§Topic · Ransomware
Ransomware
Ransomware gangs, double-extortion campaigns, decryptors, and the incidents shaping today's ransomware landscape.
All dispatches
Loading
§Topic · Ransomware
Ransomware gangs, double-extortion campaigns, decryptors, and the incidents shaping today's ransomware landscape.
All dispatchesATF confirms a system compromise linked to Qilin ransomware claims affecting investigation-related data access.
Investigation reveals Clop likely exploited critical PTC Windchill vulnerability in June, initiating extended extortion and data theft.
Clop-associated web shell on PTC Windchill/FlexPLM decrypts credentials and maps PLM engineering vault data for extortion.
FBI warns Medusa Ransomware affiliates breached over 500 critical infrastructure orgs via improved RaaS tactics and tools.
Clop gang developed a Java web shell tailored for PTC Windchill and FlexPLM to decrypt credentials and exfiltrate files.
CISA confirms ransomware groups are exploiting a high-severity Windows Task Host vulnerability previously flagged as actively exploited.
Updated FBI/CISA/HHS advisory details Medusa techniques: disabling security, exfiltrating data, and encrypting whole networks.
China-linked Storm-1175 deploys StormEncryptor ransomware, likely exploiting an N-able N-central vulnerability to gain initial access.
Microsoft warns China-linked actors are exploiting a critical flaw in N-able to deploy ransomware broadly as a launchpad.
Ransomware group claims 6 TB exfiltration and hijacks a hospital's Facebook page, exposing highly sensitive patient data categories.
CISA confirms active exploitation of a high-severity Microsoft SharePoint RCE now used in ransomware intrusions and lateral movement.
US and South Korean agencies warn of Gunra exploiting firewall and VPN flaws to hit government and critical infrastructure.
Get these articles delivered to your inbox.
Subscribe free