Advertisement
Germany Doxes UNKN: Identity of REvil and GandCrab Leader Revealed
German authorities identify Daniil Maksimovich Shchukin as UNKN, the lead operator behind the notorious GandCrab and REvil ransomware operations.
Multi-Extortion Ransomware Tactics: A Deeper Dive
Analyze the evolution of multi-extortion ransomware, its reliance on data leaks, and strategies for mitigating the impact of exfiltrated data.
BRICKSTORM Malware: Hardening vSphere & VCSA Against Advanced Threats
Defend VMware vSphere and VCSA against BRICKSTORM malware. Learn hardening strategies, identity management, Zero Trust networking, and advanced logging to thwart…
Ransomware Preparation: Healthcare Facilities' Defense Strategy
Hospitals face inevitable ransomware attacks. Learn why proactive incident response planning, regular rehearsals, and robust technical controls are crucial for defense.
Cyberattacks Target Latin American Government and Health Sectors
Recent disruptive cyberattacks and ransomware probes are targeting government infrastructure and health services across Latin America and the Caribbean.
TeamPCP Supply Chain Campaign: First Victim, Cloud Enumeration, Ransomware
Detailed analysis of TeamPCP supply chain campaign, covering the first confirmed victim, post-compromise cloud enumeration tactics, and dual ransomware operations.
Advertisement
Bearlyfy Targets 70+ Russian Firms with Custom GenieLocker Ransomware
Pro-Ukrainian group Bearlyfy deploys GenieLocker ransomware in a campaign targeting over 70 Russian organizations to cause maximum business disruption.
Silnikau Sentenced: BitPaymer Ransomware Botnet Operator Receives 2 Years
Russian national Maksim Silnikau sentenced for managing a botnet used in BitPaymer ransomware attacks targeting 72 U.S. companies and demanding $100 million.
TA551 Botnet Operator Sentenced: Analyzing Shathak Ransomware Tactics
Russian national Ilya Angelov sentenced for managing the TA551 botnet, a major facilitator of ransomware attacks via sophisticated phishing campaigns.
U.S. Sentences Yanluowang Ransomware Facilitator Aleksei Volkov
Russian national Aleksei Volkov sentenced to 81 months for facilitating Yanluowang ransomware attacks, causing $9M in damages to U.S. organizations.
M-Trends 2026: Evolving Ransomware, Persistence, and SaaS Attack Vectors
M-Trends 2026 reveals critical shifts in adversary TTPs: destructive ransomware, zero-day exploitation for persistence, and voice phishing for SaaS access.
Mandiant M-Trends 2026: Handoff Time Shrinks to 22 Seconds
Mandiant's M-Trends 2026 report reveals a drastic reduction in initial access handoff times to 22 seconds, demanding faster detection and response.
Iranian Handala Group Leverages Telegram for Malware Delivery and C2
FBI alerts organizations to Handala, an Iranian MOIS-linked group using Telegram APIs for data exfiltration, ransomware, and wiper attacks across sectors.
Beast Gang OpSec Fail: Ransomware Server Exposes TTPs
Beast Gang's OpSec failure exposes their cloud ransomware server, revealing aggressive tactics against network backups. Defenders gain insight into their TTPs.
Android Security Safeguards and UK Cyber Reporting Mandates
Analysis of new Android live threat detection features, the Operation Alice takedown, and updated UK cybersecurity reporting regulations for 2024.
54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers
Analysis reveals 54 EDR killer programs abusing 34 signed drivers via BYOVD to neutralize security before ransomware deployment.
CISA KEV Update: CVE-2025-66376 Zimbra and SharePoint Exploits
CISA warns of active exploitation for Zimbra CVE-2025-66376, SharePoint flaws, and Cisco zero-days used in ransomware attacks. Secure your systems now.
Marquis Ransomware Attack Impacts 74 Banks and 672,000 Individuals
Marquis financial services reports a massive 2025 data breach affecting 74 US banks and 672,000 customers following a ransomware incident in August.
Ransomware TTPs Shift: From Cobalt Strike to Native Tools, Data Theft Surges
Ransomware actors are abandoning Cobalt Strike for native Windows tools as payment rates decline, leading to a significant surge in data theft.
LeakNet Ransomware: ClickFix Exploitation and Deno Loader Analysis
LeakNet ransomware leverages ClickFix social engineering and Deno-based in-memory loaders to bypass traditional security controls and deploy payloads.
LeakNet Ransomware: Stealthy Exploitation via Deno and ClickFix
LeakNet ransomware adopts ClickFix social engineering and the Deno runtime for stealthy initial access and loader deployment in corporate environments.
England Hockey Investigates AiLock Ransomware Data Breach
England Hockey is investigating a potential data breach after the AiLock ransomware group claimed responsibility, impacting member data security.
Veeam Backup & Replication RCE via CVE-2024-40711 — Mitigation Guide
Veeam patches critical RCE vulnerabilities, including CVE-2024-40711, in Backup & Replication. Discover how to secure your backup servers against exploitation.
AI-Generated Slopoly Malware Linked to Interlock Ransomware Attacks
Analysis of the AI-generated Slopoly malware and its role in Interlock ransomware operations, including technical details and detection strategies.