NSO
AI Intelligence Brief cached
Edit Profile
Entity Relationships
Related YARA Rules View all on YARA Rules page →
90-Day Activity
Last 90 Days (386)
Ransomware has a new target. Is your backup ready?
Ransomware groups are increasingly targeting backup infrastructure to eliminate recovery options and increase pressure on victims to pay. Kaseya explains why...
Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany
The individual was detained in May and has been extradited to Germany to face hacking charges. The post Qilin Ransomware Suspect Arrested in Japan, Extradite...
Advantest Discloses Data Breach Months After Ransomware Attack
The Japanese chip testing giant said hackers stole personal information from its servers in the February 2026 cyberattack. The post Advantest Discloses Data ...
Advantest confirms personal information stolen in ransomware attack
Advantest Corporation is notifying affected individuals that a ransomware attack earlier this year exposed their personally identifiable data. [.
Inside a brand deal scam targeting YouTube creators
A plausible-sounding sponsorship offer could mask an attempt to compromise your Google account
Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
The FBI and Secret Service warned Fortinet users that FortiBleed, uncovered this summer, is a continuing threat. The post Alert: FortiBleed remains active ca...
Osaka Metropolitan University cancels classes after suspected ransomware attack
Osaka Metropolitan University said on Tuesday that the outage left its internal network, email and a range of administrative and academic systems unavailable.
Gentlemen Ransomware Affiliate Uses MCP as C2 Channel in Live Cyberattacks
A Russian-speaking Gentlemen ransomware affiliate used the Model Context Protocol (MCP) to execute commands during live intrusions, turning an AI coding assi...
OT Attacks on US Critical Infrastructure Could Disrupt Military Operations and Physical Processes
US critical infrastructure faces an operational technology threat that extends beyond civilian service outages. State-sponsored intrusions and direct attacks...
Johnson Controls EasyIO FG
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following vers...
Former Employee Sentenced for Damaging Employer’s Windows Network Infrastructure
A former infrastructure engineer has been sentenced to 32 months in federal prison for damaging his employer’s computer network and demanding a ransom in Bit...
Ransomware Affiliate Double-Crosses RaaS Operator to Steal Victim Funds
An affiliate of The Gentlemen RaaS group ran a parallel leak site during extortion of two dozen victims
University of Illinois Chicago College of Medicine systems impacted by ransomware attack
The University of Illinois Chicago (UIC) recently experienced a ransomware attack that disrupted access to certain systems within its College of Medicine, le...
University of Illinois Chicago affected by ransomware attack on medical school
A ransomware attack that affected the University of Illinois Chicago (UIC) College of Medicine resulted in the theft of some information from its servers.
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
A blank field. A public repo.
12 Best ITDR Tools Compared (2026): Features & Pricing
Microsoft Defender for Identity is the best ITDR solutions starting point for most estates often already licensed while CrowdStrike leads platform-consolidat...
Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns
OpenAI safety veteran David Robinson resigns, warning that the company’s culture and fast AI development model could create bigger risks. OpenAI safety veter...
Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telecoms, governments, and universities worldwide. Warlock rans...
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in a...