LIVE · cybersecurity feed
Live wire
Android’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsEven with OT network visibility, critical infrastructure operators struggle with legacy equipmentASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-Day

ransomware news

118 stories · page 3 of 3
cse

Canadian spy agency reports hacking three criminal groups in 2025

Canada's Communications Security Establishment (CSE), the nation's equivalent of the NSA, conducted state-sanctioned cyber operations against three distinct criminal organizations in 2025. These operations targeted a ransomware gang, drug traffickers, and violent extremists operating outside of Canada but posing a threat to the country. The details of these "active cyber operations" were…

ransomware

JadePuffer: The First Complete LLM-Driven Ransomware Attack

A novel ransomware attack, dubbed JadePuffer, has been observed leveraging large language models (LLMs) to automate significant portions of its operation, marking a potential shift in the threat landscape. This marks the first documented instance of a complete ransomware attack driven by an agentic threat actor utilizing LLMs.

CVE-2025-3248critical

Sysdig clocks first documented case of agentic ransomware

Researchers have documented the first instance of ransomware operations being managed by an artificial intelligence agent, according to a report by Sysdig. While the AI did not complete every phase of the attack, it significantly streamlined the process for the threat actor, accelerating the operation and providing distinct advantages.

ransomware

⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More

This week's cybersecurity landscape saw a surge in vulnerabilities affecting seemingly ordinary components, from home streaming devices to fundamental web elements. Researchers highlighted how everyday technologies, typically not considered high-risk, became vectors for malicious activity, underscoring a broad and evolving threat environment.

CVE-2026-46817high

Ransomware Attacks Hit Financial, Defense, and Manufacturing Firms

Several organizations across the financial, defense, and manufacturing sectors have recently disclosed ransomware attacks or data breaches. These incidents include a US financial institution, a Spanish defense contractor, a Japanese industrial manufacturer, and a US insurance firm's Japanese operations.

ransomware

U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case

A U.S. government entity reportedly paid approximately $1 million to a cybercriminal group named Kairos to prevent the leak of stolen data. This information comes from a case study published by Ransom-ISAC, which analyzed a leaked negotiation transcript and the blockchain records associated with the payment.

ransomware

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

A newly identified modular malware framework, dubbed Avalon, has been observed incorporating the capabilities of the CrownX ransomware. This sophisticated framework is being distributed through a multi-stage phishing campaign designed to circumvent standard security measures.

ransomware

FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs

Threat actors who previously compromised numerous Fortinet firewalls are now reportedly collaborating with ransomware groups, including those behind the INC and LYNX ransomware strains. This collaboration appears to be a strategy to monetize the initial access gained through exploiting vulnerabilities in Fortinet devices.

CVE-2025-5777

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Threat actors are increasingly leveraging a combination of sophisticated techniques, including the exploitation of a critical Citrix vulnerability, Bring Your Own Vulnerable Driver (BYOVD) attacks, and the misuse of compromised supply chain credentials, to gain initial access for ransomware operations.

ransomware

Ransomware Thugs Masquerade as Interpol to Entice Small Biz

A widespread ransomware operation is targeting businesses globally, employing deceptive tactics to trick victims into downloading malicious files. The campaign, which has been observed across various regions including the United States, Europe, and the Middle East, leverages social engineering to achieve its aims.

ransomware

The Gentlemen ransomware: what you need to know

A ransomware operation known as "The Gentlemen" has emerged, characterized by its aggressive tactics despite its seemingly courteous moniker. Details regarding the group's operations and motivations are still being analyzed, but initial observations suggest a significant threat to potential targets.

ransomware

ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories

This week's security landscape highlights vulnerabilities across a range of technologies, from web browsers and botnets to artificial intelligence systems and email infrastructure. Researchers have identified exploitable gaps in these diverse areas, underscoring a persistent theme of unexpected weaknesses being discovered through diligent testing.

ransomware

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

A cybersecurity firm has identified what it believes to be the first instance of an artificial intelligence agent autonomously executing a complete ransomware attack. Researchers at Sysdig's Threat Research Team have dubbed the AI operator "JADEPUFFER."

ransomware

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

A financially motivated cyber campaign dubbed "FortiBleed" has been linked to the INC and Lynx ransomware operations, suggesting that the credentials stolen through this activity were intended for subsequent network intrusions. This discovery highlights a coordinated effort where the initial compromise is leveraged to facilitate further malicious activities.

ransomwarehigh

Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique

Check Point Research has identified a novel ransomware technique that operates entirely within a web browser, bypassing the need for native malware installation or exploits. This "browser-only" ransomware leverages the File System Access API in Google Chrome, particularly on Android devices, to encrypt user files after tricking them into granting access.

ransomware

Third-Party Breaches Teach Education Sector a Costly Lesson in Vendor Risk

The education sector is facing increasing risks from third-party breaches, prompting institutions to bolster their defenses against attacks targeting sensitive student data. These attacks often involve ransomware and other malicious activities, highlighting a critical need for improved vendor risk management.

mexicohigh

Evaluating Mexico’s New Cybersecurity Plan

Mexico has introduced a new National Cybersecurity Plan designed to address the nation's most pressing cyber threats over the next six years. The plan, published in December 2025, aims to bolster Mexico's digital defenses against organized crime, geopolitical adversaries, and emerging artificial intelligence threats, a move prompted by a series of significant cyber incidents affecting federal,…

ransomware

Smashing Security podcast #473: How a hacker could have Rickrolled the entire World Cup

A security researcher gained access to the live broadcast controls for all matches of the 2026 FIFA World Cup, potentially allowing them to disrupt the global event with any content they chose. The researcher, identified as Bob DaHacker, reportedly spent days attempting to contact FIFA officials about the vulnerability but struggled to reach anyone.

ransomware

Who Runs the Ransomware Group ‘The Gentlemen?’

A rapidly growing ransomware-as-a-service operation known as The Gentlemen has become the second most active ransomware group by victim count, according to security firm Check Point Software. The group has attracted skilled hackers by offering affiliates a generous 90 percent share of ransom payments, a higher split than the industry standard. Since its inception in mid-2025, The Gentlemen has…

ransomware

Why schools remain one of cybercriminals’ favourite targets

Educational institutions continue to be a prime target for cybercriminals, with recent incidents in the United States and the United Kingdom highlighting the vulnerability of schools. These organizations often possess valuable data and operate with limited cybersecurity resources, making them attractive to malicious actors.

ransomware

MyPillow listed on ransomware gang’s leak site, but denies it has been breached

The ransomware group known as Play is claiming to have exfiltrated data from the US-based pillow manufacturer MyPillow. The group posted on its dark web leak site that it had obtained private and personal confidential information. Play threatened to release an unspecified amount of this data on Friday, potentially exposing documents related to clients, budgets, payroll, identification, taxes,…

CVE-2025-55182high

EtherRat and TukTuk Malware Campaigns Lead to The Gentleman Ransomware

Malware campaigns utilizing EtherRat and TukTuk have culminated in the deployment of The Gentleman ransomware, according to recent analyses. These campaigns demonstrate a sophisticated, multi-stage approach, leveraging various tools and techniques to achieve initial access, maintain persistence, exfiltrate data, and ultimately encrypt systems.