2026-04-16 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Francis deSouza · indexed 2026-08-15 18:55 UTC
Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As we harden existing software with AI, threat actors will use it to discover and exploit novel vulne…
P60
2026-04-15 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-08-15 18:55 UTC
Written by: Jamie Collier, Robin Grunewald Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previously observed in the country during 2022 and 2023. Cyber Criminals Pivoting Back to Germany Germany mo…
P15
2026-04-08 11:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
The Stryker incident revealed that a "Weaponized Remote Wipe" via compromised MDM is a more permanent and difficult threat than ransomware. Learn concrete steps to secure management platforms and prevent your security shield from becoming a weapon.
P15
2026-04-07 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A recent incident linked to the NightSpire ransomware workflow gives insight into why the RaaS structure and model, or lack thereof, are important – especially when it comes to scoping and recovering from the incident.
P15
2026-03-23 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Explore the latest manufacturing cybersecurity trends, from ransomware to OT takeovers, and real-world risks to production. Learn how to secure your plant.
P15
2026-03-16 12:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover how the 3-2-1 backup rule strengthens your backup strategy against ransomware. Plus, learn how to implement cloud backup best practices with ease.
P15
2026-03-13 07:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Get an insider look at how the Huntress SOC stopped an unsecured VPN based ransomware attack. Learn why your business needs more than just software to stay secure.
P15
2026-03-03 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn about the narrowing threat gap, the rise of cross-platform attacks (like WSL abuse), and the specific ransomware and nation-state actors targeting Linux endpoints in 2026.
P15
2026-02-12 10:00 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
When corporate data is exposed on a dedicated leak site, the consequences linger long after the attack fades from the news cycle
P15
2026-02-11 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress uncovers ransomware operations abusing employee monitoring software and SimpleHelp RMM for persistence, and ransomware deployment.
P15
2026-01-15 06:07 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog uncovers DeadLock’s stealthy usage of Polygon smart contracts for proxy address storage, a poorly-documented and under-reported technique that Group-IB analysts have observed increased usage in the wild. Variants of this technique are very wide and offer great alternatives to threat actors for bypassing traditional defenses by abusing decentralized blockchains available worldwide.
P35
2025-12-11 16:04 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Being seen as reliable is good for ‘business’ and ransomware groups care about 'brand reputation' just as much as their victims
P15
2025-12-08 06:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Hypervisors are a major target for ransomware attacks. Get expert guidance from Huntress on how to protect your virtualized infrastructure. Learn how to secure access, put runtime controls in place, simplify patching, and improve your recovery plans.
P15
2025-11-28 13:46 UTC
Other
ESET · indexed 2026-09-07 17:30 UTC
Data exposure by top AI companies, the Akira ransomware haul, Operation Endgame against major malware families, and more of this month's cybersecurity news
P15
2025-11-13 06:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors are targeting the education sector with data breaches, phishing emails, ransomware hits, brute force RDP attacks, and more.
P15
2025-11-05 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Gootloader returns with new obfuscation techniques, including custom WOFF2 fonts and updated persistence mechanisms, while continuing its partnership with Vanilla Tempest for ransomware deployment. Dive in and discover what Huntress is seeing.
P15
2025-10-22 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Incident analysis is critical, but for newcomers, it can be daunting. Learn how to confirm commands, validate findings, and spot real impact during a Qilin ransomware event.
P15
2025-10-16 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress analyzes ransomware activity, uncovering attack patterns and key detection opportunities while dispelling ransomware myths.
P15
2025-10-15 07:37 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Group-IB’s Suspicious Payment Details module for Threat Intelligence delivers payment identifiers tied to ransomware, illegal casinos, and laundering schemes. Fraud, AML, and compliance teams can now stop money from reaching criminal infrastructure.
P15
2025-09-02 19:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress found a previously unseen ransomware variant called Obscura on a victim company’s domain controller.
P15
2025-08-21 21:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
In mid-August, Huntress saw two incidents that linked back to a ransomware variant called Cephalus, which included DLL sideloading via a legitimate SentinelOne executable.
P15
2025-08-19 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Threat actors often steal data during the course of their attacks. This is particularly true for ransomware threat actors, who do it before deploying file encryption in order to engage in “double extortion” activities. This activity can be difficult to detect, particularly if it’s not dissimilar to legitimate actions taken by system administrators.
P15
2025-08-14 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Thanks in large part to our customer base, Huntress sees a great deal of interesting activity, particularly from threat actors (but also from admins). Part of that activity includes not just ransomware variants that Huntress hasn’t seen before, but also variants that may not have been documented via any public means. Further, when these incidents occur, Huntress very often gets a detailed look at the threat actor’s activity, including commands and their timing.
P15
2025-08-13 22:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
A likely zero-day vulnerability in SonicWall VPNs is being actively exploited to bypass MFA and deploy ransomware. Huntress advises disabling the VPN service immediately or severely restricting access via IP allow-listing. We're seeing threat actors pivot directly to domain controllers within hours of the initial breach.
P40
2025-07-31 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
When a clearly commented script revealed an attacker's tactics, Huntress prevented encryption. Read on to learn more about the evolution of recycled ransomware playbooks used by multiple threat actors.
P15
2025-07-18 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress has observed a new ransomware variant, Crux, being used in multiple incidents.
P15
2025-05-15 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Break down how a ransomware attack works. Why ransomware is on the side, and how Huntress helps you stay protected.
P15
2025-05-13 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
During ransomware attacks, the average time-to-ransom for attackers is almost 17 hours. Learn more about what this means for businesses.
P15
2025-04-30 06:00 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
This blog on RansomHub provides an overview into how this Ransomware-as-a-Service (RaaS) group operates, including its extortion tactics, affiliate recruitment strategies, and the features of its affiliate panel.
P15
2025-04-10 05:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Discover how a seemingly simple brute force attack led to the uncovering of a suspected ransomware-as-a-service operation. This ecosystem appears to be leveraged by initial access brokers, driving an illicit and complex network of cybercrime.
P15