Topic: ransomware deployment

  • Scattered Spider Now Targets VMware vSphere in New Attacks

    Scattered Spider Now Targets VMware vSphere in New Attacks

    A cybercrime group, Scattered Spider (UNC3944), is targeting VMware vSphere environments in critical industries like retail, airlines, and insurance using social engineering and hypervisor-level exploitation. The attackers use phone-based impersonation to gain credentials, escalate access to vCen...

    Read More »
  • Jaguar Land Rover Confirms Data Breach After Cyberattack

    Jaguar Land Rover Confirms Data Breach After Cyberattack

    Jaguar Land Rover confirmed a significant data breach and system disruption from a recent cyberattack, leading to temporary shutdowns and affecting its global operations. The company is working with cybersecurity experts to restore systems and has acknowledged that some data was stolen, though sp...

    Read More »
  • Scattered Spider Targets VMware ESXi in Latest Hacking Wave

    Scattered Spider Targets VMware ESXi in Latest Hacking Wave

    A hacking group, Scattered Spider, is targeting VMware ESXi hypervisors via social engineering, compromising U.S. corporations by impersonating employees to gain network access. The attackers exploit privileged accounts to control VMware vCenter, enabling SSH on ESXi hosts and executing disk-swap...

    Read More »
  • Clorox Sues Vendor Over $380M Hack Due to Password Mishandling

    Clorox Sues Vendor Over $380M Hack Due to Password Mishandling

    Cyberattacks frequently target human vulnerabilities, as seen in Clorox's $380M breach caused by lax authentication practices by its IT vendor, Cognizant. Hackers easily bypassed security by impersonating employees, obtaining unauthorized access through Cognizant's unverified password resets and ...

    Read More »
  • U.S. Insurance Firms Now Prime Targets for Cyber Hackers

    U.S. Insurance Firms Now Prime Targets for Cyber Hackers

    Cybercriminals, particularly the hacking group Scattered Spider, are increasingly targeting U.S. insurance companies, shifting from previous attacks on U.K. retail organizations. Recent breaches at Philadelphia Insurance Companies and Erie Insurance highlight the group's tactics, including social...

    Read More »
  • Chinese Hackers Exploit Critical SharePoint 'ToolShell' Flaws

    Chinese Hackers Exploit Critical SharePoint 'ToolShell' Flaws

    Chinese-linked hacking groups (Linen Typhoon, Violet Typhoon, Storm-2603) are exploiting critical Microsoft SharePoint vulnerabilities (CVE-2025-53770, CVE-2025-53771) to steal data or deploy ransomware. Linen Typhoon targets government and defense sectors, while Violet Typhoon focuses on intelle...

    Read More »
  • Dangerous VSCode Extensions Steal Crypto on OpenVSX

    Dangerous VSCode Extensions Steal Crypto on OpenVSX

    Malicious extensions in the VSCode ecosystem, such as C++ Playground and HTTP Format, have been downloaded thousands of times and are designed to steal cryptocurrency or create backdoors, with the threat actor TigerJack repeatedly uploading them under new names to evade detection. These extension...

    Read More »