Threat Source Newsletter (April 29, 2021)Cisco Talos·Apr 29, 18:00 UTC · Apr 29, 2021Ransomware in the wildCVE-2021-2289360
What Cisco Talos knows about the Rhysida ransomwareCisco Talos·Aug 8, 19:36 UTC · Aug 8, 2023Ransomware57
The BlackByte ransomware group is striking users all over the globeCisco Talos·May 18, 06:00 UTC · May 18, 2022Ransomware60
The BlackByte ransomware group is striking users all over the globeCisco Talos·May 11, 14:07 UTC · May 11, 2022Ransomware60
Velociraptor leveraged in ransomware attacksCisco Talos·Oct 9, 10:00 UTC · Oct 9, 2025RansomwareCVE-2025-626460
Cybercriminals camouflaging threats as AI tool installersCisco Talos·May 29, 10:00 UTC · May 29, 2025Ransomware57
Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangsCisco Talos·Apr 23, 10:00 UTC · Apr 23, 2025Ransomware60
From BlackMatter to BlackCat: Analyzing two attacks from one affiliateCisco Talos·Mar 17, 11:58 UTC · Mar 17, 2022Ransomware57
GhostSec’s joint ransomware operation and evolution of their arsenalCisco Talos·Mar 5, 13:00 UTC · Mar 5, 2024Ransomware60
Unwrapping the emerging Interlock ransomware attackCisco Talos·Nov 7, 11:00 UTC · Nov 7, 2024Ransomware57
Akira ransomware continues to evolveCisco Talos·Oct 21, 16:50 UTC · Oct 21, 2024Ransomware in the wildCVE-2024-40766CVE-2020-3259CVE-2023-20263+5 CVEs60
Understanding the Phobos affiliate structure and activityCisco Talos·Nov 17, 13:01 UTC · Nov 17, 2023Ransomware57
New threat actor targets Bulgaria, China, Vietnam and other countries with customized Yashma ransomwareCisco Talos·Aug 7, 12:00 UTC · Aug 7, 2023Ransomware57
Newly identified RA Group compromises companies in U.S. and South Korea with leaked Babuk source codeCisco Talos·May 15, 12:00 UTC · May 15, 2023Ransomware57
Small-time cybercrime is about to explode — We aren’t readyCisco Talos·Aug 29, 18:45 UTC · Aug 29, 2022Ransomware57
Avos ransomware group expands with new attack arsenalCisco Talos·Jun 21, 11:58 UTC · Jun 21, 2022RansomwareCVE-2021-44228CVE-2021-45046CVE-2021-45105+1 CVEs60
Back from the dead: Emotet re-emerges, begins rebuilding to wrap up 2021Cisco Talos·Nov 22, 13:00 UTC · Nov 22, 2021Ransomware57
SQUIRRELWAFFLE Leverages malspam to deliver Qakbot, Cobalt StrikeCisco Talos·Oct 26, 12:00 UTC · Oct 26, 2021Ransomware45
Vice Society leverages PrintNightmare in ransomware attacksCisco Talos·Aug 12, 22:33 UTC · Aug 12, 2021RansomwareCVE-2021-1675CVE-2021-3452760
Navigating cybersecurity in the age of remote workHelp Net Security·Jun 1, 00:00 UTC · Jun 1, 2023Ransomware57
REvil ransomware actors attack Kaseya in supply chain attackCisco Talos·Jul 3, 02:03 UTC · Jul 3, 2021RansomwareCVE-2021-3011660
Microsoft Exchange vulnerabilities exploited once again for ransomware, this time with BabukCisco Talos·Nov 3, 12:00 UTC · Nov 3, 2021RansomwareCVE-2021-3694260
Welcome Spelevo: New exploit kit full of old tricksCisco Talos·Jun 27, 19:10 UTC · Jun 27, 2019RansomwareCVE-2018-15982CVE-2018-817460
Attackers use domain fronting technique to target Myanmar with Cobalt StrikeCisco Talos·Nov 16, 12:00 UTC · Nov 16, 2021Ransomware57
Zyxel SCR 50AXE boosts network security for small businesses and remote workersHelp Net Security·May 22, 10:39 UTC · May 22, 2023Ransomware57
Back from vacation: Analyzing Emotet’s activity in 2020Cisco Talos·Nov 18, 16:00 UTC · Nov 18, 2020Ransomware57
Pylocky Unlocked: Cisco Talos releases PyLocky ransomware decryptorCisco Talos·Jan 10, 15:56 UTC · Jan 10, 2019Ransomware57
Files Cannot Be Decrypted? Challenge Accepted. Talos Releases ThanatosDecryptorCisco Talos·Jun 26, 15:00 UTC · Jun 26, 2018Ransomware57