Ransomware — Page 2

Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Ransomware

A Microsoft-Approved Driver Is Helping 'GodDamn' Ransomware Gut US Security Tools

A rebranded criminal gang called Hyadina is using a signed Windows driver to kill antivirus software before locking victims' files. The driver carries a legitimate Microsoft stamp, and nobody knows quite how that happened.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge
Ransomware

The Gentlemen Ransomware Gang Turns Your Own IT Tools Against You

A fast-spreading criminal group is using the software your IT team trusts every day to take over company networks. The real test is not whether they got in. It is what happens next.

3 min read
Photoreal news-editorial photograph, 16:9 framing, full-frame edge-to-edge composition
Ransomware

When the Learning Platform Goes Dark, There Is No Backup Plan

A finals-week breach of a major university software platform in 2026 left students locked out of coursework and grade books. Higher education has proved twice it will pay ransoms. That changes everything.

3 min read
Full-frame edge-to-edge photoreal news-editorial image of a dimly lit government office corridor at night, a single glowing monitor visible through a half-open
Ransomware

A U.S. Government Agency Quietly Paid $1 Million to a Group That May Not Even Be Ransomware

A leaked negotiation chat and blockchain trail suggest Kairos runs pure data-theft extortion — no file-locking, just threats to leak.

3 min read
Full-frame photoreal editorial image of a dimly lit open-plan office at night, rows of monitors glowing with cascading padlock icons and encrypted file symbols,
Ransomware

Meet Avalon: The Swiss-Army Malware That Ends in Ransomware

A newly documented toolkit called Avalon steals passwords, spreads across networks, and locks up files — all from one phishing email.

3 min read
A digital representation of a firewall with a menacing shadow of a lock looming over it, symbolizing the threat of ransomware
Ransomware

FortiBleed's Credential Theft Linked to Ransomware Gangs

Researchers reveal FortiBleed's connections to ransomware groups, posing greater risks for affected organizations.

2 min read
A plain official-looking envelope resting on a wooden desk, partially open, with a single folded letter visible inside
Ransomware

Fake Interpol Arrest Notices Are Delivering Ransomware to Small Businesses

Criminals are impersonating the international police agency to frighten small business owners into downloading malware. The tactic is simple. It's working.

3 min read
Full-frame edge-to-edge photoreal image of a dimly lit server rack in a corporate data centre, one network firewall appliance glowing red among rows of blue sta
Ransomware

FortiBleed: 11,000 Fortinet Firewalls Still Compromised, Now Tied to INC and Lynx Ransomware

Researchers say the same crew that hoarded credentials from hundreds of thousands of Fortinet firewalls has been sitting inside the negotiation panels of two major ransomware gangs.

3 min read
A digital landscape showing a lock symbol over a background of binary code, symbolizing ransomware attacks
Ransomware

Ransomware Surge Led by Lockbit and Conti Offshoots

July sees a resurgence in ransomware attacks, with Lockbit and Conti offshoots dominating the landscape.

2 min read
Full-frame edge-to-edge photoreal editorial image of a dimly lit server rack in a data center with a single amber warning LED glowing on a network appliance, co
Ransomware

Anubis Affiliates Ride Citrix Bleed 2 Into Enterprise Networks

Ransomware crews are chaining CVE-2025-5777 with RMM tooling and stolen credentials to skip past MFA entirely.

3 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Ransomware

FortiBleed: Stolen FortiGate Credentials Now Fueling INC and Lynx Ransomware Attacks

Credentials harvested from hundreds of thousands of compromised FortiGate devices are feeding active ransomware operations — and defenders who haven't rotated credentials post-patch are still exposed.

3 min read
Ransomware

FortiBleed Credential Haul Now Feeding INC and Lynx Ransomware Crews

A single operator was spotted running negotiation panels for both gangs, turning stolen FortiGate logins into ransomware payloads.

2 min read
Ransomware

Sysdig Flags 'JADEPUFFER' as First End-to-End AI-Run Ransomware Attack

Researchers say a large language model handled intrusion, lateral movement and destruction of a production database without a human at the keyboard.

2 min read
Ransomware

Double Trouble: Two Unrelated Attacks Thrive on Unpatched SharePoint

Microsoft DART uncovers dual intrusions on same server, complicating response efforts.

2 min read
Ransomware

War Room Debrief: How a Fictional Grocery Chain Got Crushed by APT 64

A tabletop exercise at Infosecurity Europe put ransomware, AI poisoning, and deepfake CEO videos inside a simulated supermarket attack. The blue team held the line. The red team shorted the stock anyway.

2 min read
© 2026 Threat Vectr