Home/ Blog/ Topics/ Ransomware
Topic

Ransomware

Ransomware attacks, extortion crews, and the intrusions that end in encryption. What happened, who is behind it, and how to cut off the path before the payload runs.

Security news

ShinyHunters beat MFA at ReliaQuest. Device trust stopped it.

ShinyHunters vished a ReliaQuest employee and got the MFA push approved, but device-trust rules blocked the theft.

Security news

A ransomware crew hijacked about 2,000 WordPress sites to spread its malware. Your site could be one of them.

Check Point unmasked StopAndProtect, a ransomware operation running on about 2,000 hacked WordPress sites.

Security news

CISA: Medusa ransomware has hit 500+ critical infrastructure orgs and weaponizes new bugs within a day

CISA and the FBI updated their Medusa ransomware advisory: 500+ critical infrastructure victims, and affiliates now weaponize new bugs within 24 hours.

Security news

Windows Task Host flaw CVE-2025-60710 gives a local user SYSTEM, and ransomware gangs now exploit it

CISA confirms ransomware crews are exploiting CVE-2025-60710, a Windows Task Host flaw that elevates a local user to SYSTEM on Windows 11 and Server 2025.

Security news

Akira ransomware reboots Windows into Safe Mode to shut off security tools

An Akira ransomware affiliate rebooted a Windows host into Safe Mode to disable EDR, stole the data, then fumbled the encryption.

Security news

Gunra ransomware beats MFA by backdooring the login server, not the user. Patching Fortinet won't evict it.

Gunra ransomware beats MFA by rewriting the login server so one chosen code always passes, after entering through Fortinet flaws.

Security news

Critical Commvault flaw lets attackers run blocked commands on the backup control server

Commvault patched CVE-2026-13737, a critical CVSS 9.2 allowlist bypass in CommServe that lets attackers run commands the backup control server should block.

Security news

China-linked Storm-1175 turns N-able N-central into a ransomware launchpad with new StormEncryptor

Microsoft ties China-linked Storm-1175 to StormEncryptor ransomware deployed through the N-able N-central auth bypass (CVE-2026-18577). Patch, then hunt.

Security news

A Palo Alto VPN auth bypass is now a Qilin ransomware front door

CVE-2026-0257 lets attackers open a Palo Alto GlobalProtect VPN session with no login, and the Qilin ransomware crew is using it for initial access.

Security news

Inc ransomware used the SonicWall SMA zero-days to steal MFA seeds. Resetting passwords will not evict it.

Rapid7 ties the SonicWall SMA 1000 zero-days to an Inc ransomware actor that stole credentials, sessions, and TOTP seeds. A password reset won't evict it.

Security news

GigaWiper fakes a ransomware hit to cover a disk wipe, and the only early warning is on the host

GigaWiper encrypts files to .candy with no key and no ransom note, because the ransomware is a decoy for a disk wipe. Here are the host signals that catch it.

Security news

Three ransomware responders secretly worked for BlackCat. Trust is the attack surface.

Three incident-response insiders at DigitalMint and Sygnia were sentenced for helping run BlackCat ransomware, one leaking victims' insurance limits.

Security news

GodDamn ransomware blinds EDR with a signed kernel driver. Detect the load, not the file.

GodDamn ransomware uses PoisonX, a kernel driver carrying a valid Microsoft signature, to disable EDR.

Security news

A low-privilege user could overreach on Dell's Data Domain backup appliances. The fix is out.

CVE-2026-56086 lets a low-privileged remote user gain unauthorized access on Dell PowerProtect Data Domain backup appliances. CVSS 8.8. Patched builds are out.

Security news

Kairos stole 2TB, encrypted nothing, and still got $1M. Watch the login, not the file locker.

Kairos stole 2TB from a US county, encrypted nothing, and was paid $1M. Encryptionless extortion breaks file-locker alarms. Detect the login and egress.

Security news

We said a password reset wouldn't stop FortiBleed. Now it is deploying ransomware.

FortiBleed harvested 110 million Fortinet credentials. SOCRadar links that access to INC and Lynx ransomware, with 12 encryptions and a Nextcloud zero-day.

Security news

A poisoned security scanner ran on your build server and walked out with your cloud keys

The FBI's TeamPCP FLASH alert shows why a trojanized scanner steals from your servers, not the registry, and why pinning packages will not save you.

Security news

Scattered Spider keeps winning because your help desk, not a CVE, is the way in

An extradited Scattered Spider suspect breached a retailer in under three hours through a help-desk password reset. Here is the identity control that stops it.

Security news

The first AI-run ransomware locked a database with a key it never saved

The first ransomware attack run end to end by an AI agent broke in through a year-old Langflow flaw and encrypted a database with a key it never saved.

Security news

Ransomware that runs inside your browser tab, where antivirus cannot see it

Check Point built browser-only ransomware from a DeepSeek AI output: a web page encrypts your files through a legitimate browser API, with no binary for

Security news

Mistic backdoor writes nothing to disk and quietly sells your network to ransomware crews

Mistic is an in-memory backdoor that access broker KongTuke uses to hold footholds and sell them to Qilin and other ransomware crews. Here is where to catch it.

Security news

Police seized the malware that stole 27 million passwords. The passwords still work.

Operation Endgame seized the servers behind the Amadey and StealC malware, but the 27 million credentials they already stole stay valid until you rotate them.

Security news

Prinz Eugen ransomware hits your newest files first and never leaves a note

Prinz Eugen ransomware encrypts your most recently changed files first and drops no ransom note, defeating canary traps and note-based SOC alerts. What to do.

Security news

EDR evasion is now a shipped product. Your agent's silence is the only alarm left.

The Gentlemen ransomware gang ships a standardized EDR killer to affiliates using BYOVD. Here is why driver-name hunting fails and what to detect instead.

Security news

DragonForce hides its C2 inside Microsoft Teams relays. Your network sensors see a clean call.

DragonForce's Backdoor.Turn routes C2 through Microsoft Teams TURN relays, so network sensors see only Microsoft.

Security news

INC ransomware never used a zero-day. It used your patch backlog.

INC reached top-tier RaaS in 2026 with no zero-days. Every edge-device flaw it exploits was patched months earlier. Here is what to actually fix.

Security news

PeopleSoft's PSEMHUB zero-day turns the patch service into the breach

CVE-2026-35273 sits in PeopleSoft's Updates Environment Management module. Mandiant ties active exploitation to ShinyHunters, with 100+ orgs already breached.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.