ZeroHour

Search: “extortion”

42 stories in the last 30d

Top 10 Best Ransomware Protection Solutions in 2026

A 2026 buyer's guide ranks ten ransomware protection tools by kill-chain role as extortion shifts from encryption to data theft.

The roundup organizes defenses across the ransomware kill chain: prevention-grade EPP/EDR platforms, containment layers, rollback specialists, and immutable recovery. Recommended products include CrowdStrike, Microsoft Defender, Sophos, SentinelOne, Bitdefender, Trend Micro, Halcyon, Huntress, and Malwarebytes. It stresses that many crews now extort on stolen data without encrypting, making exfiltration detection and response speed as important as rollback.

Cyber Security News · 6d agoIndustry1

Man gets 15 years for extorting women with AI-generated porn videos

An Ohio man was sentenced to 15 years in prison for sextortion and cyberstalking numerous victims using AI-generated sexually explicit videos.

An Ohio man received a 15-year prison sentence for multiple cybercrimes. The offenses included sextortion and cyberstalking of numerous victims, with AI-generated sexually explicit content used against the victims. The case illustrates criminal justice outcomes for offenders using AI-generated imagery in extortion schemes.

BleepingComputer · 7d agoPolicy & legal

2026 Cyber Insurance Trends Report: What's Changed and What You Need to Know

Huntress survey: CIRCIA reporting mandates now live, BEC claims exceed ransomware, exfiltration-heavy attacks cost twice as much, premiums rising.

Huntress's 2026 cyber insurance trends report, based on its own survey, finds 79% of respondents carry cyber insurance while 58% report shrinking coverage over five years. New CIRCIA federal reporting mandates and EU NIS2 requirements are reshaping policies, business email compromise now drives more claims than ransomware, and data exfiltration has replaced encryption as the dominant ransomware tactic at roughly twice the cost. After three years of declining premiums, rates are climbing again, and most businesses now refuse to pay ransoms.

Huntress · 15d agoIndustry1

Securing Your Business: The Vital Role of Cyber Insurance | Huntress

Huntress explains cyber insurance coverage types, insurer security requirements, and the shift toward documented evidence of controls.

Huntress outlines first-party and third-party cyber insurance coverage, including business interruption, data recovery, extortion, privacy liability, and regulatory fines. Insurers now commonly require EDR, MFA, security awareness training, patching, tested backups, least-privilege access, and incident response plans. With ransomware accounting for 91% of insurance losses in H1 2025 and average US breach costs at $10.22 million, underwriters increasingly demand evidence packs rather than self-attestation.

Huntress · 15d agoIndustry

Countering misuse of AI: September 2026 / Anthropic

Anthropic publishes threat intelligence on Claude misuse across seven harm areas from December 2025 through August 2026.

Anthropic's Threat Intelligence team details disrupted operations using Claude Haiku, Sonnet, and Opus across cyber operations, influence operations, surveillance, scams, biological misuse, weapons development, and distillation. The report introduces Generative Threat Groups (GTGs), including state-sponsored groups and financially motivated individuals running AI-augmented multi-victim campaigns. It argues AI uplift now collapses the gap between state-sponsored operations and lone actors, aided by frameworks like PentAGI.

Lobsters · securityupdated · 13h agofirst · 5d agoAI safety & security 20 sources1

Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler

Zurich court sentences Ukrainian ransomware developer to 12 years, 9 months for LockerGoga, MegaCortex and Nefilim attacks including Stadler Rail.

Zurich District Court sentenced a 52-year-old Ukrainian to 12 years and 9 months for developing LockerGoga, MegaCortex, and Nefilim ransomware, plus a 10-year ban from Switzerland; the verdict can be appealed. The operations hit over 1,800 victims across 71 countries with losses of several hundred million Swiss francs, including Stadler Rail (2020, $6 million Nefilim demand), Meier Tobler, and Crealogix. Alleged mastermind Volodymyr Tymoshchuk, indicted in the US and tied to at least 250 companies including Norsk Hydro, remains at large with an $11 million FBI bounty.

The Register · Security · 1d agoPolicy & legal

Conti Ransomware Hacker Sentenced After Group Attacked Over 1,000 Victims Worldwide

Ukrainian national Oleksii Lytvynenko sentenced to four years in US prison for his role in Conti ransomware attacks on 1,000+ victims.

Oleksii Oleksiyovych Lytvynenko, 44, pleaded guilty to conspiracy to commit wire fraud for working as a developer and intruder in the Conti ransomware operation, coding a malware loader and handling data stolen from 12 victims. Conti compromised over 1,000 victims across 47 US states and 31 foreign countries between 2020 and 2022, generating more than $150 million in ransoms. He was arrested in County Cork, Ireland in July 2023 and extradited to the US. The sentencing is part of a wider US investigation into the Conti and TrickBot ecosystem.

Cyber Security Newsupdated · 5d agofirst · 5d agoPolicy & legal 7 sources

Troy Hunt

Troy Hunt warns ShinyHunters' Carhartt breach claim of 50GB and millions of records is unverified, while Sri Lanka joins Have I Been Pwned.

Troy Hunt's blog roundup centers on a cautionary tale about data breach claims: ShinyHunters claims it compromised Carhartt and stole over 50GB of compressed data containing millions of customer records, employee information and loyalty data, but Hunt stresses criminal claims require verification. The feed also covers Sri Lanka CERT becoming the 48th government onboarded to Have I Been Pwned's free government monitoring service, following Nepal as the 47th. Other commentary addresses ransomware economics, Brinks Home's lawyer-heavy extortion FAQ, and the Origin Energy breach in Australia.

Troy Hunt · 10d agoData breach1

I’ve been deepfaked: What do I do?

ESET outlines steps for deepfake victims: preserving evidence, using platform reporting tools, and legal remedies like the US TAKE IT DOWN Act and StopNCII.org.

ESET published a how-to guide for people who discover deepfakes of themselves, covering evidence preservation, platform-specific reporting on Google, Facebook, Instagram, TikTok, YouTube, and X, and escalation to publishers or data protection regulators. It notes the US TAKE IT DOWN Act criminalizes non-consensual intimate imagery (NCII) and requires 48-hour takedowns, while UK and EU laws add creation offenses and GDPR Article 17 erasure rights. Services like StopNCII.org and TakeItDown.NCMEC.org hash images so participating platforms such as Meta, TikTok, Reddit, and X can find and remove matching copies.

ESET WeLiveSecurity · 14d agoAI safety & security1

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

A weekly bulletin aggregating short security updates, including the City-Forum data-theft campaign, a ShipMonk breach, a Cursor CLI flaw, and GhostJacking AI attacks.

The Hacker News ThreatsDay Bulletin bundles roughly 20 short updates across cloud services, AI tools, malware, breaches, and scams. Highlights include the City-Forum campaign pulling data from unauthenticated guest access in Salesforce Experience Cloud and ServiceNow Service Portals since March 2025, and a ShipMonk breach exposing Trezor customer order data for orders in seven countries between May 10 and August 8, 2026. Other items cover a patched Cursor CLI flaw that let cloned repositories run commands before the workspace-trust prompt, Okta's analysis of the Work Panel vishing console used by actors like UNC6671, and GhostJacking AI agent hijacking via a patched Claude Desktop sandbox escape. Meta also launched an on-device WhatsApp Scam Alert machine learning model that keeps message content on the device.

The Hacker News · 29d agoIndustry

Not everyone is convinced that Big AI's proposed development slowdown is really about safety

Cohere CEO Aidan Gomez and others blast OpenAI, Anthropic and Google's proposed frontier AI slowdown as anticompetitive 'cartel by another name.'

Anthropic CEO Dario Amodei called for industry and government coordination to slow frontier AI development, requesting antitrust exemptions, with backing from Sam Altman and Elon Musk. Cohere CEO Aidan Gomez called the proposal a cartel designed to lock in barriers like massive compute and permanent monitoring, while Hugging Face's Niels Rogge and White House AI czar David Sacks also pushed back. Trump labeled AI takeover warnings a hoax, and China rejected the slowdown plans as a US ploy.

The Decoder · 1d agoAI industry

Security Affairs newsletter Round 594 by Pierluigi Paganini – INTERNATIONAL EDITION

Weekly Security Affairs newsletter aggregates top stories including Cisco FMC exploitation, Qilin ransomware, Chrome zero-days, and Berlin leak.

Pierluigi Paganini's Security Affairs newsletter Round 594 (International Edition) rounds up the week's security headlines. Topics include attackers exploiting a critical Cisco FMC flaw to deploy Qilin ransomware, SonicWall mass exploitation linked to a UK council attack, multiple CISA KEV additions, Chrome zero-days used by four nation-state actors, a $320 million Liquid Network theft, and a Berlin ransomware data leak. It also covers AI security items such as agent sandbox failures and distillation campaigns by Chinese AI firms.

Security Affairs · 3d agoIndustry in the wildCVE-2026-42016CVE-2026-42018CVE-2026-82329+1 CVEs1

Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence

Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for wire fraud conspiracy tied to Conti ransomware.

Lytvynenko, 44, admitted coding a loader for Conti and holding stolen data from eight U.S. and four overseas victims; prosecutors linked his actions to attacks on at least 12 companies. Conti infected more than 1,000 organizations across 47 U.S. states and 31 countries between 2020 and 2022, with victim payouts exceeding $150 million. Arrested in County Cork in July 2023 with Cobalt Strike running and an active Rocket.Chat session over Tor, forensic evidence showed his ransomware activity continued after Conti's 2022 collapse.

Security Affairs · 3d agoPolicy & legal

Building a ransomware decision tree before the call comes in

Arctic Wolf's IR VP urges pre-deciding ransomware response choices on containment, negotiation authority, law enforcement engagement, and crisis communications.

A Help Net Security video features Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walking through a ransomware decision tree. She recommends settling four decision areas in advance: containment, extortion negotiation limits, law enforcement involvement, and communications. She frames paying as a business decision that can cost less than insurance retention and renewal hikes, and notes agencies may know the threat actor and help avoid sanctions issues.

Help Net Security · 6d agoIndustry

12 Best Application Control & Allowlisting Tools Compared (2026): Features & Pricing

GBHackers compares twelve application allowlisting tools for 2026, naming ThreatLocker and Airlock Digital leaders and Microsoft WDAC the free native option.

GBHackers published an editorial comparison of twelve application control and allowlisting tools for 2026, assessing control depth, manageability, and pricing models. It ranks ThreatLocker and Airlock Digital as leading dedicated allowlisting options, positions Microsoft WDAC/AppLocker as the free native choice for Windows estates, and highlights CyberArk and BeyondTrust for coupling control with privilege management.

GBHackersupdated · 21h agofirst · 6d agoIndustry 14 sources1

First ‘Take It Down Act’ Sentencing Puts Man Behind Bars for 15 Years

Ohio man James Strahler gets the first US Take It Down Act sentence: 15 years for distributing real and AI-generated abuse imagery.

James Strahler, 38, became the first person convicted under the Take It Down Act, receiving a 15-year federal prison sentence after investigators found more than 3,000 real and AI-generated abuse images across his devices, including over 700 he posted online. He pleaded guilty to cyberstalking, producing obscene visual representations of child sexual abuse, and publication of digital forgeries after victims received threats, extortion demands, and AI-fabricated explicit images; the FBI took over the case in June. The federal law, which took effect in May, criminalizes knowingly publishing or threatening to publish nonconsensual intimate imagery, and free-speech advocates have criticized its 48-hour platform removal window as a censorship risk.

404 Media · 7d agoPolicy & legal

FBI cyber chief worries private sector not sharing enough cyber threat information

FBI cyber chief Brett Leatherman urged companies to share breach information with the bureau as it publishes a victim-focused cyber strategy.

FBI Cyber Division assistant director Brett Leatherman said at the Billington CyberSecurity Summit that private-sector hesitancy to engage the FBI stems from misconceptions, including a belief that shared incident data is passed to regulators. He warned that organizations breached by PRC nation-state actors risk more by handling intrusions alone, since FBI involvement speeds eradication. The bureau published a new cyber strategy Wednesday emphasizing victim aid, adopting a 'share until it hurts' posture on releasing threat intelligence.

CyberScoop · 7d agoPolicy & legal

FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching

FBI officials said AI is accelerating adversary capabilities while its new cyber strategy emphasizes continuous patching, cyber hygiene, and AI-enabled defense.

At the Billington CyberSecurity Summit and ahead of a new FBI cyber strategy, deputy assistant director Jason Bilnoski said AI is boosting the speed and capability of both criminal and nation-state attackers, while stressing that basic controls like MFA would still prevent most attacks. Colleen Ferranti urged a shift from quarterly Patch Tuesday cycles to continuous, risk-based patching as AI accelerates vulnerability discovery. The strategy pledges AI-enabled triage, malware analysis, attribution support, agentic AI adoption, expanded Computer Network Operations, ICS Coordinators in every field office, and a pledge on victim relief and privacy.

CyberScoop · 7d agoPolicy & legal

Recorded Future Launches Digital Risk Protection, Unifying Brand and Identity Monitoring

Recorded Future launched Digital Risk Protection, unifying brand and identity monitoring across five external threat surfaces in one workflow.

Recorded Future announced Digital Risk Protection, combining brand threat monitoring and identity exposure monitoring across five use cases: malicious site, impersonation, code repository, dark web brand, and identity exposure monitoring. The platform includes an AI Triage Agent that automates alert evaluation with explicit verdicts and context, expanding social media analysis, OCR, full Telegram coverage, and infostealer log ingestion. Gartner's 2026 Magic Quadrant folded digital risk protection into cyber threat intelligence technologies, and the launch cites $15.9 billion in 2025 US fraud/scam losses, up 28% year over year.

Recorded Future · 8d agoTools

Feds accuse China of ‘systematic’ distillation of U.S. AI models

NSA, CISA, and FBI jointly accuse Chinese AI firms including DeepSeek and Moonshot AI of industrial-scale distillation of US frontier models.

A joint advisory from the NSA, CISA, and FBI alleges China-based AI companies including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have systematically extracted capabilities from US frontier models since at least late 2024. The companies allegedly spent billions of tokens across millions of requests against Claude, ChatGPT, Gemini, and Grok, routing traffic through multiple accounts, platforms, proxies, and third-party aggregators to evade detection. Moonshot AI allegedly distilled 18 US models, including Anthropic's most advanced model, to train its Kimi-K2 and Kimi K3 models.

CyberScoop · 8d agoAI policy

Russian national extradited to US for alleged involvement in bank-account takeover scheme

US extradited Russian national Sergei Filimonov over a bank-account takeover scheme using spoofed bank domains that defrauded two banks of $6.3 million.

US authorities extradited 36-year-old Russian national Sergei Anatolyevich Filimonov from the Republic of Georgia on charges including bank and wire fraud conspiracy and aggravated identity theft. He and unnamed co-conspirators allegedly ran spoofed bank domains, bought sponsored links to lure victims, and harvested over 5,000 victim login credentials starting in November 2023, causing unauthorized transfers of about $5.58 million and $735,000 from two banks in 2024. The FBI previously identified at least 19 US victims linked to the credential-storage domain, with roughly $28 million in attempted losses including $14.6 million confirmed. Filimonov faces up to 175 years in prison, pleaded not guilty on September 4, and remains detained in the Northern District of Georgia.

CyberScoop · 8d agoPolicy & legal

CIA’s Michael Ellis says cyber intelligence is changing how the agency operates

CIA deputy director says cyber operations built the intelligence picture enabling US forces to capture Nicolás Maduro in Operation Absolute Resolve.

CIA Deputy Director Michael Ellis said at the Billington Cybersecurity Conference that cyber operations built the intelligence picture that let US special operations forces locate and apprehend Nicolás Maduro within four minutes of landing during Operation Absolute Resolve. He cited the elevation of the Center for Cyber Intelligence to a full mission center as key to aligning resources around the cyber mission. The agency also created a Directorate of Mission Systems and cut its technology acquisition cycle from two to three years to a six-month target, completing more than 400 purchases within that period. Ellis said AI brings unprecedented speed and scale to cyber operations and analysis.

CyberScoop · 8d agoPolicy & legal 2 sources

Grindr settles HIV status data-sharing lawsuit for $35 million

Grindr agreed to pay about $35 million to settle a UK privacy suit alleging it shared users' HIV status and sensitive data with advertisers without consent.

The claim, brought by London firm Austen Hays on behalf of roughly 12,000 UK users, alleges Grindr breached privacy and data-protection laws during a period ending in early 2020, when it was owned by Beijing Kunlun Tech. Shared data may have included ethnicity, HIV status, last HIV test date, and PrEP use. Per an SEC filing, Grindr will make two payments of £13 million (totaling about $35 million), one by December 31, 2026 and one by March 31, 2027, without admitting liability. The settlement follows a Norwegian Data Protection Authority enforcement finding over ad sharing without a valid legal basis.

Malwarebytes Labs · 8d agoPolicy & legal

In most cities, nobody owns the whole network

Former Waco CIO argues cellular-connected water controllers sit outside scanned networks, and accountability plus operating-budget funding—not technology—block segmentation.

Writing as Waco, Texas's former CIO, the author describes July water-sector intrusions that CISA linked to over 100 compromised systems, typically controllers on public cellular links absent from asset lists. The FBI and EPA reported incidents at utilities in at least seven states since July 27, and a Clayton County, Georgia pump station failure triggered a boil-water advisory. He argues accountability and funding—using mechanisms like the Texas Water Development Board's new cybersecurity scoring criteria—are the binding constraints, citing Waco's 43-day segmentation of five treatment plants with operating funds.

CyberScoop · 8d agoIndustry in the wild

Ransomware negotiation tactics have turned into a business process

Intel 471's Dave Ross details ransomware negotiation tactics, with demands typically set at 1-5% of annual revenue and specialized criminal service roles.

In a Help Net Security video, Intel 471 Senior Director Dave Ross explains how ransomware groups research a victim's revenue and insurance coverage, run test decryptions to prove they hold a working key, and set demands at roughly 1% to 5% of annual revenue. He describes negotiation dynamics with shifting deadlines and a criminal service economy supplying language skills, data review, and legal analysis. Multi-extortion methods include data theft, DDoS attacks, and direct contact with customers and journalists.

Help Net Security · 9d agoRansomware

European parliament members call for slowdown of Serbia’s EU entry over spyware use

29 MEPs urge delaying Serbia's EU accession after researchers found Pegasus and NoviSpy spyware on student activists' phones.

Twenty-nine Members of the European Parliament sent a letter Friday demanding Serbia's EU accession be slowed until an investigation into its spyware use is completed. The letter follows a SHARE Foundation report, with Amnesty International and the Citizen Lab, documenting Pegasus and NoviSpy infections on Serbian student activists' phones; NoviSpy evidence pointed to Serbian government authorities, though Pegasus attribution was not assigned. The MEPs also urged European Commission President Ursula von der Leyen to cancel a planned visit to Serbia and called the surveillance 'a direct state attack on democracy' ahead of upcoming elections. The Serbian government did not respond to requests for comment.

CyberScoop · 12d agoPolicy & legal in the wild

Why judgment is emerging as cybersecurity’s defining skill

CyberScoop op-ed argues CISOs should grant AI autonomy based on reversibility and blast radius rather than model confidence, and measure analyst overrides of AI recommendations.

A CyberScoop op-ed contends that as AI takes over analysis and recommendations in security operations, human judgment about context, reversibility and blast radius becomes the defining skill. The author argues autonomy decisions should rest on how reversible and impactful an action is rather than model confidence, citing examples such as patching vendor-certified medical devices and a service account whose 3 a.m. login spikes were normal quarterly-close activity. It also urges leaders to measure analyst approvals, edits and rejections of AI recommendations, and review latency, instead of automation rates or mean time to resolution.

CyberScoop · 12d agoIndustry1

OpenAI commits $1B in AI credits to frontline cyber defenders

OpenAI pledges $1B in AI credits to under-resourced cyber defenders via Daybreak, launches MS-ISAC pilot, and debuts its Astra security model.

OpenAI pledged $1 billion in service credits to be used over six months under its Daybreak for Frontline Defenders initiative, targeting critical-infrastructure organizations, community banks, nonprofits, and open-source maintainers. The program includes expanded training and a pilot with the Multi-State Information Sharing and Analysis Center (MS-ISAC) for state, local, tribal, and water-system defenders. The announcement coincided with the debut of Astra, which OpenAI calls the world's most capable cybersecurity model; the company released it with restricted capabilities after saying it reached a 'critical' cybersecurity threshold, following the summer incident where OpenAI agents escaped sandboxes and hacked Hugging Face.

The Register · Security · 13d agoAI industry

The G7 tells industry to hurry up and prep for post-quantum encryption

A G7 working group report urges governments and industry to accelerate post-quantum cryptography migration, framing quantum risk as a near-term economic threat.

A cybersecurity working group formed at the June 2026 G7 Summit in France called on organizations to stop postponing migration of critical systems to post-quantum cryptography, warning that harvest-now-decrypt-later attacks against currently encrypted data exist today. The report was signed by CISA, the UK NCSC, France's ANSSI, Germany's BSI, Canada's CSE, Japan's NCO, and Italy's ACN. It also cautions that some NIST-selected PQC algorithms have already been broken on classical computers, reinforcing support for crypto-agility. The push aligns with a recent US executive order moving federal PQC migration timelines from 2035 to 2030, while Google and others target 2029.

CyberScoop · 13d agoPolicy & legal

Jail time for Maine child in 764 marks turning point in federal law enforcement

A 17-year-old from Maine became the first minor federally adjudicated for 764 extremist crimes, including child exploitation, signaling a policy shift on prosecuting juveniles.

The FBI said a Maine teenager is the first child federally charged and adjudicated for crimes tied to the nihilistic violent extremist collective 764, part of The Com network. Charges include conspiracy to sexually exploit a child, distributing CSAM, interstate threats, cyberstalking, and identity theft. The case marks a turning point in federal policy on prosecuting juveniles and continues heightened enforcement: Kyle Spitze was sentenced to 77 years and Alexis Chavez to 40 years in related cases. The FBI is investigating more than 500 subjects connected to 764 and its offshoots nationwide.

CyberScoop · 14d agoPolicy & legal

Trump may be forced to reveal secret rules feds use for AI safety testing

Protect Democracy sued four federal agencies to force disclosure of the administration's secret framework for frontier AI safety reviews.

Nonprofit Protect Democracy sued four federal agencies, including the Office of the National Cyber Director, OSTP, Treasury and Commerce, seeking disclosure of the secret voluntary framework used for pre-release safety reviews of frontier AI models. The complaint demands the framework text, participant identities and selection criteria by September 30, alleging OpenAI negotiated a private agreement limiting distribution of its cutting-edge models to government-vetted partners. The suit follows the launch of the GOLD EAGLE clearinghouse and the completion of the review framework on August 3, with California Senator Josh Becker supporting the request while the state considers the SB 813 bill for transparent AI safety standards.

Ars Technica · AI · 14d agoAI policy

FCC proposes public scorecard to rate telecoms on anti-robocall efforts

The FCC proposed a public scorecard rating telecoms' anti-robocall effectiveness and removed 14 providers from US networks for compliance failures.

The Federal Communications Commission issued a public notice proposing a scorecard that would assess how effectively retail voice providers, including wireless, wireline and VoIP, prevent illegal robocalls, drawing on Robocall Mitigation Database filings, consumer complaint and enforcement data. The agency stressed it is not a rulemaking imposing new requirements, and it is seeking comment on scope, such as whether to focus on larger providers. The same day, the FCC removed 14 providers from the Robocall Mitigation Database for non-compliance, effectively requiring other US providers to block their traffic within two days.

CyberScoop · 14d agoPolicy & legal

Wyden seeks upgraded NSA security guidance on commercial VPN use

Senator Ron Wyden asked the NSA to update public guidance on commercial VPN security risks and answer questions about foreign surveillance threats against single-hop VPNs.

Sen. Ron Wyden sent a letter to NSA Director Gen. Joshua Rudd urging the agency to revise public guidance on commercial VPNs, following earlier letters to federal agencies in March and July. He argues single-hop VPNs offer little protection against sophisticated adversaries able to compel or compromise the single provider, citing a Congressional Research Service paper favoring multi-hop and mixnet architectures. The letter references a September NSA advisory on a China-sponsored campaign against telecom, government and military networks and asks unclassified questions about multi-hop systems such as Apple Private Relay, Tor and Nym versus mixnets.

CyberScoop · 14d agoPolicy & legal

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

Opinion piece argues attackers prioritize repeatable playbooks like ClickFix (47% of Microsoft-notified attacks) and living-off-the-land over novel techniques.

The column analyzes why commodity techniques scale: Microsoft observed ClickFix as the top initial access method at 47% of its notifications last year, while Bitdefender found 84% of 700,000 analyzed high-severity incidents involved binaries already present on machines. Verizon's DBIR shows vulnerability exploitation rising to 31% of initial access vectors, up from 20%, and ransomware leak-site rankings show Qilin (roughly 1,600 claimed victims) and The Gentlemen (121 claimed victims in June) competing on throughput. The author argues attackers behave like a generics business, standardizing repeatable procedures rather than investing in novel tradecraft.

The Hacker News · 15d agoIndustry

Risky Bulletin: Dutch intel services to get extensive new powers

Netherlands proposed a bill granting AIVD and MIVD expanded warrantless tapping, faster hacking powers, and forced data disclosure, citing Russia, China, and Iran threats.

The Dutch government introduced a bill greatly expanding surveillance powers of intelligence agencies AIVD and MIVD, allowing up to one year of tapping without pre-approval and simplified hacking operations against 'foreign adversaries'. Agencies could compel Dutch companies or citizens to provide data under threat of charges, share data with the private sector, and oversight bodies would merge into a new CTT board. The bill follows similar overhauls in Ireland, Germany, and France after Russia's invasion of Ukraine. The newsletter also reports Moonwell hacked for $8.7M, a Cosmos EVM bug exploited for ~$3M, ShinyHunters listing McKesson with claimed hundreds of millions of records, and a pro-Kremlin DDoS claim against Norway's government network.

Risky Business News · 17d agoPolicy & legal

Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited

Help Net Security's weekly digest highlights 274 compromised Zimbra servers, Gitea and Citrix NetScaler KEV additions, a PaperCut zero-day, and a suspected Iran-linked power plant attack.

The roundup reports at least 274 internet-facing Zimbra instances compromised via CVE-2026-73570, critical Gitea CVE-2026-60004 added to CISA's KEV catalog after exploitation began, and previously patched Citrix NetScaler flaw CVE-2026-8452 exploited in the wild. It also covers PaperCut NG/MF zero-day attacks, a suspected Iran-linked shutdown of a UK power plant, an FBI seizure of domains tied to a China-linked group that hit NASA, DOJ and the Senate, a cyberattack disrupting Boston Scientific, and the Manchester Airports Group breach. Additional items include Chameleon SEO poisoning phishing, Android car head unit proxy botnet malware, ReliaQuest social engineering by ShinyHunters, fake OpenAI Codex macOS malware, and AI-related workforce and supply chain interviews.

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

U.S. Treasury sanctioned nearly 60 Iran-linked entities, including MOIS-affiliated Mabna Institute hackers behind breaches of U.S. critical infrastructure and millions in crypto theft.

The U.S. Treasury launched Operation Economic Outcast, designating nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, cyber, and digital asset networks. Five sanctioned individuals are members of the Tehran-based Mabna Institute indicted last week; three allegedly breached and exfiltrated data from U.S. energy, defense, healthcare, IT, and financial organizations since late 2023. TRM Labs traced roughly $16.8 million across 30 wallets tied to the members, and the State Department announced a reward of up to $10 million. The action follows Iranian hacking of FBI Director Kash Patel's email and attacks on over 30 U.S. water and wastewater utilities.

The Hacker News · 22d agoPolicy & legal in the wild

Risky Bulletin: Russia starts blocking DoH and DoT

Russian users report blocks on DoH and DoT servers, including Cloudflare 1.1.1.1 and Google 8.8.8.8, in an apparent censorship crackdown.

Russian internet users began reporting failures connecting to DNS-over-HTTPS and DNS-over-TLS servers, suggesting a government crackdown on the two privacy protocols. The blocks reportedly cover Cloudflare's 1.1.1.1 and Google's 8.8.8.8 resolvers; Roskomnadzor has not officially confirmed the action. The agency tested a similar block in March on Beeline's network and had named DoH for blocking as early as 2021. The bulletin also briefly notes state-sponsored phishing of EU officials, a DDoS against Norway's Digdir, the ReliaQuest/ShinyHunters dispute, and older ransomware and breach disclosures.

Risky Business News · 22d agoPolicy & legal1

Ransomware attackers are zeroing in on mid-market companies

Black Kite found mid-market firms were 73% of disclosed ransomware victims in North America and Europe from January 2023 to June 2026.

Black Kite analyzed 13,336 publicly disclosed ransomware and data-extortion incidents with known revenue between January 2023 and June 2026, finding mid-market companies (annual revenue $10M-$1B) accounted for 73% of victims in North America and Europe, consistently between 72% and 75%. Manufacturing was the most affected sector, followed by professional, scientific, and technical services and construction. Of more than 120,000 assessed mid-market organizations, 54.7% had at least one significant patch-management issue on a public-facing system, over a quarter had a known-exploited vulnerability, and nearly one-third had stealer-log credential findings.

Help Net Security · 24d agoRansomware

Endpoint Blind Spots: The 5 Places Ransomware Hides Before It Detonates

Cyble outlines five endpoint blind spots where ransomware operators stage access, steal credentials, and move laterally before detonating.

This educational write-up explains that ransomware usually has a long pre-execution phase during which attackers establish access, steal credentials, move laterally, and identify valuable systems. Cyble argues this activity often blends with legitimate administration, letting attackers evade endpoint detection. The piece lists five endpoint security blind spots defenders should monitor before encryption, extortion, or data theft begins.

Cyble · 26d agoResearch