Medusa ransomware has compromised over 500 organizations since June 2021, targeting critical infrastructure sectors including healthcare, defense, manufacturing, and government…
Read More »ransomware-as-a-service
The FBI warns that the Medusa ransomware operation has breached over 500 organizations worldwide, many in critical infrastructure, and has…
Read More »Gunra ransomware operators are exploiting two legacy Fortinet vulnerabilities (CVE-2024-55591 and CVE-2025-24472) to breach government and critical infrastructure networks, using…
Read More »U.S. and South Korean agencies issued a joint advisory urging global critical infrastructure to defend against Gunra, a double-extortion ransomware…
Read More »A new alliance between the Vect ransomware group and the credential-theft collective TeamPCP creates an "unprecedented model of industrialized ransomware,"…
Read More »The Gentlemen ransomware group uses a proprietary EDR killer suite called GentleKiller, which employs a bring-your-own-vulnerable-driver (BYOVD) technique to terminate…
Read More »The ransomware gang Gentlemen uniquely develops and maintains an in-house framework called GentleKiller, a suite of EDR-killer tools directly supplied…
Read More »DragonForce ransomware group used a custom malware strain called Backdoor.Turn to hide its command-and-control traffic within Microsoft Teams relay infrastructure,…
Read More »A critical coding error in Vect 2.0 ransomware permanently destroys files larger than 128 KB instead of encrypting them, making…
Read More »A new ransomware-as-a-service group called "The Gentlemen" has rapidly emerged as a major threat, claiming over 320 victims with a…
Read More »TeamPCP has not retreated but has strategically paused its supply chain attacks to partner with a new ransomware-as-a-service (RaaS) operation…
Read More »An emerging ransomware group called The Gentlemen, operating on a ransomware-as-a-service model, was exposed by a disgruntled affiliate, revealing its…
Read More »A new analysis reveals 54 distinct EDR killer programs are exploiting vulnerabilities in 35 legitimate, signed drivers (BYOVD) to disable…
Read More »A routine brute force attack on an exposed RDP server provided a critical entry point, revealing the operational patterns of…
Read More »AkzoNobel, a major paints and coatings company, confirmed a contained cybersecurity breach at a U.S. facility, with the impact appearing…
Read More »A new, highly sophisticated ransomware-as-a-service operation named **Vect** is rapidly emerging, posing a critical threat by targeting organizations and actively…
Read More »Ransomware data leaks surged dramatically in late 2025, with victim organizations posted to extortion sites increasing by 50% from the…
Read More »An operational security lapse by the INC ransomware gang allowed forensic investigators to discover and access a persistent repository containing…
Read More »Ukrainian and German authorities have identified and placed Russian national Oleg Evgenievich Nefedov, the leader of the Black Basta ransomware…
Read More »A new ransomware-as-a-service platform called ShinySp1d3r is being developed by threat actors linked to ShinyHunters and Scattered Spider, marking a…
Read More »


















