-
The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing Langflow instance via CVE-2025-3248, used the AI-host env…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A novel, practical ransomware technique that runs entirely inside the browser by abusing the File System Access API, demonstrating how AI can turn high-level malicious ideas into operational attack chains without any native payload. The proof-of-concep…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A direct operational link between the large-scale FortiBleed credential-harvesting campaign and two active ransomware-as-a-service (RaaS) groups: INC Ransom and Lynx. This finding provides the first confirmed evidence that mass theft of FortiGate crede…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Ransomware-proof backup planning helps IT teams protect clean data copies, isolate storage, test recovery, and keep operations running after cyber attacks fast.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Fake Interpol investigation emails are targeting small businesses with Proton Drive links that deliver ransomware, encrypt files, and route victims to Tox chat.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The Gentlemen ransomware group has emerged in 2026 as a highly adaptive and technically sophisticated ransomware-as-a-service (RaaS) operation targeting large corporations and critical infrastructure across multiple regions. Public reporting places The…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers increasingly rely on vulnerable, legitimately signed Windows drivers to neutralize endpoint defenses, turning defense evasion into a decisive phase of modern ransomware attacks. Over the past three years the Bring Your Own Vulnerable Driver (BY…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
BumbleBee and AdaptixC2 are being used in a highly efficient intrusion chain that starts with Bing SEO poisoning and ends with Akira ransomware deployment, showing how trusted search traffic is now being turned into an enterprise compromise vector. The…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
SystemBC (also tracked as Coroxy) remains a versatile and persistent Windows malware family that operators routinely deploy to convert compromised hosts into SOCKS5 proxy gateways and to maintain remote access for follow-on operations. First observed a…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Woodgnat Hackers use Backdoor.Mistic, a stealthy RAT, to let brokers compromise networks and sell entry points to ransomware groups, putting firms at risk.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


