#ransomware

[ follow ]
fromThe Hacker News
5 hours ago

Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More

Dozens of Orgs Impacted by Exploitation of Oracle EBS Flaw - Dozens of organizations may have been impacted following the zero-day exploitation of a security flaw in Oracle's E-Business Suite (EBS) software since August 9, 2025, according to Google Threat Intelligence Group (GTIG) and Mandiant. The activity, which bears some hallmarks associated with the Cl0p ransomware crew, is assessed to have fashioned together multiple distinct vulnerabilities, including a zero-day flaw tracked as CVE-2025-61882 (CVSS score: 9.8), to breach target networks and exfiltrate sensitive data.
Information security
Information security
fromDataBreaches.Net
1 day ago

From sizzle to drizzle to fizzle: The massive data leak that wasn't - DataBreaches.Net

A ransomware group leaked data from six of 39 targeted companies, published downloads across onion and clear-net sites, then halted further leaks despite followers' expectations.
#velociraptor
#healthcare-breach
fromDataBreaches.Net
2 days ago
Information security

Watsonville Community Hospital had a data breach - or two. It would be helpful to know which. - DataBreaches.Net

fromDataBreaches.Net
2 days ago
Information security

Watsonville Community Hospital had a data breach - or two. It would be helpful to know which. - DataBreaches.Net

#raas
fromIT Pro
3 days ago
Information security

Rocketing number of ransomware groups as new, smaller players emerge

fromDataBreaches.Net
5 days ago
Information security

DragonForce, LockBit, and Qilin, a new triad aims to dominate the ransomware landscape - DataBreaches.Net

fromIT Pro
3 days ago
Information security

Rocketing number of ransomware groups as new, smaller players emerge

fromDataBreaches.Net
5 days ago
Information security

DragonForce, LockBit, and Qilin, a new triad aims to dominate the ransomware landscape - DataBreaches.Net

Information security
fromComputerWeekly.com
4 days ago

Warlock ransomware may be linked to Chinese state | Computer Weekly

Warlock ransomware, exploiting ToolShell SharePoint vulnerabilities, is likely linked to Chinese state-sponsored APTs Linen Typhoon and Violet Typhoon.
fromDataBreaches.Net
4 days ago
Privacy professionals

Missing Risk Analysis Cost NY CPA Firm $175K-But Not the Big Group Whose Data Was Breached in 2019 - DataBreaches.Net

An accounting firm acting as a business associate incurred a $175,000 OCR HIPAA settlement after a 2019 PHI breach, highlighting recurring ransomware and risk-analysis issues.
US news
fromDataBreaches.Net
4 days ago

Policyholder Plot Twist: Cyber Insurer Sues Policyholder's Cyber Pros - DataBreaches.Net

Ace American sued CoWorx's cybersecurity vendors alleging negligence and breach of contract to recover $500,000 paid under its cyber insurance policy.
Information security
fromTheregister
4 days ago

3 infamous ransomware crews collab to 'maximize income'

Three major ransomware-as-a-service groups — DragonForce, Qilin, and LockBit — formed a coalition to coordinate attacks, reduce conflicts, and maximize collective profits.
#cybercrime
#data-breach
Information security
fromTheregister
1 week ago

Preschool network attackers take aim at Minnesota hospital

Radiant Group claims ransomware attacks on a preschool network and a Minnesota hospital, threatening to publish hospital data within seven days if demands are unmet.
Privacy professionals
fromDataBreaches.Net
1 week ago

Legal Practice Board of Western Australia begins notifying data breach victims - DataBreaches.Net

Legal Practice Board of Western Australia is notifying individuals after Dire Wolf ransomware accessed additional health, financial, and personal data, including legal practitioners' information.
Information security
fromThe Hacker News
5 days ago

LockBit, Qilin, and DragonForce Join Forces to Dominate the Ransomware Ecosystem

DragonForce, LockBit, and Qilin formed a strategic ransomware alliance to share techniques, resources, and infrastructure, amplifying ransomware capabilities and risk to critical infrastructure.
fromDataBreaches.Net
5 days ago

Salesforce Tells Clients It Won't Pay Hackers for Extortion - DataBreaches.Net

Salesforce Inc. told customers Tuesday that it won't pay a ransom demand from a hacker who claimed to have stolen a large amount of client data and threatened to publish it, according to an email seen by Bloomberg News. The company said in a security notification that it had received "credible threat intelligence" indicating that a hacking group, known as ShinyHunters, was planning to share information stolen during a security incident earlier in the year involving a number of its customers, according to the email.
Information security
fromTheregister
5 days ago

Teens arrested in London preschool ransomware attack

In a very aggressive - and disgusting - attempt to extort a ransom payment from Kido, the criminals published profiles of 10 children, including photos, names, and home addresses, along with their parents' contact details and in some cases places of work, threatening to expose more if the ransom demand wasn't met. A new crime crew calling itself the Radiant Group claimed responsibility for the attack, and posted the preschool's name, along with its pupils' profiles, as the first leak on its dark web site. The ransomware gang later deleted the kids' and parents' data, apparently under pressure from other criminals - but not before some of the parents reported receiving threatening calls.
UK news
Information security
fromTheregister
6 days ago

Microsoft blames Medusa affiliates for GoAnywhere exploits

Medusa-linked attackers exploited a critical deserialization flaw in Fortra's GoAnywhere MFT (CVE-2025-10035) to enable code execution, deploy RMM tools, and maintain persistence.
#cybersecurity
Information security
fromwww.dw.com
3 weeks ago

Airport cyberattacks: What you need to know DW 09/22/2025

Ransomware targeting MUSE check-in and boarding systems disrupted major European airports, causing cancellations, delays, and revealing critical dependence on vulnerable IT.
Privacy professionals
fromDataBreaches.Net
3 weeks ago

Survival Flight reports second cybersecurity incident in less than a year - DataBreaches.Net

Survival Flight experienced a cybersecurity incident on July 17 exposing patient names, addresses, medical treatment details and health insurance information; investigation and notifications are ongoing.
#oracle-e-business-suite
fromIT Pro
1 week ago
Information security

Google warns executives are being targeted for extortion with leaked Oracle data

fromIT Pro
1 week ago
Information security

Google warns executives are being targeted for extortion with leaked Oracle data

Information security
fromTechzine Global
1 week ago

Minimizing liability is not the same as security: Lessons learned from Collin's Aerospace cyberattack

A ransomware attack on Collins Aerospace's ARINC vMUSE disrupted European airport check-in systems, exposing vendor security and supply-chain vulnerabilities that require modernization and resilience.
Information security
fromSecurityWeek
1 week ago

Beer Giant Asahi Says Data Stolen in Ransomware Attack

Asahi Group Holdings experienced a ransomware attack that caused week-long outages at domestic subsidiaries, disrupting orders, shipments, call centers, and resulting in data exfiltration.
UK news
fromwww.theguardian.com
1 week ago

Six out of 10 UK secondary schools hit by cyber-attack or breach in past year

UK educational institutions face disproportionately high cyber-attacks, with schools and universities frequently targeted by phishing, access-broker-facilitated breaches, and ransomware.
Information security
fromTheregister
1 week ago

No suds for you! Asahi attack leaves Japanese drinkers dry

A ransomware attack disabled Asahi's Japanese distribution and call-center systems, forcing manual order processing and causing domestic supply shortages while investigations continue.
#cyberattack
Information security
fromwww.theguardian.com
1 week ago

Japan days away from running out of Asahi Super Dry due to cyber attack reports

Asahi Group faces near depletion of flagship Super Dry within days after a ransomware attack halted production at most of its 30 domestic breweries.
Information security
fromTechCrunch
1 week ago

Hackers are sending extortion emails to executives after claiming Oracle apps' data breach | TechCrunch

Clop-linked hackers claim to have stolen sensitive data from Oracle E-Business Suite and are sending extortion emails to executives at numerous large organizations.
#google-drive
fromZDNET
1 week ago
Artificial intelligence

Google releases AI-powered ransomware detection features for cloud files

fromZDNET
1 week ago
Artificial intelligence

Google releases AI-powered ransomware detection features for cloud files

Information security
fromAbove the Law
1 week ago

When Ransomware Meets AI: The Next Frontier Of Cyber Extortion - Above the Law

Generative AI dramatically lowers the technical barrier to ransomware, creating fast, automated attacks that pose legal, operational, and reputational threats to law firms and clients.
fromWIRED
1 week ago

Google's Latest AI Ransomware Defense Only Goes So Far

Ransomware attacks have loomed for years as an urgent digital threat with no easy solution -especially as they have evolved to include data grab-and-leak attacks that may not even involve data-encrypting malware at all. Traditional ransomware that locks up files and systems is still rampant, though, and Google on Tuesday launched a new defense for its Google Drive for desktop apps that aims to quickly detect ransomware activity and halt cloud syncing before an infection can spread.
Information security
#phishing
fromZDNET
2 weeks ago
Information security

Phishing training doesn't stop your employees from clicking scam links - here's why

fromZDNET
2 weeks ago
Tech industry

Employees learn nothing from phishing security training, and this is why

fromZDNET
2 weeks ago
Privacy professionals

Employees learn close to nothing from phishing training, and this is why

fromZDNET
2 weeks ago
Information security

Phishing training doesn't stop your employees from clicking scam links - here's why

fromZDNET
2 weeks ago
Tech industry

Employees learn nothing from phishing security training, and this is why

fromZDNET
2 weeks ago
Privacy professionals

Employees learn close to nothing from phishing training, and this is why

Information security
fromwww.bbc.com
2 weeks ago

'You'll never need to work again': Criminals offer reporter money to hack BBC

Criminal gangs recruit insiders by offering employees a percentage of ransom payments in exchange for login credentials and PC access to facilitate ransomware attacks.
Healthcare
fromDataBreaches.Net
2 weeks ago

ApolloMD notifies patients of 11 physician practices affected by a June cyberattack - DataBreaches.Net

Qilin claimed to possess 238 GB of ApolloMD files and threatened to publish them; ApolloMD later confirmed unauthorized access but no leaked download appeared.
Information security
fromSecurityWeek
2 weeks ago

In Other News: LockBit 5.0, Department of War Cybersecurity Framework, OnePlus Vulnerability

New Department of War CSRMC, Dragos Platform 3.0, a 3-million-record Lotte Card breach, and LockBit ransomware developments mark notable cybersecurity events.
fromTheregister
2 weeks ago

LockBit's new variant is 'most dangerous yet'

The Windows variant now loads payloads via DLL reflection and employs aggressive anti-analysis packing; the Linux variant accepts command-line directives to tailor which directories and file types to hit; and the ESXi version is built to seize virtualization infrastructure by encrypting VMs. What's more, each encrypted file is stamped with a random 16-character extension, a move designed to make restoring your data even more of a nightmare.
Information security
fromSecurityWeek
2 weeks ago

RTX Confirms Airport Services Hit by Ransomware

The company said in an SEC filing that it became aware of the cybersecurity incident on September 19. The disclosure does not mention Collins Aerospace, the subsidiary that offers the impacted airport check-in and boarding solutions. RTX confirmed that customers have resorted to backup and manual processes, which has led to flights being delayed and cancelled. The company explained that ransomware was found on "systems that support its Multi-User System Environment (MUSE) passenger processing software," adding, "This software enables multiple airlines to share check-in and gate resources at airports, including baggage handling.
Information security
#collins-aerospace
fromTechCrunch
3 weeks ago
Information security

EU cyber agency confirms ransomware attack causing airport disruptions | TechCrunch

fromTechCrunch
3 weeks ago
Information security

EU cyber agency confirms ransomware attack causing airport disruptions | TechCrunch

Information security
fromThe Verge
2 weeks ago

UK arrests man in airport ransomware attack that caused delays across Europe

A man in his forties was arrested on conditional bail over a ransomware attack on Collins Aerospace's MUSE system that disrupted European airport check-ins.
#airports
fromTechCrunch
2 weeks ago
Miscellaneous

UK police arrest man linked to ransomware attack that caused airport disruptions in Europe | TechCrunch

fromTechCrunch
2 weeks ago
Miscellaneous

UK police arrest man linked to ransomware attack that caused airport disruptions in Europe | TechCrunch

#aviation
Information security
fromThe Hacker News
2 weeks ago

How One Bad Password Ended a 158-Year-Old Business

A single easily guessed password allowed Akira ransomware to cripple KNP Logistics, destroy backups, demand £5 million, and force administration, costing 700 jobs.
Information security
fromSecurityWeek
2 weeks ago

European Airport Cyberattack Linked to Obscure Ransomware, Suspect Arrested

A HardBit ransomware variant infected Collins Aerospace systems, causing major European airport disruptions, persistent reinfections, and attribution complications due to affiliate sharing.
Information security
fromwww.bbc.com
2 weeks ago

Man arrested in connection with airport cyber-attacks

A 40-year-old man was arrested in West Sussex over a cyber-attack on Collins Aerospace that disrupted airport check-in and baggage systems, causing widespread flight delays.
Healthcare
fromSecuritymagazine
2 weeks ago

Disabling Hospital HVAC Is Now a Bargaining Chip in Ransomware

Many healthcare Building Management Systems are outdated, internet-exposed, and contain known exploited vulnerabilities that could enable cyberattacks affecting patient safety.
Miscellaneous
fromTechCrunch
2 weeks ago

European airports still dealing with disruptions days after ransomware attack | TechCrunch

Ransomware attack on Collins Aerospace disrupted check-in and boarding systems at multiple European airports, causing widespread flight delays and manual workarounds.
fromPrx
2 weeks ago

The World

The 80th session of the United Nations General Assembly is in New York this week. One issue that's at the top of the agenda is connected to the war in Gaza. Several countries announced over the weekend that they will formally recognize a state of Palestine. Other US allies are doing the same this week. Also, from London to Brussels and Berlin, some of Europe's biggest airports are grappling with a ransomware attack that has caused delays and cancellations.
World news
#scattered-spider
fromwww.aljazeera.com
3 weeks ago

Cyberattack on European airports caused by ransomware, EU finds

A cyberattack that has caused major airport disruptions in the United Kingdom, Germany and Belgium was caused by ransomware, the European Union Agency for Cybersecurity (ENISA) says. In a statement on Monday, ENISA said law enforcement was involved to investigate the software that holds data until those targeted pay to have their access back.
Miscellaneous
US politics
fromApp Developer Magazine
9 months ago

Push for FTC to Investigate Microsoft

Microsoft's cybersecurity practices and default Windows configurations present national-security risks and contributed to large ransomware breaches affecting critical infrastructure and healthcare.
Miscellaneous
fromwww.theguardian.com
3 weeks ago

Poland will shoot down objects violating its airspace, PM says, as UN security council to meet over Russian provocations Europe live

Poland will shoot down any flying objects that violate its territory, will act cautiously in ambiguous cases, and seeks assurances of allied support before escalation.
Information security
fromTheregister
3 weeks ago

Ransomware attack linked to gold heist at museum

A ransomware attack disabled a French museum's security systems, enabling thieves to steal about $705,000 in gold nuggets that were likely melted and unrecoverable.
fromThe Hacker News
3 weeks ago

Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell

In a report examining the malicious use of LLMs, the cybersecurity company said AI models are being increasingly used by threat actors for operational support, as well as for embedding them into their tools - an emerging category called LLM-embedded malware that's exemplified by the appearance of LAMEHUG (aka PROMPTSTEAL) and PromptLock. This includes the discovery of a previously reported Windows executable called MalTerminal that uses OpenAI GPT-4 to dynamically generate ransomware code or a reverse shell.
Information security
Information security
fromThe Hacker News
3 weeks ago

CountLoader Broadens Russian Ransomware Operations With Multi-Version Malware Loader

CountLoader is a versatile malware loader used by Russian ransomware affiliates and IABs to deliver Cobalt Strike, AdaptixC2, PureHVNC RAT, and other post-exploitation tools.
[ Load more ]