto · indexed 2026-09-16 14:20 UTC
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. [...]
P15
2026-09-15 12:16 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-15 12:30 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. [...]
P15
2026-09-14 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-14 19:45 UTC
Attackers exploit Volume Shadow Copy for credential theft and ransomware defense evasion. See how Huntress spots the difference from routine IT activity.
P15
2026-09-13 09:19 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-13 10:15 UTC
Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced the 44-year-old to four years in prison this week for conspiracy […]
P15
2026-09-11 12:00 UTC
Security Journalism
The Record · indexed 2026-09-11 12:10 UTC
A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022.
P15
2026-09-11 11:29 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-11 11:35 UTC
Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023. The post Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison appeared first on SecurityWeek.
P15
2026-09-11 10:14 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-11 10:55 UTC
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls, run […]
P30
2026-09-11 06:48 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-11 06:55 UTC
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]
P15
2026-09-11 06:19 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 07:40 UTC
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass
P30
2026-09-10 21:40 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-10 21:45 UTC
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...]
P15
2026-09-10 15:43 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-10 15:55 UTC
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]
P15
2026-09-10 09:10 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-10 09:30 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. [...]
P40
2026-09-09 15:31 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-09 15:35 UTC
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]
P15
2026-09-09 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-11 16:45 UTC
Threat actors are exploiting GTA6 hype with fake leaked downloads spread via SEO poisoning, packed with RATs, infostealers, and wiper ransomware. Here’s what Huntress found.
P15
2026-09-08 21:44 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-09 00:10 UTC
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will e…
P65
2026-09-08 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC
Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…
P35
2026-09-08 03:30 UTC
Other
Group-IB · indexed 2026-09-08 03:50 UTC
Group-IB's 2026 data shows ransomware accelerating across APAC. See where response plans fail, and the 5-pillar framework built to hold under pressure.
P15
2026-09-07 07:19 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-07 08:30 UTC
Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out […]
P15
2026-09-03 21:15 UTC
Vendor Research
AWS Security Blog · Oscar Diaz · indexed 2026-09-03 21:35 UTC
In Part 1 of this guide, we examined two common incident scenarios: cross-account Amazon Simple Storage Service (Amazon S3) data deletion with ransomware implications, and cryptocurrency mining deployed through AWS CloudFormation using exposed AWS Management Console credentials. We also introduced key incident response terminology and investigative frameworks for analyzing AWS CloudTrail events. In this second […]
P15
2026-09-02 15:07 UTC
Security Journalism
The Record · indexed 2026-09-02 15:15 UTC
The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week.
P15
2026-09-02 14:02 UTC
Security Journalism
BleepingComputer · Sponsored by Acronis · indexed 2026-09-02 14:15 UTC
Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]
P15
2026-09-01 21:03 UTC
Security Journalism
Dark Reading · Arielle Waldman · indexed 2026-09-01 21:05 UTC
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.
P15