Ransomware — Page 2

A Microsoft-Approved Driver Is Helping 'GodDamn' Ransomware Gut US Security Tools
A rebranded criminal gang called Hyadina is using a signed Windows driver to kill antivirus software before locking victims' files. The driver carries a legitimate Microsoft stamp, and nobody knows quite how that happened.

The Gentlemen Ransomware Gang Turns Your Own IT Tools Against You
A fast-spreading criminal group is using the software your IT team trusts every day to take over company networks. The real test is not whether they got in. It is what happens next.

When the Learning Platform Goes Dark, There Is No Backup Plan
A finals-week breach of a major university software platform in 2026 left students locked out of coursework and grade books. Higher education has proved twice it will pay ransoms. That changes everything.

A U.S. Government Agency Quietly Paid $1 Million to a Group That May Not Even Be Ransomware
A leaked negotiation chat and blockchain trail suggest Kairos runs pure data-theft extortion — no file-locking, just threats to leak.

Meet Avalon: The Swiss-Army Malware That Ends in Ransomware
A newly documented toolkit called Avalon steals passwords, spreads across networks, and locks up files — all from one phishing email.

FortiBleed's Credential Theft Linked to Ransomware Gangs
Researchers reveal FortiBleed's connections to ransomware groups, posing greater risks for affected organizations.

Fake Interpol Arrest Notices Are Delivering Ransomware to Small Businesses
Criminals are impersonating the international police agency to frighten small business owners into downloading malware. The tactic is simple. It's working.

FortiBleed: 11,000 Fortinet Firewalls Still Compromised, Now Tied to INC and Lynx Ransomware
Researchers say the same crew that hoarded credentials from hundreds of thousands of Fortinet firewalls has been sitting inside the negotiation panels of two major ransomware gangs.

Ransomware Surge Led by Lockbit and Conti Offshoots
July sees a resurgence in ransomware attacks, with Lockbit and Conti offshoots dominating the landscape.

Anubis Affiliates Ride Citrix Bleed 2 Into Enterprise Networks
Ransomware crews are chaining CVE-2025-5777 with RMM tooling and stolen credentials to skip past MFA entirely.

FortiBleed: Stolen FortiGate Credentials Now Fueling INC and Lynx Ransomware Attacks
Credentials harvested from hundreds of thousands of compromised FortiGate devices are feeding active ransomware operations — and defenders who haven't rotated credentials post-patch are still exposed.

FortiBleed Credential Haul Now Feeding INC and Lynx Ransomware Crews
A single operator was spotted running negotiation panels for both gangs, turning stolen FortiGate logins into ransomware payloads.

Sysdig Flags 'JADEPUFFER' as First End-to-End AI-Run Ransomware Attack
Researchers say a large language model handled intrusion, lateral movement and destruction of a production database without a human at the keyboard.

Double Trouble: Two Unrelated Attacks Thrive on Unpatched SharePoint
Microsoft DART uncovers dual intrusions on same server, complicating response efforts.

War Room Debrief: How a Fictional Grocery Chain Got Crushed by APT 64
A tabletop exercise at Infosecurity Europe put ransomware, AI poisoning, and deepfake CEO videos inside a simulated supermarket attack. The blue team held the line. The red team shorted the stock anyway.