Skip to main content

Malware & Ransomware

Brightly-lit server room with subtle signs of security breach.

China-Linked Hackers Expose Wide-Ranging Espionage Campaign

Meet SHADOW-EARTH-053, a China-aligned espionage group that's been secretly lurking in the shadows since December 2024, using clever tactics like exploiting vulnerabilities and deploying web shells to gain persistent access to sensitive targets. Their sophisticated attacks have been linked to other notorious intrusion sets, revealing a vast and complex espionage campaign.

Analyst 207
A brightly-lit office workspace with a laptop on a desk, surrounded by ordinary decor and a subtle hint of a phone nearby.

Cybercrime Groups Exploit Vishing, SSO Abuse in SaaS Extortion Spree

Cybercrime groups are launching lightning-fast extortion attacks within trusted SaaS environments, exploiting vishing and SSO abuse to evade detection and strike with precision. By hiding in plain sight, they're creating significant challenges for defenders trying to keep up.

Analyst 207
Rack-mounted servers and network equipment in a brightly-lit data center interior.

cPanel Vulnerability Exploited, Ransomware Attacks Reported

A critical cPanel vulnerability, CVE-2026-41940, has been exploited, putting servers at risk of full takeover and ransomware attacks - with a near-worst-case severity score of 9.8. This flaw affects cPanel, WebHost Manager, and WP Squared, and has already been flagged by the US government's cybersecurity agency as being exploited in the wild.

Analyst 207
Government building with tall windows, abstract seal, and blurred laptop in foreground.

US Sentences Two Cybersecurity Pros for BlackCat Ransomware Role

Two cybersecurity experts turned to a life of crime, using their specialized knowledge to extort victims through BlackCat ransomware attacks, and have been sentenced to four years in prison for their roles. Ryan Goldberg and Kevin Martin deployed the ransomware against multiple US victims between April and December 2023.

Analyst 207
Rows of computer equipment and cables in a brightly-lit server room or network operations center.

Pro-Iran Hackers Extort Canonical with Sustained DDoS Attacks

Canonical, the company behind Ubuntu, is battling a relentless cyber assault, with its website crippled by a sustained Distributed Denial of Service (DDoS) attack that has left its main site inaccessible. The Islamic Cyber Resistance in Iraq, also known as 313 Team, has claimed responsibility for the attack.

Analyst 207
Two men in formal attire sit in a courtroom with a judge's bench in the background under natural light.

US Cybersecurity Workers Jailed for Aiding BlackCat Ransomware Gang

Meet Ryan Goldberg and Kevin Martin, two cybersecurity experts who abused their skills to line their pockets by aiding the notorious BlackCat ransomware gang. They've been sentenced to four years in prison for their roles in facilitating devastating ransomware attacks.

Analyst 207
Formal courthouse interior with podium and judge's bench under tall windows.

Ransomware Negotiators Sentenced for BlackCat Attacks

Two former cybersecurity experts, who once worked to protect companies, were sentenced to four years in prison for using their skills to extort US businesses as affiliates of the notorious BlackCat ransomware gang. They exploited their specialized knowledge to orchestrate attacks on US companies, leaving a trail of devastation in their wake.

Analyst 207
Person working at desk with laptop in a well-lit office setting.

Malicious AI Browser Extensions Exfiltrate User Data

Beware of AI browser extensions that promise to boost productivity but secretly steal your data. Researchers uncovered 18 malicious extensions that masquerade as helpful tools but deliver spyware, Trojans, and other threats that can hijack your online activity.

Analyst 207
Formal courthouse interior with podium and blurred emblem in background.

Ex-Incident Responders Sentenced for Ransomware Extortion Scheme

Two former cybersecurity pros, Ryan Clifford Goldberg and Kevin Tyler Martin, have been sentenced to four years in prison for using their specialized knowledge to orchestrate a string of devastating ransomware attacks, extorting victims instead of protecting them. The pair, who once worked in incident response, now face the consequences of their crimes.

Analyst 207
Modern workspace with a computer on a clutter-free desk, surrounded by minimal office decor.

Malware Worms Into SAP, Intercom and Lightning Developer Tools

Malicious actors struck SAP's JavaScript and cloud application development ecosystem on April 29, releasing poisoned versions of four widely-used npm packages that receive a staggering 572,000 weekly downloads. The compromised packages, which included mbt, @cap-js/db-service, @cap-js/postgres, and @cap-js/sqlite, were published in a brief window of just two hours.

Analyst 207
Hospital staff member in scrubs looks concerned while reviewing patient chart on laptop in busy emergency department with…

Ransomware Attacks on Hospitals Target Patient Care, Spark Calls for Tougher Stance

Hospitals are under attack - literally. Last year, a staggering 460 ransomware attacks hit American hospitals and healthcare systems, causing 47 patient deaths, diverted ambulances, and canceled surgeries.

Analyst 207
Office worker sits at desk with laptop and papers, surrounded by ordinary office atmosphere.

Phishing campaigns increasingly harness AI to evade detection

Phishing campaigns are getting smarter by the minute, with a whopping 86% of recent attempts leveraging AI to sneak past detection. This marks a significant jump from just two years ago, when AI was used in 80% of phishing ops.

Analyst 207
Modern office setting with laptop and notepad in foreground, blurred workstations in background.

Phishing Kit Bluekit Incorporates AI to Streamline Attacks

Meet Bluekit, a cutting-edge phishing kit that's revolutionizing the game with an AI Assistant panel, pairing traditional templates with advanced AI models to help cybercriminals quickly draft campaign materials. This innovative tool is streamlining attacks, making it easier for malicious actors to launch sophisticated phishing campaigns.

Analyst 207
A cluttered office workspace with laptop and papers on a desk in a brightly-lit room.

Silver Fox APT Targets Russia, India with ABCDoor Backdoor

Over 1,600 malicious emails, disguised as tax-audit notices, were sent to targets in India and Russia between January and February 2026, aiming to trick recipients into downloading a backdoor or clicking on a malicious link. The cleverly crafted phishing campaign unfolded in two waves, using PDFs and archives to spread the ABCDoor backdoor.

Analyst 207
New Extortion Crews Mimic Scattered Spider Tactics in Rapid Attacks

New Extortion Crews Mimic Scattered Spider Tactics in Rapid Attacks

New extortion crews, Cordial Spider and Snarky Spider, are rapidly carrying out data-theft-for-extortion campaigns, closely mimicking the tactics of notorious group Scattered Spider. These financially motivated groups, tied to The Com, have been targeting US-based organizations since October 2025.

Analyst 207
Researchers Uncover Fast16 Malware's Stealthy Industrial Sabotage Role

Researchers Uncover Fast16 Malware's Stealthy Industrial Sabotage Role

Researchers have uncovered a highly sophisticated malware, Fast16, designed to secretly sabotage industrial operations by subtly manipulating critical calculations, leading to potentially catastrophic failures. This stealthy threat can silently spread across networks, altering results in high-precision applications and causing damage to real-world equipment.

Analyst 207
Semi-truck and trailer in a brightly-lit shipping yard with cargo containers in the background.

FBI Warns of Surging Cyber-Enabled Cargo Theft Attacks

The FBI is sounding the alarm on a surge in cyber-enabled cargo theft, where sophisticated hackers impersonate legitimate businesses to hijack high-value shipments and reroute deliveries. With nearly $725 million in losses in 2025 alone, this growing threat is costing businesses big time.

Analyst 207
City street scene with modern and worn infrastructure, laptop on outdoor table or bench, hint of unease.

AI-Driven Cybercrime Fuels 389% Surge in Ransomware Victims

Get ready for a wake-up call: ransomware victims have skyrocketed by 389% in just one year, thanks to cybercriminals harnessing the power of AI to launch more sophisticated attacks. This alarming trend is driven by the growing availability of malicious AI tools, making it easier for hackers to wreak havoc.

Analyst 207
Windows computer workstation in an office with a blank laptop screen and notepad.

Python Backdoor Evades Detection on Windows with Advanced Evasion Techniques

Meet Deep#Door, a sneaky Python-based backdoor framework that hides its malicious payload inside a batch dropper, making it super hard to detect on Windows systems. By embedding its code, it dodges network-based detection and slips into restricted environments with ease.

Analyst 207
People walk in a cityscape with cell towers and cables in the background.

Cyberattacks Expose 1.8M RDP Servers Online

A shocking 1.8 million RDP servers are currently vulnerable to cyberattacks, leaving them open to exploitation by opportunistic hackers. Canadian authorities have also cracked down on SMS blaster phishing, arresting three men and seizing a device that sent fake texts to unsuspecting phones.

Analyst 207
Cluttered home office workspace with laptop and faint GitHub logo.

GitHub Facades Used to Disguise EtherRAT Malware Distribution

Malicious actors have been using 44 cleverly disguised GitHub facades to spread EtherRAT malware, masquerading as legitimate admin and dev tools between December 2025 and April 2026. These fake repositories were designed to manipulate search results, leading victims to download a malicious MSI installer hidden in a second, secret GitHub account.

Analyst 207
Windows computer workstation in an office setting with router and cables, and a blank laptop screen on the desk.

Python Backdoor Exploits Tunneling Service to Harvest Browser, Cloud Credentials

Meet DEEP#DOOR, a sneaky Python-based backdoor framework that's harvesting browser and cloud credentials by exploiting a tunneling service, and learn how it infiltrates systems through a clever sequence of stealthy steps. This sophisticated threat starts with a simple batch script that disables Windows security controls and ends with a fully featured Remote Access Trojan (RAT).

Analyst 207
Office worker looks concerned at laptop with login page, phone ringing nearby.

Phishing Exploits Persist, Breaching Half of UK Businesses

Phishing attacks remain a major threat, with nearly half of UK businesses falling victim to these scams in the past year, and a staggering 85% of breaches involving phishing as the primary entry point. These attacks often rely on human error, using tactics like impersonation emails and fake logins to trick staff into handing over sensitive information.

Analyst 207
Law enforcement officials gather in a briefing room with a cityscape backdrop.

Global Operation Disrupts Crypto Scam Centers, Arrests 276 Suspects

In a major crackdown on crypto scams, a global operation led by Dubai Police has arrested 276 suspects and shut down nine fraudulent investment centers, dealing a significant blow to scammers who thought they were safe from law enforcement. This coordinated effort with US, Chinese, and Thai authorities has brought global justice to victims of these crimes.

Analyst 207