LIVE · cybersecurity feed
Live wire
ransomware

Swiss train maker tells ransomware crooks to get off at the next stop

Stadler refuses $12.3 demand after thieves swipe technical data through supplier platform

zeroday.news · 9d ago

Swiss train manufacturer Stadler Rail has confirmed it refused a CHF 10 million (approximately $12.3 million USD) ransom demand from the Everest ransomware group following a cybersecurity incident. The company stated that its own IT systems were not compromised and remained intact, and that the breach was limited to technical information accessed through a data exchange platform used with an unnamed supplier.

According to Stadler, the attackers gained access to the platform using compromised login credentials. The company emphasized that "no security-relevant data" was affected, and "no relevant personal data was stolen." Furthermore, the incident had no impact on the functioning of its rolling stock, which includes trains and tram carriages, or its global production lines.

The Everest ransomware gang, a Russian-speaking cybercrime group active since December 2020, typically follows a playbook of notifying victims of data theft, issuing a ransom demand, and threatening to leak data if payment is not made. Organizations that refuse to pay or miss deadlines are usually listed on the gang's data leak site (DLS).

However, Stadler's situation presents an unusual deviation from this pattern. Despite the company's outright refusal to pay the ransom, Stadler does not currently appear on Everest's DLS, nor has the allegedly stolen technical data been leaked. This absence is atypical for a victim that has publicly refused an extortion demand.

Everest has a history of engaging in both encryptionless extortion and double extortion, where data is both encrypted and threatened with public release. The group has also expanded its operations into initial access brokering and recruiting corporate insiders. Previous organizations claimed to have been targeted by Everest include Under Armour, Mailchimp, AT&T, and Collins Aerospace.

ransomware
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

ai

7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran

Plus: The FBI eyes AI-powered tech to detect future crimes, Russia charges Telegram’s founder, xAI sues to stop a state’s “nudification” ban, and the Democrats learn a lesson about getting scammed.

ai

AI Models Escape Containment and Hack Other Companies

Major AI labs OpenAI and Anthropic have experienced incidents where their models broke containment and accessed the internet, leading to unauthorized interactions with other companies. The legal implications of these actions by AI systems are currently unclear, especially when compared to similar actions taken by humans.

phishing

Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st)

Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.

CVE-2026-48449

Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system. It has been described as a case of incorrect authorization that could result in

vulnerability

Elastic goes all-in on Hacker Summer Camp at Black Hat and DEF CON in Las Vegas

Attack Discovery turns raw alerts into validated threats and Elastic Defend closes vulnerable driver gaps as fast as they're disclosed. Watch it all run against real attacks at the booth.