Articles tagged "Ransomware"

Found 380 articles

The FBI has reported that the Medusa ransomware group has successfully attacked over 500 critical infrastructure organizations across the United States since June 2021. This includes sectors crucial for national security and public welfare, such as energy, water, and transportation. The attacks typically involve encrypting data and demanding a ransom for decryption keys, which can lead to significant operational disruptions and financial losses for the affected organizations. The widespread nature of these attacks raises concerns about the vulnerability of essential services and the potential impact on everyday citizens. As the threat continues to evolve, organizations are urged to enhance their cybersecurity measures to protect against such ransomware incidents.

Read Original

Researchers from ReliaQuest discovered a web shell linked to the Clop ransomware gang that targets PTC Windchill and FlexPLM servers. This web shell exploits a serious vulnerability in the software, allowing attackers to decrypt credentials and map sensitive engineering data. The malicious tool is designed specifically for enterprise Product Lifecycle Management (PLM) software, which many organizations rely on to manage their product data. The presence of this web shell poses significant risks to companies using these systems, as it can lead to data breaches and extortion. Organizations using PTC Windchill and FlexPLM need to be vigilant and address this vulnerability promptly to protect their sensitive information.

Read Original
Actively Exploited

Researchers have identified a custom web shell linked to the Clop ransomware gang, specifically designed to target PTC Windchill and FlexPLM servers. This malicious tool includes features that allow attackers to decrypt stored credentials, scan file repositories, and exfiltrate sensitive files. The web shell poses a significant risk to organizations using these platforms, as it enables cybercriminals to gain unauthorized access to critical data. Companies using Windchill and FlexPLM need to be vigilant and take steps to secure their systems against this specific threat. The incident underscores the ongoing challenges organizations face in protecting their data from sophisticated ransomware attacks.

Read Original

The FBI, CISA, and HHS have issued an updated advisory regarding the Medusa ransomware group, revealing that hundreds of new victims have been identified over the past year. The advisory outlines the tactics the group uses to gain initial access to networks, which often involves exploiting vulnerabilities or using stolen credentials. Once inside, attackers encrypt data and demand ransom payments, posing significant risks to organizations across various sectors. This surge in attacks emphasizes the need for companies to strengthen their cybersecurity measures and remain vigilant against evolving threats. The growing number of affected organizations highlights the critical situation surrounding ransomware attacks, making it essential for all businesses to be proactive in their defenses.

Read Original
Actively Exploited

A recent study by Black Kite reveals that mid-market firms are increasingly becoming prime targets for ransomware attacks, with manufacturers being the most affected sector. The research indicates that around 75% of ransomware incidents are directed at these mid-sized companies, which often lack the robust cybersecurity measures seen in larger organizations. This trend is concerning as it highlights a vulnerability in the mid-market that attackers are keen to exploit. The implications are significant, as these companies may face severe operational disruptions and financial losses due to such attacks. As ransomware continues to evolve, understanding the specific risks faced by mid-market firms is essential for developing effective defense strategies.

Read Original

General Electric (GE) and Philips are currently investigating claims that their systems were breached by the Clop ransomware gang, which allegedly stole sensitive data. Both companies have confirmed they are looking into these claims, but specific details about the stolen data or the extent of the breach have not been disclosed. This incident raises concerns about the security of critical infrastructure, particularly given the significant roles both GE and Philips play in healthcare and technology sectors. If the allegations are confirmed, it could have serious implications for patient privacy and operational integrity. The situation is still developing as both companies work to determine the full impact of the breach.

Read Original

Cybersecurity researchers have identified a new security threat linked to a suspected China-nexus advanced persistent threat group. The group is exploiting a serious vulnerability in Broadcom's VMware vCenter, known as CVE-2026-59310, which has a CVSS score of 9.8, indicating its severity. This directory-traversal flaw allows attackers to execute arbitrary code on affected systems. Recent reports show that the attackers are deploying Babuk-derived ransomware during these exploits, raising concerns for organizations using VMware vCenter. Companies that rely on this software need to act quickly to secure their environments and protect sensitive data from potential ransomware attacks.

Read Original
Actively Exploited

The data extortion group known as ExfilSquad, which surfaced on July 26, has claimed responsibility for stealing data from 15 organizations. So far, they have publicly leaked information from 13 victims, indicating a significant impact on businesses in various sectors. ExfilSquad's tactics include threatening to release sensitive data unless a ransom is paid, which puts additional pressure on affected organizations to comply. This incident raises concerns about data security and the potential for reputational damage for the victims involved. Organizations must remain vigilant and consider strengthening their cybersecurity measures to prevent similar attacks in the future.

Read Original

Shell is currently investigating a potential security incident after the Clop ransomware group claimed to have stolen 89GB of sensitive data from the company. The group is known for targeting large organizations and demanding ransom payments to prevent the public release of stolen information. Although Shell has not confirmed the specifics of the data taken, the incident raises concerns about the security of sensitive corporate information and the potential impacts on operations and reputation. As the investigation unfolds, it remains to be seen how the company will respond and whether any sensitive information has already been compromised. This incident serves as a reminder for all organizations to bolster their cybersecurity measures against ransomware attacks.

Read Original

On August 12, President Trump signed a National Security Presidential Memorandum that permits vetted private companies in the U.S. to conduct offensive cyber operations against foreign criminal networks. This initiative aims to empower these companies to confront international cyber threats under the oversight of the U.S. government. By allowing private entities to engage in hacking operations, the administration seeks to bolster national security and tackle issues such as ransomware and other cyber crimes originating from abroad. This move could change how the U.S. approaches cybersecurity, potentially leading to more aggressive stances against foreign adversaries. However, it raises questions about the accountability and ethical considerations of allowing private firms to engage in such activities.

Read Original
Actively Exploited

Colombia's Ministry of Justice recently became the target of a ransomware attack that disrupted essential services, particularly those related to drug monitoring and legal procedures. This incident follows a warning from Colombia's national Computer Emergency Response Team (CERT), which had alerted agencies about an uptick in ransomware activity in the country. The attack raises significant concerns about the vulnerability of government systems to cyber threats, particularly as they handle sensitive information regarding drug-related crimes. The impact of this breach could delay legal processes and hinder the monitoring of illicit activities, potentially allowing criminal operations to flourish. As ransomware attacks continue to escalate globally, this incident serves as a stark reminder of the need for enhanced cybersecurity measures in critical government sectors.

Read Original

The Colombian Justice Ministry has fallen victim to a ransomware attack just days before a presidential transition. This incident is part of a broader trend of increasing cyberattacks targeting government and critical infrastructure in Latin America. The breach raises concerns about the security of sensitive governmental data and the potential disruption of services during a politically sensitive time. As attackers continue to exploit vulnerabilities within public institutions, the urgency for enhanced cybersecurity measures becomes more evident. The ramifications of such attacks can extend beyond immediate operational impacts, potentially affecting public trust in government stability and security.

Read Original
Actively Exploited

On August 10, 2026, cybersecurity officials from the US and South Korea issued a joint alert regarding a notable rise in Gunra ransomware attacks. This ransomware is targeting various sectors, including healthcare and critical infrastructure, posing a significant risk to organizations that may not be adequately prepared. The advisory emphasizes the need for improved cybersecurity measures to defend against these evolving threats. Companies are encouraged to enhance their security protocols, perform regular backups, and educate employees about phishing tactics that often facilitate these attacks. The rise in Gunra ransomware underscores the ongoing challenges organizations face in safeguarding their data and systems from malicious actors.

Read Original

The DeadLock ransomware group is employing a unique approach by utilizing blockchain technology to enhance its operations. This decentralized infrastructure allows them to secure communication with victims and manage data leaks more effectively. By using blockchain-backed services, the group is making it more challenging for law enforcement and cybersecurity experts to disrupt their activities. This is significant because it represents a shift in how ransomware groups can operate, potentially increasing their resilience against takedown efforts. Victims of such attacks may find it harder to recover their data or prevent further exploitation due to these advanced tactics.

Read Original
Actively Exploited

ExfilSquad, a new cybercrime group that surfaced in mid-2026, has targeted 13 organizations by exploiting cloud portals to steal sensitive data. Unlike traditional ransomware attacks, this group focuses on data theft and then threatens to release the stolen information to amplify the damage. They have started distributing the stolen data through torrents, making it more difficult for affected organizations to contain the breach. Researchers from Resecurity are actively monitoring ExfilSquad's activities as they announce new victims. This incident raises concerns about the security of cloud services and the need for organizations to strengthen their defenses against data theft.

Read Original
PreviousPage 2 of 26Next