ransomware news
118 stories · page 1 of 3
Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks
The FBI and Secret Service have issued a joint alert regarding "FortiBleed," a credential compromise campaign targeting Fortinet firewalls and VPN gateways. The agencies confirm that the campaign remains active and poses a significant threat, potentially leading to user lockouts and serving as an initial entry point for ransomware attacks.

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
The Warlock ransomware group, tracked by Symantec as Longlegs and also known as Storm-2603, continues to exploit unpatched vulnerabilities in Microsoft SharePoint, more than a year after these flaws were initially publicized. The group, which has historical ties to China-nexus clusters CL-CRI-1040, CamoFei, and ChamelGang, has recently targeted critical infrastructure, including water…

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock has reportedly been exploiting vulnerabilities in Microsoft SharePoint to disable security tools and deploy ransomware. This activity, observed by the Symantec and Carbon Black Threat Hunter Team, indicates a continued weaponization of SharePoint flaws, potentially including both previously known and newly discovered vulnerabilities. The…

N0n Ransomware Group Emerges, Quickly Targets Victims
A new ransomware operation, dubbed N0n, has reportedly emerged and is actively targeting organizations, according to recent observations. The group has quickly established an online presence, including a dark web leak site where it claims to be publishing data from compromised entities. This rapid operationalization suggests a prepared and potentially well-resourced threat actor.

Warlock ransomware breach SharePoint in water, telecom operator attacks
The Warlock ransomware group, identified by Symantec as Longlegs, has been observed targeting a range of organizations, including a water utility, a telecommunications provider, a regional government body, and a university. These attacks, which have primarily focused on Portuguese and Spanish-speaking countries in Europe, Africa, and Latin America over the past two months, leverage…

Mississippi mayor says ransomware incident led city to shut down systems
The city of Vicksburg, Mississippi, has experienced a ransomware attack that led to the shutdown of its computer systems, according to Mayor Willis Thompson. The incident, which was publicly disclosed by Thompson on Thursday evening, has impacted utility payments but has not affected emergency services.

'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries
A Chinese threat group is reportedly deploying "Warlock" ransomware in attacks targeting critical infrastructure organizations in Portuguese and Spanish-speaking countries. The campaign exploits various vulnerabilities within Microsoft SharePoint, according to recent analysis from the Symantec Threat Hunter Team.

Alleged KillSec Ransomware Mastermind a 16-Year-Old
Recent reports indicate that law enforcement agencies from multiple countries have collaborated to disrupt a significant cybercrime operation, identifying the alleged mastermind behind the KillSec ransomware as a 16-year-old individual. This operation is reported to have impacted approximately 500 victims globally over the past two years, marking a notable takedown in the ongoing fight against…

Werkzeug Path Traversal Flaw Linked to Ransomware Use
CVE-2024-49766, a path traversal vulnerability in Werkzeug, is now linked to ransomware campaigns. The flaw was publicly known for over two years before this connection was made.

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
The ShinyHunters cybercrime group has claimed responsibility for breaching and defacing the data leak site operated by the Clop ransomware gang. The attack, which began on a Friday night, involved defacing Clop's Tor-based site with ASCII art and a message, and ShinyHunters alleges it also stole server data and private keys for Clop's onion service.

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Recent reports highlight several significant developments in the cybersecurity landscape, including the sentencing of a ransomware developer, a novel AI-driven attack dubbed "Plugin4Shell," and a critical vulnerability affecting SAP systems. These incidents underscore the diverse and evolving threats faced by organizations and individuals alike, ranging from traditional criminal enterprises to…

Smashing Security podcast #485: These researchers got drunk to hack an LG TV
Cybersecurity researchers reportedly circumvented legal restrictions on testing LG smart TVs by intentionally becoming inebriated before agreeing to the devices' terms and conditions. The researchers' rationale was that a contract agreed to under the influence of alcohol would not be legally binding, thus allowing them to proceed with security testing without violating LG's terms of service.

Most Firms Unable to Recover Quickly from Ransomware
A new report from incident response firm Fenix24 indicates that very few organizations are able to recover quickly from ransomware attacks, with only a tiny fraction achieving even partial operational capacity within their target recovery windows. The firm's first "State of Recoverability" report, released on September 15, analyzed over 500 ransomware recovery engagements and found that none…

Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence
A Ukrainian national involved in the Conti ransomware operation, Oleksii Oleksiyovych Lytvynenko, has been sentenced to four years in a U.S. federal prison for conspiracy to commit wire fraud. The 44-year-old, formerly residing in Cork, Ireland, pleaded guilty to the charge on June 10, 2026.

From Hacks to Bioweapons, Claude Misuse Is Now Everywhere
Anthropic, the developer of the Claude AI service, has released a comprehensive report detailing a wide array of misuses of its platform over the past eight months, ranging from state-sponsored hacking to attempts at bioweapon development. The company stated it successfully disrupted all identified malicious activities.

New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain, dubbed Mantax Otax, has been identified as combining ransomware, spyware, and harassment capabilities. The malware, reportedly distributed by Indonesian operators, targets users through malicious APKs hosted outside of Google Play, employing phishing and social engineering tactics.

Conti ransomware crew member sentenced to four years in prison
A Ukrainian national, Oleksii Oleksiyovych Lytvynenko, 44, has been sentenced to four years in prison for his involvement with the Conti ransomware group. Lytvynenko, also known as Alexsey Alexseevich Litvinenko, pleaded guilty in June to conspiracy to commit wire fraud.

CISA: WatchGuard RCE flaw now exploited in ransomware attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical remote code execution (RCE) vulnerability in WatchGuard Firebox firewalls, tracked as CVE-2025-14733, is now being exploited by ransomware groups. CISA added this flaw to its Known Exploited Vulnerabilities (KEV) catalog in December, at which point it was already being actively exploited.

Proxmox VE Auth Bypass Exploited Same Day as Disclosure
CVE-2023-54391, a critical authentication bypass in Proxmox VE, was exploited on the same day it was published, leaving no patch window. The vulnerability affects end-of-life versions.

Hackers Leak Millions of Airport Passenger Records After Ransom Refusal
Manchester Airports Group (MAG) has confirmed a data breach affecting customer information stored in a third-party database, leading to the exposure of personal details for approximately 8.8 million individuals. The incident, which MAG disclosed on August 27, involved data related to parking, lounge, and Fast Track bookings, as well as airport Wi-Fi sign-ups.

AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
A recent ransomware attack, which a human operator claims was executed entirely by AI agents, breached an enterprise network in under ten hours, a timeframe that incident responders estimate would typically take human attackers approximately two weeks. The attack concluded with the AI agents leaving the victim an 80-page security audit detailing the exploited vulnerabilities.

Ransomware protection for MSPs: A 6-point checklist for faster recovery
A cybersecurity report identified 143 managed service providers (MSPs), IT service providers, and telecommunication companies as ransomware victims in 2025. Phishing was responsible for 52% of initial access incidents, while unpatched vulnerabilities accounted for 27%. In response, a six-point checklist has been proposed for MSPs to enhance ransomware protection and accelerate recovery.

Berlin confirms data theft after Rhysida ransomware attack claims
Berlin's city administration has confirmed that it is facing an extortion attempt following a cyberattack by the Rhysida ransomware group, which listed the city on its data leak site. The incident, discovered in mid-August, was publicly claimed by the attackers on August 28. Berlin Mayor Kai Wegner stated that the city will not pay the ransom. The State Criminal Police Office, the public…

Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION
A cyberattack on UK airport operator Manchester Airports Group (MAG) has led to the exposure of data belonging to 8.7 million customers across three of its airports. The breach was confirmed by MAG, though specific details about the nature of the data compromised or the exact timeline of the attack were not immediately available.

Rhysida Ransomware Group Targets Berlin Government Ahead of Vote
The Berlin state government is currently managing an extortion attempt by the Rhysida ransomware group, which claims to have stolen 5.79 terabytes of data from the city-state's administrative network. This incident comes just weeks before Berlin's state parliament elections on September 20.

ATF confirms cyberattack hit system containing info on its investigation targets
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed this week that it experienced a cyberattack affecting a standalone system that contained information on targets of its investigations. The agency stated that the incident was isolated and did not impact its critical operations or other internal systems.

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter
A joint analysis by Tenable and SentinelOne reveals that edge infrastructure is a shared attack surface, with both state-sponsored actors and cybercriminals independently targeting the same vulnerabilities and vendors. This convergence challenges the perception that edge device exploitation is primarily a nation-state problem, demonstrating a broader threat landscape.

Employee benefits platform Paylogix says hackers stole financial and health data
Paylogix, a technology company specializing in employee benefits management, has confirmed a data breach that resulted in the theft of sensitive personal, financial, and health information belonging to tens of thousands of individuals. The New York-based firm, which provides benefits administration tools to employers and insurance companies, disclosed the incident through state regulatory…

The cybercrime supply chain has five stages, each with a price
The modern cybercrime ecosystem operates as a sophisticated, multi-stage supply chain, a significant departure from the outdated image of a lone attacker. This intricate structure involves distinct specialized roles, each with its own pricing model, allowing for a division of labor that enhances efficiency and profitability for criminal enterprises.

Tricky 'SynkLoader' Multitool May Herald Ransomware
Security researchers have identified a sophisticated new malware family, dubbed "SynkLoader," which exhibits advanced capabilities including screen hijacking for credential theft and a range of novel features. This multitool malware is believed to be a precursor to more damaging attacks, potentially including ransomware deployments, and is notable for its multilingual support and a return to…

Ransomware attackers are zeroing in on mid-market companies
Mid-sized companies have become the primary target for ransomware and data extortion attacks, accounting for nearly three-quarters of publicly disclosed incidents in North America and Europe between January 2023 and June 2026. An analysis of 13,336 incidents with known revenue, conducted by Black Kite, defined mid-market companies as those with annual revenues ranging from $10 million to $1…

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
A threat actor known as "TheHatman" has claimed to have exfiltrated millions of employee records from the Microsoft Azure environments of several Fortune 500 companies. The alleged victims include prominent global businesses such as McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services (TCS).

Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen
The Hospital for Sick Children (SickKids) in Toronto, Canada, has confirmed a recent cybersecurity incident that resulted in the theft of personal information belonging to current and former employees. This marks the second significant cyberattack against the institution, following a ransomware incident in 2022.

Cl0p Targets 40+ Organizations Through PTC Windchill Flaw
The Cl0p ransomware group claims to have compromised over 40 organizations by exploiting a critical vulnerability in PTC's Windchill and FlexPLM product lifecycle management (PLM) software. This vulnerability, identified as CVE-2026-12569, is a remote code execution (RCE) flaw with a CVSS score of 9.3, stemming from the deserialization of untrusted data. It affects all CPS versions and…

US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline
US Bank is currently investigating claims made by the LockBit ransomware group, which alleges it breached the financial institution and exfiltrated data. LockBit has set a deadline of September 3 for US Bank to pay an extortion demand, threatening to publish the stolen information if the payment is not made.

Ransomware crook poses as recovery firm to steal payments from fellow extortionists
A ransomware affiliate has reportedly adopted a new tactic: posing as a data recovery service to intercept ransom payments from victims. Researchers at GuidePoint Security identified an operation calling itself "Ransom Busters" that contacts ransomware victims before their attacks become public, offering to recover encrypted files and delete stolen data for a significantly lower fee than the…

StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network
A newly identified cybercrime operation, dubbed "StopAndProtect" by researchers at Check Point, has co-opted nearly 2,000 compromised WordPress websites, transforming them into a criminal network for malware distribution, data exfiltration, surveillance, and ransomware deployment. The campaign was first observed in May 2026.

Rogue ransomware affiliate poses as recovery firm to steal payments
A suspected ransomware affiliate is reportedly posing as a recovery service called "Ransom Busters," contacting victims of cyberattacks before the incidents become public. This group claims to possess decryption keys and the ability to delete stolen data for a fee, ranging from $20,000 to $60,000.

Rogue ransomware affiliate poses as data recovery firm to steal payments
A suspected ransomware affiliate is reportedly posing as a data recovery service, "Ransom Busters," contacting victims of cyberattacks before the incidents become public. The group claims to possess decryption keys and the ability to delete stolen data for a fee, ranging from $20,000 to $60,000.

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
The Cl0p ransomware group has reportedly named over 40 organizations as victims in a recent campaign, specifically targeting instances of PTC Windchill. This public naming on their dark web leak site is a common tactic employed by ransomware groups to exert pressure on victims to pay the ransom, threatening to release stolen data if demands are not met.

Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware
The Medusa ransomware-as-a-service (RaaS) operation has impacted over 500 critical infrastructure organizations as of April 2026, according to a recent advisory issued by the FBI, CISA, and the Department of Health and Human Services. This marks a significant increase from an earlier US government advisory in March 2025, which reported over 300 critical infrastructure organizations affected by…

Medusa ransomware gang has hit over 500 organizations, CISA warns
The Medusa ransomware group has compromised over 500 organizations across various critical infrastructure sectors since its emergence in June 2021, according to a joint advisory updated by the FBI, CISA, and the Department of Health and Human Services (HHS). The updated guidance, released in August 2026, incorporates findings from FBI investigations conducted through April 2026 and expands…

More than 200 victims of Medusa ransomware identified over the last year, CISA says
Federal cybersecurity agencies have identified over 200 new victims of the Medusa ransomware group in the past year, bringing the total confirmed victim count to more than 500 as of April 2026. This updated figure comes from an advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI, which was initially released in March 2025 and previously reported 300…

Clop created custom web shell for Windchill data theft attacks
A custom Java web shell, believed to be linked to the Clop ransomware group, has been identified as specifically designed for PTC Windchill and FlexPLM servers. The web shell possesses built-in functionalities to decrypt credentials, enumerate file repositories, and exfiltrate data.

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
The Medusa ransomware-as-a-service group has expanded its victim count to over 500 organizations, an increase of more than 200 since March 2025, according to an updated advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Department of Health and Human Services (HHS). The group, first identified in 2021, has also refined its tactics for initial…

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
A new entity calling itself "Ransom Busters" has reportedly begun contacting victims of ransomware attacks, asserting that it has successfully breached the servers of various ransomware groups. Ransom Busters is subsequently offering to delete the data stolen by these ransomware groups for a fee, which reportedly ranges from $20,000 to $60,000. This development introduces a novel layer to the…

CISA: Windows Task Host flaw now exploited by ransomware gangs
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware groups are actively exploiting a high-severity privilege escalation vulnerability in Windows Task Host. This flaw, identified as CVE-2025-60710, was initially flagged by CISA as being actively exploited in April, and the agency recently updated its Known Exploited Vulnerabilities (KEV) Catalog to…

Weekly Update 517: Cyber Ransoms
A recent report indicates a complex and evolving landscape within the realm of cyber ransoms, highlighting a significant disconnect between the technical execution of attacks and the subsequent financial operations. The situation is characterized by a high volume of successful extortion attempts, often lacking traditional malware components, and a notable challenge for perpetrators in…