LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
ransomwarehigh

N0n Ransomware Group Emerges, Quickly Targets Victims

A new ransomware operation, dubbed N0n, has reportedly emerged and is actively targeting organizations, according to recent observations. The group has quickly established an online presence, including a dark web leak site where it claims to be publishing data from compromised entities. This rapid operationalization suggests a prepared and potentially well-resourced threat actor.

ZeroDay News ·

Source: Graham Cluley

A new ransomware operation, dubbed N0n, has reportedly emerged and is actively targeting organizations, according to recent observations. The group has quickly established an online presence, including a dark web leak site where it claims to be publishing data from compromised entities. This rapid operationalization suggests a prepared and potentially well-resourced threat actor.

The N0n ransomware group reportedly began its activities in mid-September 2026. Since its emergence, the group has been actively adding new victims to its claimed list of compromised organizations. The establishment of a dedicated leak site is a common tactic among modern ransomware operations, used to pressure victims into paying ransoms by threatening to publicly release sensitive data.

Ransomware attacks typically involve the encryption of a victim's files and systems, rendering them inaccessible. Threat actors then demand a ransom, usually in cryptocurrency, for the decryption key. Beyond encryption, many groups, including N0n based on its leak site activity, engage in data exfiltration, stealing sensitive information before encryption. This "double extortion" strategy increases leverage over victims, as they face both operational disruption and the reputational and regulatory consequences of a data breach.

The initial access vectors for ransomware groups like N0n commonly include exploiting vulnerabilities in internet-facing systems, phishing campaigns to compromise user credentials, or leveraging misconfigured remote access services. Once inside a network, attackers often move laterally, escalate privileges, and deploy their ransomware payload across as many systems as possible to maximize impact.

Mitigation strategies against ransomware involve a multi-layered approach. Organizations are typically advised to maintain robust backup and recovery systems, segment networks to limit lateral movement, implement strong endpoint detection and response (EDR) solutions, and enforce multi-factor authentication (MFA) across all services. Regular security awareness training for employees is also crucial to defend against phishing and social engineering tactics.

Furthermore, promptly patching known vulnerabilities, particularly those in public-facing applications and VPNs, is a critical preventative measure. Incident response plans should be well-practiced to ensure a swift and effective reaction in the event of a compromise, minimizing downtime and potential data loss.

The rapid emergence and operational tempo of the N0n ransomware group underscore the persistent and evolving threat posed by cyber extortion. The continuous appearance of new threat actors highlights the need for organizations to remain vigilant, continuously update their security postures, and adhere to best practices in cybersecurity to defend against sophisticated and determined adversaries.

ransomwarecyber extortionthreat actorleak site
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.