Chinese ransomware group Warlock targets Spanish- and Portuguese-speaking countries
A Chinese ransomware outfit, known as Warlock, is exploiting Microsoft technologies to target large and critical organizations in Spanish- and Portuguese-spe...
A Chinese ransomware outfit, known as Warlock, is exploiting Microsoft technologies to target large and critical organizations in Spanish- and Portuguese-spe...
An international police operation has disrupted the KillSec ransomware group, with three suspects arrested, five servers seized and…
Operation KillSwitch: Europol says the KillSec ransomware group, allegedly led by a 16-year-old, was dismantled after attacks on about 1,000 victims. Law enf...
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from orga...
European police said raids against the KillSec ransomware-as-a-service operation included the arrest of a high-profile teen suspect.
An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrest...
Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims. The post Police Shut Down KillSec Ransomware, Iden...
A 16-year-old is suspected of being the main operator of KillSec, a ransomware group that Eurojust says is responsible for almost 1,000 attacks worldwide. Se...
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct...
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials and...
The incident at ATNS, which manages approximately 10% of the world's airspace, involved suspicious activity detected in OT environments supporting weather se...
Cofense researchers reveal how Global Group uses payment-themed phishing, malicious ISO files and WinMerge to deploy ransomware and extort large enterprises.
“Advanced and suspected state-sponsored threat actors” are likely to be behind the initial targeted intrusions that leveraged CVE-2026-88772, one of the two ...
The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor. The post Russian APT Star Blizzard Uses ‘RedFlick’...
Mandiant researchers said dozens of organizations have been impacted by attacks attributed to advanced and suspected state-sponsored threat groups. They expe...
Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to del...
Keio, a major Japanese railway operator, was hit by ransomware, disrupting business systems and forcing the company to shut down its network. Keio Corporatio...
The ransomware attack, which occurred in the early hours of Saturday, September 26, 2026, appears to have primarily affected Keio's hospitality business, inc...
Starting yesterday, our sensors picked up a small number of scans for "wordfence-waf.php".
A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for...