LIVE · cybersecurity feed
Live wire
Android’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsEven with OT network visibility, critical infrastructure operators struggle with legacy equipmentASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-Day

ransomware news

118 stories · page 1 of 3
fortinethigh

Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks

The FBI and Secret Service have issued a joint alert regarding "FortiBleed," a credential compromise campaign targeting Fortinet firewalls and VPN gateways. The agencies confirm that the campaign remains active and poses a significant threat, potentially leading to user lockouts and serving as an initial entry point for ransomware attacks.

ransomwarehigh

Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure

The Warlock ransomware group, tracked by Symantec as Longlegs and also known as Storm-2603, continues to exploit unpatched vulnerabilities in Microsoft SharePoint, more than a year after these flaws were initially publicized. The group, which has historical ties to China-nexus clusters CL-CRI-1040, CamoFei, and ChamelGang, has recently targeted critical infrastructure, including water…

ransomwarecritical

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The suspected China-linked threat actor known as Warlock has reportedly been exploiting vulnerabilities in Microsoft SharePoint to disable security tools and deploy ransomware. This activity, observed by the Symantec and Carbon Black Threat Hunter Team, indicates a continued weaponization of SharePoint flaws, potentially including both previously known and newly discovered vulnerabilities. The…

ransomwarehigh

N0n Ransomware Group Emerges, Quickly Targets Victims

A new ransomware operation, dubbed N0n, has reportedly emerged and is actively targeting organizations, according to recent observations. The group has quickly established an online presence, including a dark web leak site where it claims to be publishing data from compromised entities. This rapid operationalization suggests a prepared and potentially well-resourced threat actor.

ransomware

Warlock ransomware breach SharePoint in water, telecom operator attacks

The Warlock ransomware group, identified by Symantec as Longlegs, has been observed targeting a range of organizations, including a water utility, a telecommunications provider, a regional government body, and a university. These attacks, which have primarily focused on Portuguese and Spanish-speaking countries in Europe, Africa, and Latin America over the past two months, leverage…

ransomwarehigh

Mississippi mayor says ransomware incident led city to shut down systems

The city of Vicksburg, Mississippi, has experienced a ransomware attack that led to the shutdown of its computer systems, according to Mayor Willis Thompson. The incident, which was publicly disclosed by Thompson on Thursday evening, has impacted utility payments but has not affected emergency services.

ransomwarehigh

'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries

A Chinese threat group is reportedly deploying "Warlock" ransomware in attacks targeting critical infrastructure organizations in Portuguese and Spanish-speaking countries. The campaign exploits various vulnerabilities within Microsoft SharePoint, according to recent analysis from the Symantec Threat Hunter Team.

ransomware

Alleged KillSec Ransomware Mastermind a 16-Year-Old

Recent reports indicate that law enforcement agencies from multiple countries have collaborated to disrupt a significant cybercrime operation, identifying the alleged mastermind behind the KillSec ransomware as a 16-year-old individual. This operation is reported to have impacted approximately 500 victims globally over the past two years, marking a notable takedown in the ongoing fight against…

CVE-2024-49766high

Werkzeug Path Traversal Flaw Linked to Ransomware Use

CVE-2024-49766, a path traversal vulnerability in Werkzeug, is now linked to ransomware campaigns. The flaw was publicly known for over two years before this connection was made.

ransomware

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters cybercrime group has claimed responsibility for breaching and defacing the data leak site operated by the Clop ransomware gang. The attack, which began on a Friday night, involved defacing Clop's Tor-based site with ASCII art and a message, and ShinyHunters alleges it also stole server data and private keys for Clop's onion service.

ransomwarecritical

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

Recent reports highlight several significant developments in the cybersecurity landscape, including the sentencing of a ransomware developer, a novel AI-driven attack dubbed "Plugin4Shell," and a critical vulnerability affecting SAP systems. These incidents underscore the diverse and evolving threats faced by organizations and individuals alike, ranging from traditional criminal enterprises to…

ransomware

Smashing Security podcast #485: These researchers got drunk to hack an LG TV

Cybersecurity researchers reportedly circumvented legal restrictions on testing LG smart TVs by intentionally becoming inebriated before agreeing to the devices' terms and conditions. The researchers' rationale was that a contract agreed to under the influence of alcohol would not be legally binding, thus allowing them to proceed with security testing without violating LG's terms of service.

ransomware

Most Firms Unable to Recover Quickly from Ransomware

A new report from incident response firm Fenix24 indicates that very few organizations are able to recover quickly from ransomware attacks, with only a tiny fraction achieving even partial operational capacity within their target recovery windows. The firm's first "State of Recoverability" report, released on September 15, analyzed over 500 ransomware recovery engagements and found that none…

ransomware

Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence

A Ukrainian national involved in the Conti ransomware operation, Oleksii Oleksiyovych Lytvynenko, has been sentenced to four years in a U.S. federal prison for conspiracy to commit wire fraud. The 44-year-old, formerly residing in Cork, Ireland, pleaded guilty to the charge on June 10, 2026.

ransomware

From Hacks to Bioweapons, Claude Misuse Is Now Everywhere

Anthropic, the developer of the Claude AI service, has released a comprehensive report detailing a wide array of misuses of its platform over the past eight months, ranging from state-sponsored hacking to attempts at bioweapon development. The company stated it successfully disrupted all identified malicious activities.

ransomware

New Android malware encrypts files, steals data, and harasses victims

A new Android malware strain, dubbed Mantax Otax, has been identified as combining ransomware, spyware, and harassment capabilities. The malware, reportedly distributed by Indonesian operators, targets users through malicious APKs hosted outside of Google Play, employing phishing and social engineering tactics.

ransomware

Conti ransomware crew member sentenced to four years in prison

A Ukrainian national, Oleksii Oleksiyovych Lytvynenko, 44, has been sentenced to four years in prison for his involvement with the Conti ransomware group. Lytvynenko, also known as Alexsey Alexseevich Litvinenko, pleaded guilty in June to conspiracy to commit wire fraud.

CVE-2025-14733critical

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that a critical remote code execution (RCE) vulnerability in WatchGuard Firebox firewalls, tracked as CVE-2025-14733, is now being exploited by ransomware groups. CISA added this flaw to its Known Exploited Vulnerabilities (KEV) catalog in December, at which point it was already being actively exploited.

CVE-2023-54391critical

Proxmox VE Auth Bypass Exploited Same Day as Disclosure

CVE-2023-54391, a critical authentication bypass in Proxmox VE, was exploited on the same day it was published, leaving no patch window. The vulnerability affects end-of-life versions.

data breachhigh

Hackers Leak Millions of Airport Passenger Records After Ransom Refusal

Manchester Airports Group (MAG) has confirmed a data breach affecting customer information stored in a third-party database, leading to the exposure of personal details for approximately 8.8 million individuals. The incident, which MAG disclosed on August 27, involved data related to parking, lounge, and Fast Track bookings, as well as airport Wi-Fi sign-ups.

ransomware

AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit

A recent ransomware attack, which a human operator claims was executed entirely by AI agents, breached an enterprise network in under ten hours, a timeframe that incident responders estimate would typically take human attackers approximately two weeks. The attack concluded with the AI agents leaving the victim an 80-page security audit detailing the exploited vulnerabilities.

ransomware

Ransomware protection for MSPs: A 6-point checklist for faster recovery

A cybersecurity report identified 143 managed service providers (MSPs), IT service providers, and telecommunication companies as ransomware victims in 2025. Phishing was responsible for 52% of initial access incidents, while unpatched vulnerabilities accounted for 27%. In response, a six-point checklist has been proposed for MSPs to enhance ransomware protection and accelerate recovery.

ransomware

Berlin confirms data theft after Rhysida ransomware attack claims

Berlin's city administration has confirmed that it is facing an extortion attempt following a cyberattack by the Rhysida ransomware group, which listed the city on its data leak site. The incident, discovered in mid-August, was publicly claimed by the attackers on August 28. Berlin Mayor Kai Wegner stated that the city will not pay the ransom. The State Criminal Police Office, the public…

ransomware

Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION

A cyberattack on UK airport operator Manchester Airports Group (MAG) has led to the exposure of data belonging to 8.7 million customers across three of its airports. The breach was confirmed by MAG, though specific details about the nature of the data compromised or the exact timeline of the attack were not immediately available.

ransomwarehigh

Rhysida Ransomware Group Targets Berlin Government Ahead of Vote

The Berlin state government is currently managing an extortion attempt by the Rhysida ransomware group, which claims to have stolen 5.79 terabytes of data from the city-state's administrative network. This incident comes just weeks before Berlin's state parliament elections on September 20.

cyberattackhigh

ATF confirms cyberattack hit system containing info on its investigation targets

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed this week that it experienced a cyberattack affecting a standalone system that contained information on targets of its investigations. The agency stated that the incident was isolated and did not impact its critical operations or other internal systems.

CVE-2026-15409critical

Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

A joint analysis by Tenable and SentinelOne reveals that edge infrastructure is a shared attack surface, with both state-sponsored actors and cybercriminals independently targeting the same vulnerabilities and vendors. This convergence challenges the perception that edge device exploitation is primarily a nation-state problem, demonstrating a broader threat landscape.

data breachhigh

Employee benefits platform Paylogix says hackers stole financial and health data

Paylogix, a technology company specializing in employee benefits management, has confirmed a data breach that resulted in the theft of sensitive personal, financial, and health information belonging to tens of thousands of individuals. The New York-based firm, which provides benefits administration tools to employers and insurance companies, disclosed the incident through state regulatory…

ransomware

The cybercrime supply chain has five stages, each with a price

The modern cybercrime ecosystem operates as a sophisticated, multi-stage supply chain, a significant departure from the outdated image of a lone attacker. This intricate structure involves distinct specialized roles, each with its own pricing model, allowing for a division of labor that enhances efficiency and profitability for criminal enterprises.

ransomware

Tricky 'SynkLoader' Multitool May Herald Ransomware

Security researchers have identified a sophisticated new malware family, dubbed "SynkLoader," which exhibits advanced capabilities including screen hijacking for credential theft and a range of novel features. This multitool malware is believed to be a precursor to more damaging attacks, potentially including ransomware deployments, and is notable for its multilingual support and a return to…

ransomware

Ransomware attackers are zeroing in on mid-market companies

Mid-sized companies have become the primary target for ransomware and data extortion attacks, accounting for nearly three-quarters of publicly disclosed incidents in North America and Europe between January 2023 and June 2026. An analysis of 13,336 incidents with known revenue, conducted by Black Kite, defined mid-market companies as those with annual revenues ranging from $10 million to $1…

ransomware

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

A threat actor known as "TheHatman" has claimed to have exfiltrated millions of employee records from the Microsoft Azure environments of several Fortune 500 companies. The alleged victims include prominent global businesses such as McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services (TCS).

ransomware

Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen

The Hospital for Sick Children (SickKids) in Toronto, Canada, has confirmed a recent cybersecurity incident that resulted in the theft of personal information belonging to current and former employees. This marks the second significant cyberattack against the institution, following a ransomware incident in 2022.

CVE-2026-12569critical

Cl0p Targets 40+ Organizations Through PTC Windchill Flaw

The Cl0p ransomware group claims to have compromised over 40 organizations by exploiting a critical vulnerability in PTC's Windchill and FlexPLM product lifecycle management (PLM) software. This vulnerability, identified as CVE-2026-12569, is a remote code execution (RCE) flaw with a CVSS score of 9.3, stemming from the deserialization of untrusted data. It affects all CPS versions and…

ransomware

US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline

US Bank is currently investigating claims made by the LockBit ransomware group, which alleges it breached the financial institution and exfiltrated data. LockBit has set a deadline of September 3 for US Bank to pay an extortion demand, threatening to publish the stolen information if the payment is not made.

ransomware

Ransomware crook poses as recovery firm to steal payments from fellow extortionists

A ransomware affiliate has reportedly adopted a new tactic: posing as a data recovery service to intercept ransom payments from victims. Researchers at GuidePoint Security identified an operation calling itself "Ransom Busters" that contacts ransomware victims before their attacks become public, offering to recover encrypted files and delete stolen data for a significantly lower fee than the…

ransomware

StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network

A newly identified cybercrime operation, dubbed "StopAndProtect" by researchers at Check Point, has co-opted nearly 2,000 compromised WordPress websites, transforming them into a criminal network for malware distribution, data exfiltration, surveillance, and ransomware deployment. The campaign was first observed in May 2026.

ransomwarehigh

Rogue ransomware affiliate poses as recovery firm to steal payments

A suspected ransomware affiliate is reportedly posing as a recovery service called "Ransom Busters," contacting victims of cyberattacks before the incidents become public. This group claims to possess decryption keys and the ability to delete stolen data for a fee, ranging from $20,000 to $60,000.

ransomware

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is reportedly posing as a data recovery service, "Ransom Busters," contacting victims of cyberattacks before the incidents become public. The group claims to possess decryption keys and the ability to delete stolen data for a fee, ranging from $20,000 to $60,000.

ransomware

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign

The Cl0p ransomware group has reportedly named over 40 organizations as victims in a recent campaign, specifically targeting instances of PTC Windchill. This public naming on their dark web leak site is a common tactic employed by ransomware groups to exert pressure on victims to pay the ransom, threatening to release stolen data if demands are not met.

ransomwarecritical

Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware

The Medusa ransomware-as-a-service (RaaS) operation has impacted over 500 critical infrastructure organizations as of April 2026, according to a recent advisory issued by the FBI, CISA, and the Department of Health and Human Services. This marks a significant increase from an earlier US government advisory in March 2025, which reported over 300 critical infrastructure organizations affected by…

ransomwarecritical

Medusa ransomware gang has hit over 500 organizations, CISA warns

The Medusa ransomware group has compromised over 500 organizations across various critical infrastructure sectors since its emergence in June 2021, according to a joint advisory updated by the FBI, CISA, and the Department of Health and Human Services (HHS). The updated guidance, released in August 2026, incorporates findings from FBI investigations conducted through April 2026 and expands…

ransomwarecritical

More than 200 victims of Medusa ransomware identified over the last year, CISA says

Federal cybersecurity agencies have identified over 200 new victims of the Medusa ransomware group in the past year, bringing the total confirmed victim count to more than 500 as of April 2026. This updated figure comes from an advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI, which was initially released in March 2025 and previously reported 300…

ransomware

Clop created custom web shell for Windchill data theft attacks

A custom Java web shell, believed to be linked to the Clop ransomware group, has been identified as specifically designed for PTC Windchill and FlexPLM servers. The web shell possesses built-in functionalities to decrypt credentials, enumerate file repositories, and exfiltrate data.

ransomware

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics

The Medusa ransomware-as-a-service group has expanded its victim count to over 500 organizations, an increase of more than 200 since March 2025, according to an updated advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Department of Health and Human Services (HHS). The group, first identified in 2021, has also refined its tactics for initial…

ransomwarehigh

Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

A new entity calling itself "Ransom Busters" has reportedly begun contacting victims of ransomware attacks, asserting that it has successfully breached the servers of various ransomware groups. Ransom Busters is subsequently offering to delete the data stolen by these ransomware groups for a fee, which reportedly ranges from $20,000 to $60,000. This development introduces a novel layer to the…

ransomwarehigh

CISA: Windows Task Host flaw now exploited by ransomware gangs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware groups are actively exploiting a high-severity privilege escalation vulnerability in Windows Task Host. This flaw, identified as CVE-2025-60710, was initially flagged by CISA as being actively exploited in April, and the agency recently updated its Known Exploited Vulnerabilities (KEV) Catalog to…

ransomware

Weekly Update 517: Cyber Ransoms

A recent report indicates a complex and evolving landscape within the realm of cyber ransoms, highlighting a significant disconnect between the technical execution of attacks and the subsequent financial operations. The situation is characterized by a high volume of successful extortion attempts, often lacking traditional malware components, and a notable challenge for perpetrators in…