❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 11 August 2026Security/Privacy

CISA Advisory: #StopRansomware: Gunra Ransomware

By: Dissent
10 August 2026 at 15:02
Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom...

Source

Yesterday β€” 10 August 2026Security/Privacy

Ransomware gangs skip the CEO, head straight for the 40-something IT manager

By: Dissent
9 August 2026 at 08:24
Carly Page reports: Turns out the fastest way to get a company to consider paying a ransom isn’t calling the CEO – it’s targeting the 46-year-old IT manager. That’sΒ according to Zscaler, whose ThreatLabz researchers tracked 351 victims across 334 organizations caught up in a single ransomware campaign over the course of a month. The data...

Source

Before yesterdaySecurity/Privacy

City of Coweta refuses to pay ransom after system-wide cyberattack

By: Dissent
8 August 2026 at 08:40
An update on the ransomware attack affecting the City of Coweta: the city manager has been through a ransomware attack before with another city, and reports that after they paid, they were reinfected weeks later, so Coweta will not be paying any ransom demands. Threat actors who don’t keep their word do spoil it for...

Source

City of Coweta hit with system-wide ransomware attack, has backup

By: Dissent
7 August 2026 at 16:26
KTUL in Oklahoma reports: The City of Coweta says they are currently responding to a ransomware attack. According to officials, on Werdnesday, August 5, the City experienced at system-wide attack and immediately contacted their contracted IT provider and additional cycbersecurity professionals to secure their systems to prevent any further intrusion and to begin a recovery...

Source

Cardiology Associates of Port Huron remains silent although they were allegedly hacked and had patient data stolen in June. (1)

By: Dissent
6 August 2026 at 15:29
There have been approximately 4 dozen new threat actor groups targeting U.S. medical entities in the first half of 2026. One of them calls itself β€œOrova.” They have no β€œAbout” page or information about themselves on their dark web leak site, so seeing that they had recently listed two U.S. medical entities, DataBreaches contacted them...

Source

Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison

By: Dissent
6 August 2026 at 08:11
There is an update to the case of Maksim Silnikau, who was extradited from Poland to the U.S. in August 2024 to stand trial here.Β  Ionut Arghire reports: The Belarusian creator and administrator of the Ransom Cartel ransomware was sentenced to 16 years in prison in the US. Maksim Silnikau, 40, built the ransomware operation...

Source

Anthropic AI agent faked identities, phished real developers in UK government hacking test

An artificial intelligence agent built by Anthropic independently planted malicious code in a real software project and sent phishing emails to developers during a U.K. government security evaluation, according to Britain’s AI Security Institute.

Massive supply-chain attack compromises 440 packages under four hours

4 August 2026 at 18:07

In less than four hours early Tuesday, an attacker compromised a GitHub maintainer account and unleashed a self-replicating piece of malware which injected malicious code into more than 440 distinct npm packages, according to multiple security firms.Β 

The worm, built on the open-source Mini Shai-Hulud repository that TeamPCP published in May, was initially let loose in keyv, a data management interface software package with more than 600 million monthly downloads. The attacker spent the next 30 minutes compromising additional packages controlled by the same maintainer, including cacheable, flat-cache, file-entry-cache.

The attack spread to other maintainers, eventually compromising more than 860 packages with a β€œcombined total of over 2 billion monthly installs,” Ilyas Makari, malware researcher at Aikido Security, wrote in a blog post.Β 

Wiz researchers told CyberScoop it hasn’t observed any new malicious packages since the initial wave moved through a massive footpoint of cloud and code environments in those first four hours.Β 

β€œThis is the most critical initial compromise, with over 155 million weekly downloads on the root packages,” Wiz Research said in an email.Β 

Some of the compromised packages, including keyv, flat-cache and file-entry-cache, are present in more than 46% of all cloud environments, according to Wiz. β€œBy comparison, back in the Shai-Hulud 2.0 campaign the most prevalent packages were only in about 28% of environments,” the company said.Β 

β€œTime will tell whether the eventual cost and impact outpaces past attacks, or whether adoption of hardening mechanisms such as package aging, and the usage of the relatively less aggressive Mini Shai-Hulud code as basis, will defray the final toll here,” Wiz Research added.Β 

Researchers from multiple firms sprung into action to monitor the widening attack spree and published indicators of compromise to help potential victims hunt for malicious activity in their systems.Β 

The Mini Shai-Hulud variant used in these attacks scoops up a trove of sensitive data, including npm, GitHub, AWS and continuous integration credentials. It also steals AI-related configuration files and cryptocurrency wallets, researchers said.Β 

Microsoft, Aikido, Socket and Wiz all said the same payload and pattern was observed across all affected packages, indicating a single attacker or threat cluster was behind the supply-chain attack and using multiple stolen tokens.Β 

The malware showcased a few pieces of new functionality, but retained the same core mechanisms that are hallmarks of Mini Shai-Hulud.Β 

β€œThe evolution is consistent with what we’ve seen from them in past waves, however we don’t yet have the hard links” to confidently attribute the attacks to TeamPCP, Wiz Research said.

The notorious threat actor, which Google previously told CyberScoop it attributes to one core operator that was located in South Africa during at least some of the attacks, compromised and injected malicious code into more than 1,000 software packages in less than four months earlier this year.

The post Massive supply-chain attack compromises 440 packages under four hours appeared first on CyberScoop.

The double extortion of a Russian ransomware threatens the medical records that Diater has kept for 10 years.

By: Dissent
1 August 2026 at 10:30
Miguel Gomez reports: The biopharmaceutical company Diater, founded in Madrid in 1999, has appeared on the list of victims that the ransomware group DeadLock is disseminating on the dark web. The intrusion affects a company that manages particularly sensitive information of patients and healthcare professionals. The contrast lies in the type of data compromised and...

Source

Ransomware in Italy: RedACT report sheds light on an evolving threat environment

By: Dissent
31 July 2026 at 12:44
SuspectFile has published a great interview with the people behind RansomNews.online: Within this context, the first RedACT H1 2026 report,Β published byΒ ransomNews.online, represents a valuable contribution to the analysis of ransomware activity targeting Italy. The project presents itself as a new independent initiative focused on continuously monitoring the ransomware ecosystem through the collection, verification, and analysis...

Source

North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn

By: Dissent
31 July 2026 at 08:59
Alexander Martin reports: Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations, according to new research released Thursday alongside aΒ joint advisoryΒ by four South Korean security and intelligence agencies. TheΒ technical reportΒ from cybersecurity firm AhnLab details how the state-sponsored North Korean group, widely tracked...

Source

Crime Stoppers International seeking tips on INC Ransom as part of new bounty program: Operation Silent Vector

By: Dissent
30 July 2026 at 10:15
Crime Stoppers International has announced a new program: Operation Silent Vector. And the first target they are offering a bounty for is INC Ransomware. Cybercriminals operate behind anonymity; this program pulls that mask off. Crime Stoppers International is seeking tips to accelerate the arrest of cybercriminals in the INC Ransomware Cybercrime-as-a-Service group as well as...

Source

HHS OCR Settles Ransomware Investigation of OSF Healthcare System and Affiliated Covered Entities

By: Dissent
30 July 2026 at 07:26
In June 2021, DataBreaches reported on a ransomware attack affecting OSF Healthcare by a little-known gang called Xing Team. Our reporting noted OSF’s lack or response to inquiries and lack of timely notification. When OSF issued a statement in October, DataBreaches reported on that, too, commenting that we did not find their incident response timely...

Source

❌
❌