Articles tagged "Ransomware"

Found 380 articles

A recent report from Dragos reveals that ransomware attacks targeting industrial organizations are on the rise, with 1,140 incidents recorded in the second quarter of 2026, a 12% increase from the previous quarter. Notably, attackers do not need direct access to industrial control systems (ICS) to cause significant disruptions; targeting the IT systems that support these environments can be sufficient. The manufacturing sector was particularly hard hit, accounting for 747 of the reported incidents. This trend raises concerns about the vulnerability of industrial operations, as disruptions can lead to production delays and financial losses. Companies need to bolster their cybersecurity measures to protect against these types of attacks, which are increasingly common and damaging.

Read Original

Microsoft Threat Intelligence has reported that a group known as Storm-1175, which is believed to operate from China, has exploited an authentication-bypass vulnerability (CVE-2026-18577) in N-able's N-central remote monitoring and management tool. This exploitation allowed the attackers to gain initial access to systems and subsequently deploy a new ransomware variant called StormEncryptor. Organizations using N-central are at risk, as the vulnerability could lead to significant data loss and operational disruption. The incident emphasizes the importance of monitoring for vulnerabilities in remote management tools, as they can be entry points for cybercriminals. Companies should ensure they are using the latest security updates and patches to protect against such threats.

Read Original

U.S. and South Korean government agencies are warning organizations to be vigilant against the Gunra ransomware gang, which has targeted critical infrastructure sectors worldwide. This group operates as a ransomware-as-a-service platform, making it easier for threat actors to launch attacks on various systems. Their activities pose significant risks to essential services, potentially disrupting operations in sectors like healthcare, energy, and transportation. Authorities emphasize the need for heightened security measures as these attacks could lead to severe financial losses and compromise sensitive data. Businesses and government entities are encouraged to review their cybersecurity protocols and ensure they are prepared against this growing threat.

Read Original

A recent analysis found that nearly two-thirds of individuals targeted in a specific ransomware campaign were in managerial roles or higher. This shift in focus by attackers indicates that they are increasingly targeting those with access to sensitive information and decision-making power within organizations. As a result, managers are now more at risk of falling victim to these attacks. This trend raises concerns about the security measures in place at companies, as attackers often exploit weaknesses to gain access to critical data. Companies should prioritize training and implementing stronger security protocols to protect their leadership from these evolving threats.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has reported that ransomware groups are actively exploiting two vulnerabilities in the SonicWall SMA1000 series. One of these flaws is a severe server-side request forgery (SSRF) vulnerability, which could allow attackers to send unauthorized requests to internal resources. Organizations using the affected SonicWall devices are at risk, as these vulnerabilities can lead to unauthorized access and data breaches. SonicWall has released patches for these issues, and it is crucial for users to apply these updates promptly to protect their systems. The exploitation of these vulnerabilities underscores the ongoing threat posed by ransomware gangs targeting critical infrastructure and business operations.

Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have issued a warning about the Gunra ransomware group, which is targeting multiple sectors of critical infrastructure. Organizations in areas such as healthcare, energy, and government are particularly at risk. Researchers have noted that Gunra actors are employing sophisticated tactics to infiltrate systems and encrypt sensitive data, demanding ransom for its release. This situation is concerning as it poses a threat to essential services that many rely on daily. Companies are urged to bolster their cybersecurity measures and remain vigilant against potential attacks.

Read Original
Critical
Ransomware Surges in July After Q2 Lull

Infosecurity Magazine

Actively Exploited

In July 2023, ransomware attacks surged significantly following a quieter second quarter. The finance, technology, and healthcare sectors were the primary targets, with attackers increasingly focusing on these industries due to their sensitive data and critical operations. Comparitech's analysis indicates that the uptick in incidents could pose serious risks to the affected organizations, potentially leading to data breaches and operational disruptions. Companies in these sectors should be particularly vigilant and enhance their cybersecurity measures to protect against these threats. The rise in ransomware activity underscores the ongoing challenges organizations face in safeguarding their systems from malicious actors.

Read Original

Maksim Silnikau, the creator of the Ransom Cartel ransomware-as-a-service operation, was sentenced to 16 years in prison on August 5 by a federal judge in Alexandria, Virginia. Ransom Cartel, which he launched in 2021, was responsible for cyberattacks on at least 18 companies across the U.S., including businesses in California, New York, and Nebraska, as well as targets overseas. The Justice Department's action underscores the seriousness of ransomware operations and the legal consequences for those who engage in such criminal activities. Ransomware-as-a-service models allow other criminals to use the malware for their own attacks, amplifying the threat to businesses and organizations that may not have robust cybersecurity measures in place. This case serves as a reminder of the ongoing challenges posed by ransomware and the importance of cybersecurity vigilance.

Read Original

Maksim Silnikau, the mastermind behind the Ransom Cartel ransomware operation, has been sentenced to 16 years in prison following his involvement in attacks on at least 18 companies across the globe. Ransom Cartel was notorious for deploying ransomware that encrypted victims' data, demanding payment for its release. The sentencing serves as a significant step in holding cybercriminals accountable and aims to deter future ransomware attacks. This case highlights the ongoing risks that ransomware poses to businesses, as attackers continue to exploit vulnerabilities for financial gain. Companies are urged to strengthen their cybersecurity measures to protect against such threats.

Read Original

The INC ransomware group has been linked to recent attacks exploiting zero-day vulnerabilities in SonicWall products. While they weren't the first to take advantage of these flaws, their aggressive tactics in combining both vulnerabilities have made them particularly effective at stealing and encrypting sensitive data for ransom. This situation poses a significant risk for organizations using affected SonicWall devices, as it can lead to severe data breaches and financial losses. Users and companies relying on SonicWall's security products need to be vigilant and implement necessary precautions to protect their systems. The ongoing threat from INC highlights the importance of timely updates and monitoring for unusual activity in network environments.

Read Original

The INC Ransomware group is actively exploiting vulnerabilities in SonicWall's Secure Mobile Access (SMA) 1000 series devices. This campaign has been marked by aggressive tactics, including phone calls and emails aimed at pressuring victims into paying ransoms. Resecurity researchers have identified this group as the primary threat actor taking advantage of these recently disclosed flaws. Organizations worldwide that utilize SonicWall products may be at risk, as the group has ramped up its operations in response to these vulnerabilities. It’s crucial for companies to assess their security measures and consider immediate actions to prevent potential breaches and data loss.

Read Original
Actively Exploited

Recent attacks have seen the INC ransomware exploiting two zero-day vulnerabilities in SonicWall's SMA 1000 series. These vulnerabilities have raised concerns among organizations using these devices, as they could lead to unauthorized access and data breaches. SonicWall's SMA 1000 series is commonly used for secure remote access, making it a critical target for attackers. With the ransomware actively leveraging these exploits, organizations should be on high alert and prioritize securing their systems. It's essential for affected users to implement security measures as soon as possible to mitigate potential risks.

Read Original

The INC Ransomware group has become a major threat by taking advantage of security vulnerabilities in SonicWall's Secure Mobile Access (SMA) 1000 series VPN appliances. Since early August 2026, the group has ramped up its operations, targeting multiple organizations and posting their information on a data leak site. This surge in activity is particularly concerning for businesses using these VPN appliances, as it puts sensitive data at risk. Researchers have linked the increased ransomware attacks directly to the recently disclosed flaws in the SonicWall products, emphasizing the urgent need for users to address these vulnerabilities. Organizations should be vigilant and take immediate steps to secure their systems against these attacks.

Read Original

River Bank, a bank holding company, experienced a ransomware attack back in June. During this incident, hackers reportedly deleted the data they had stolen, which raises concerns about the potential loss of sensitive information and the bank's ability to recover. The investigation into the breach is still ongoing, meaning the full extent of the attack and its implications have yet to be fully understood. This incident highlights the risks financial institutions face from cybercriminals and emphasizes the need for robust data protection measures. Customers and stakeholders may be anxious about their information security following such a breach.

Read Original

The INC Ransomware gang has been exploiting vulnerabilities in SonicWall's SMA1000 appliances, gaining root access and moving laterally within networks. This targeted attack poses significant risks to organizations using these devices, as it allows attackers to access sensitive data and potentially disrupt operations. Users of SonicWall's SMA1000 should be particularly vigilant, as the exploitation indicates a clear trend of ransomware groups targeting specific hardware vulnerabilities. The situation is alarming, as it underscores the growing sophistication of ransomware tactics that directly target network devices. Organizations are urged to assess their security measures and apply any available patches to mitigate these risks.

Read Original
PreviousPage 3 of 26Next