A new alert system from CISA seems to be effective — now we just need companies to sign upCisco Talos·May 9, 18:00 UTC · May 9, 2024Ransomware in the wildCVE-2023-4960660
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 FlawsThe Hacker News·Aug 3, 16:15 UTC · Aug 3, 2026RansomwareCVE-2026-15409CVE-2026-15410160
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root AccessThe Hacker News·Jul 20, 16:44 UTC · Jul 20, 2026RansomwareCVE-2026-15409CVE-2026-1541060
North Korean Hackers Spotted Using New MultiThe Hacker News·Jul 23, 09:18 UTC · Jul 23, 2020Ransomware57
Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026The Hacker News·Mar 21, 07:03 UTC · Mar 21, 2026Ransomware in the wildCVE-2026-2013160
Talos IR trends Q4 2024: Web shell usage and exploitation of publicCisco Talos·Jan 30, 11:00 UTC · Jan 30, 2025Ransomware57
Black Basta ransomware gang linked to a malware campaignSecurity Affairs·Aug 15, 08:40 UTC · Aug 15, 2024RansomwareCVE-2022-2692360
Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR ToolsThe Hacker News·Apr 6, 10:07 UTC · Apr 6, 2026Ransomware57
A Multi-Method Approach to Identifying Rogue Cobalt Strike ServersRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Ransomware57
New BYOVD loader behind DeadLock ransomware attackCisco Talos·Dec 9, 11:00 UTC · Dec 9, 2025RansomwareCVE-2024-5132460
TA505 Cybercrime targets system integrator companiesSecurity Affairs·Nov 12, 13:50 UTC · Nov 12, 2019Ransomware57
2025 Cloud Threat Hunting and Defense LandscapeRecorded Future·Nov 6, 00:00 UTC · Nov 6, 2025Ransomware57
Iranian APT UNC1860 Linked to MOIS Facilitates Cyber Intrusions in Middle EastThe Hacker News·Sep 20, 12:44 UTC · Sep 20, 2024RansomwareCVE-2019-060460
Darknets in the Deep Web, the home of assassins and pedosSecurity Affairs·Apr 22, 21:52 UTC · Apr 22, 2017Ransomware60
March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC ZeroRecorded Future·Jun 3, 00:00 UTC · Jun 3, 2026Ransomware in the wildCVE-2017-7921CVE-2026-27483CVE-2026-27944+10 CVEs260
Friday Squid Blogging: Brittle Star Catches a SquidSchneier on Security·Jan 29, 08:02 UTC · Jan 29, 2020Ransomware57
Hackers Exploit Mitel VoIP ZeroThe Hacker News·Jun 27, 05:55 UTC · Jun 27, 2022RansomwareCVE-2022-29499CVE-2022-29854CVE-2022-2985560
ThreatsDay Bulletin: Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More StoriesThe Hacker News·Jun 25, 12:30 UTC · Jun 25, 2026RansomwareCVE-2026-8932CVE-2026-5016060
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channelCisco Talos·Jul 23, 10:00 UTC · Jul 23, 2026Ransomware57
Head Mare and Twelve: Joint attacks on Russian entitiesKaspersky Securelist·Mar 13, 10:07 UTC · Mar 13, 2025RansomwareCVE-2023-38831CVE-2021-2685560
Attackers exploited a Mitel VOIP zeroSecurity Affairs·Jun 25, 11:59 UTC · Jun 25, 2022RansomwareCVE-2022-2949960
Blind Eagle Hacking Group Targets South America With New ToolsInfosecurity Magazine·Jan 6, 17:00 UTC · Jan 6, 2023Ransomware57
Threat Assessment: Black Basta RansomwarePalo Alto Unit 42·Jun 5, 17:55 UTC · Jun 5, 2024Ransomware60
Your Organization’s Network Access Is King: Here’s What to Do About ItRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Ransomware57
Interlock group exploiting the CISCO FMC flaw CVE-2026Security Affairs·Mar 19, 09:22 UTC · Mar 19, 2026RansomwareCVE-2026-2013160
De-anonymizing ransomware domains on the dark webCisco Talos·Jun 28, 12:00 UTC · Jun 28, 2022Ransomware57
Lemon Duck brings cryptocurrency miners back into the spotlightCisco Talos·Oct 13, 14:59 UTC · Oct 13, 2020Ransomware57
North Korean Hackers Target Critical Infrastructure for Military GainInfosecurity Magazine·Jul 26, 11:02 UTC · Jul 26, 2024Ransomware60
Threat Assessment: BlackByte RansomwarePalo Alto Unit 42·Jun 5, 22:40 UTC · Jun 5, 2024RansomwareCVE-2021-34473CVE-2021-34523CVE-2021-31207160
Modified Zyklon and plugins from IndiaCisco Talos·May 23, 13:05 UTC · May 23, 2017RansomwareCVE-2013-3906CVE-2012-185660
Head Mare hacktivists: attacks on companies in Russia and BelarusKaspersky Securelist·Sep 2, 10:00 UTC · Sep 2, 2024RansomwareCVE-2023-3883160
Attackers use domain fronting technique to target Myanmar with Cobalt StrikeCisco Talos·Nov 16, 12:00 UTC · Nov 16, 2021Ransomware57
Player 3 Has Entered the Game: Say Hello to 'WannaCry'Cisco Talos·May 12, 22:09 UTC · May 12, 2017Ransomware57
Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangsCisco Talos·Apr 23, 10:00 UTC · Apr 23, 2025Ransomware60