Akira Ransomware Reboots Windows Into Safe Mode to Disable EDR and Microsoft Defender
An Akira ransomware affiliate has been observed rebooting a compromised Windows host into Safe Mode with Networking to disable endpoint protection an anti-ED...
An Akira ransomware affiliate has been observed rebooting a compromised Windows host into Safe Mode with Networking to disable endpoint protection an anti-ED...
Gunra ransomware has added a Linux encryptor to its arsenal, giving affiliates control over how they lock enterprise data. The command-line payload can launc...
The ransomware payload ultimately failed to deploy due to insufficient virtual memory.
The attack, which impacted services related to illicit-drug monitoring and legal processes, followed a warning from Colombia's national CERT about increased ...
Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned
A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixe...
The group, which extorts victims by threatening to publish stolen data rather than using ransomware, has expanded its operations, according to a recent repor...
The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims...
CISA gave no specifics, but one expert said it's potentially the work of China-linked Storm-2603.
The hackers claimed to have exfiltrated 6 terabytes of data, including highly sensitive health information like records related to sexual assault, mental hea...
The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a...
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagge...
The U.S.
U.S.
Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to...
Cybersecurity and intelligence agencies from South Korea and the U.S.
DeadLock, an emerging financially motivated ransomware operation that couples conventional intrusion tradecraft with decentralized infrastructure engineered ...
CISA and international law-enforcement partners have issued a joint #StopRansomware advisory warning that Gunra ransomware affiliates are exploiting exposed ...
Microsoft Threat Intelligence indicates that Storm-1175, believed to be China-based, likely exploited an authentication-bypass vulnerability (CVE-2026-18577)...