CISA Adds Actively Exploited Windows WinSock Vulnerability to KEV Catalog
The U.S.
The U.S.
Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort
Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says China-linked, ...
An Akira ransomware affiliate has been observed rebooting a compromised Windows host into Safe Mode with Networking to disable endpoint protection an anti-ED...
Gunra ransomware has added a Linux encryptor to its arsenal, giving affiliates control over how they lock enterprise data. The command-line payload can launc...
The ransomware payload ultimately failed to deploy due to insufficient virtual memory.
The attack, which impacted services related to illicit-drug monitoring and legal processes, followed a warning from Colombia's national CERT about increased ...
Gunra actors are using stealth to exfiltrate vast volumes of data from Microsoft services, US and Korean agencies have warned
A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixe...
The group, which extorts victims by threatening to publish stolen data rather than using ransomware, has expanded its operations, according to a recent repor...
The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims...
CISA gave no specifics, but one expert said it's potentially the work of China-linked Storm-2603.
The hackers claimed to have exfiltrated 6 terabytes of data, including highly sensitive health information like records related to sexual assault, mental hea...
The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a...
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagge...
The U.S.
U.S.
Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to...
Cybersecurity and intelligence agencies from South Korea and the U.S.