ZeroHour

Search: “ransomware-mitigation”

14 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

12 Best Ransomware Protection Solutions Compared (2026): Features & Pricing

GBHackers compares 12 ransomware protection solutions for 2026, recommending layered stacks of EDR prevention, managed detection, containment, and guaranteed recovery.

The editorial comparison argues no single product stops ransomware, recommending a layered strategy across prevention, early detection, blast-radius containment, and clean recovery. CrowdStrike and SentinelOne are named best-in-class EDR, Huntress and Sophos MDR for managed 24/7 coverage, ColorTokens for microsegmentation containment, and Rubrik and Acronis for guaranteed recovery. The guide notes ransomware is now professionalized with double extortion and encryption sprints measured in minutes.

GBHackersupdated · 5h agofirst · 5d agoIndustry 13 sources1

Top 10 Best Ransomware Protection Solutions in 2026

A 2026 buyer's guide ranks ten ransomware protection tools by kill-chain role as extortion shifts from encryption to data theft.

The roundup organizes defenses across the ransomware kill chain: prevention-grade EPP/EDR platforms, containment layers, rollback specialists, and immutable recovery. Recommended products include CrowdStrike, Microsoft Defender, Sophos, SentinelOne, Bitdefender, Trend Micro, Halcyon, Huntress, and Malwarebytes. It stresses that many crews now extort on stolen data without encrypting, making exfiltration detection and response speed as important as rollback.

Cyber Security News · 6d agoIndustry1

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Tenable details ransomware group Storm-0501's Azure tenant-hijacking tactics and how its cloud detection and response identifies them.

Tenable's blog describes how cybercrime group Storm-0501 conducts cloud-first ransomware campaigns against Azure environments. The group has shifted from endpoint encryption to total hijacking of cloud tenants and systematically neutralizes resource locks, immutability policies, and backups. Tenable outlines its One Cloud Exposure detections, using AI-powered threat stories and precision alerts, to expose these TTPs early.

Tenable Blog · Aug 17, 2026Threat actor in the wild

Local governments in four states dealing with cyberattacks that have shut down services

Ransomware and cyberattacks disrupted local governments in California, Oklahoma, South Dakota, Texas and Wisconsin, taking Suisun City's 911 offline.

Suisun City, California (population 30,000) shut down its IT network after malicious software hit 911 routing, police and fire dispatch; the city declared a state of emergency and the FBI is investigating. Coweta, Oklahoma confirmed a ransomware attack affecting all computers and digital services, with off-site backups slated for restoration. Mitchell (South Dakota), Coryell County (Texas) and Washburn County (Wisconsin) also disclosed cyberattacks that shut down networks and disrupted phone and payment systems.

The Record · Aug 11, 2026Ransomware in the wild

Weekly Update 517: Cyber Ransoms

Troy Hunt's weekly commentary argues much ransomware is simple extortion by young actors who struggle to monetize ransoms.

In Weekly Update 517, Troy Hunt comments on the current ransomware landscape, noting many attacks involve pure extortion rather than actual malware. He observes that many actors are young and earn large sums but face practical difficulties spending ransom proceeds. The piece is opinion commentary rather than a new incident disclosure.

Troy Hunt · 29d agoIndustry

Ransomware Now Shows Up in Nearly Half of All Breaches: A Survival Playbook for Lean Security Teams

Cyble reports 5,967 ransomware attacks in 2025, up 50%, accounting for nearly half of all tracked breaches.

Cyble's Global Cybersecurity Report 2025 documented 5,967 ransomware attacks, a 50% year-over-year jump. Against 6,046 data breaches and leaks recorded in the same period, ransomware accounted for 49.7% of the combined total. The blog lays out an incident response playbook for lean security teams facing this dominant threat.

Cyble · Aug 10, 2026Ransomware

Ransomware negotiation tactics have turned into a business process

Intel 471's Dave Ross details ransomware negotiation tactics, with demands typically set at 1-5% of annual revenue and specialized criminal service roles.

In a Help Net Security video, Intel 471 Senior Director Dave Ross explains how ransomware groups research a victim's revenue and insurance coverage, run test decryptions to prove they hold a working key, and set demands at roughly 1% to 5% of annual revenue. He describes negotiation dynamics with shifting deadlines and a criminal service economy supplying language skills, data review, and legal analysis. Multi-extortion methods include data theft, DDoS attacks, and direct contact with customers and journalists.

Help Net Security · 8d agoRansomware

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics

CISA, FBI, and HHS updated their Medusa ransomware advisory, reporting over 500 victims and detailing the gang's access-broker and exploit tactics.

A joint advisory update from CISA, the FBI, and HHS expands the March 2025 Medusa guidance, drawing on a year of FBI investigations. The ransomware-as-a-service group's known victim tally grew from more than 300 to more than 500 between March 2025 and April 2026, with the Healthcare and Public Health sector frequently hit. Medusa pays access brokers $100 to $1 million, has exploited flaws such as Fortra GoAnywhere and BeyondTrust vulnerabilities, and leverages newly announced exploits within 24 hours, sometimes a week before public disclosure. The group uses living-off-the-land techniques, remote monitoring and management software, and RDP for lateral movement, and has been linked to actors including Microsoft-tracked Storm-1175 and North Korean hackers targeting healthcare.

CyberScoop · 28d agoRansomware in the wild

The true cost of a ransomware attack, with and without BCDR

Ransomware's true cost averages $5.08 million per incident versus a $139,875 median ransom, and mature BCDR strategies with immutable backups cut downtime and recovery expenses.

IBM's Cost of a Data Breach Report 2025 puts the average ransomware incident at $5.08 million, far above the $139,875 median ransom payment cited in Verizon's 2026 DBIR. Datto's State of BCDR Report 2025 found 60% of organizations believed they could recover within a day, but only 35% actually did. The Datto-sponsored piece argues mature BCDR with immutable WORM backups shortens downtime, citing a Techify case that restored 19 TB and returned a client to operations in under two hours without paying a ransom. It also flags compliance deadlines such as GDPR's 72-hour breach notification and the SEC's four-business-day disclosure rule.

BleepingComputer · 1h agoIndustry

Stronger Security Drives Ransomware Groups to Recruit From Within

Researchers report ransomware groups increasingly recruiting insiders at target companies to bypass stronger security, with insider-assisted attacks costing victims millions.

Security researchers have observed an uptick in insider-assisted ransomware attacks as organizations strengthen their defenses. Ransomware groups are reportedly recruiting from within target companies, and malicious insiders also enable other costly threats. No specific victims or campaigns are named in the report.

Dark Reading · 14d agoRansomware

Building a ransomware decision tree before the call comes in

Arctic Wolf's IR VP urges pre-deciding ransomware response choices on containment, negotiation authority, law enforcement engagement, and crisis communications.

A Help Net Security video features Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walking through a ransomware decision tree. She recommends settling four decision areas in advance: containment, extortion negotiation limits, law enforcement involvement, and communications. She frames paying as a business decision that can cost less than insurance retention and renewal hikes, and notes agencies may know the threat actor and help avoid sanctions issues.

Help Net Security · 5d agoIndustry

Medusa ransomware gang has hit over 500 organizations, CISA warns

FBI, CISA, and HHS warn Medusa ransomware has hit over 500 organizations across critical infrastructure since June 2021, using phishing and unpatched flaws.

An updated joint advisory from CISA, FBI, and HHS states Medusa ransomware has affected more than 500 organizations, spanning healthcare, defense, manufacturing, government, IT, financial services, education, insurance, and legal sectors. Since early 2023 Medusa has operated a ransomware-as-a-service affiliate model and buys access from initial access brokers for $100 to $1 million. Affiliates gain entry via phishing and unpatched internet-facing software, exploiting newly disclosed flaws in ScreenConnect, Fortinet EMS, Fortra GoAnywhere, and BeyondTrust within 24 hours. The group runs double extortion, giving victims 48 hours before leak-site publication, with $10,000 in cryptocurrency buying a one-day delay.

Help Net Security · 28d agoRansomware in the wild

Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks

CISA, FBI, and South Korean agencies warn Gunra ransomware, with 51 victims since April 2025, exploits Fortinet flaws for double-extortion attacks on critical infrastructure.

CISA, the FBI, and South Korean agencies warned of Gunra ransomware attacks targeting healthcare, financial services, government, and professional services worldwide. The Conti-derived operation exploits internet-facing Fortinet FortiOS and FortiProxy flaws CVE-2024-55591 and CVE-2025-24472 for initial access, then deploys double extortion with Salsa20/ChaCha20 encryption and publishes non-payers on a leak site within five to seven days. Ransomware.Live lists 51 victims since April 2025, mostly in South Korea, Brazil, Spain, Thailand, and Hong Kong. The group uses Impacket tools for SMB lateral movement and NTDS credential dumping, tampers with VDI authentication to accept a designated OTP value to bypass MFA, and launched a RaaS affiliate program in January 2026 under the new alias Golden Community.

The Hacker News · Aug 12, 2026Ransomware in the wildCVE-2024-55591CVE-2025-24472

Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware

FBI warns Medusa ransomware-as-a-service has hit over 500 critical infrastructure organizations while significantly improving its tactics, techniques and procedures.

The FBI warned that the Medusa ransomware-as-a-service operation has compromised more than 500 critical infrastructure organizations. The agency said the group has significantly enhanced its tactics, techniques and procedures, making it harder for defenders to counter. Defenders in critical infrastructure sectors should review exposure and harden against Medusa's updated TTPs.

Infosecurity Magazine · 28d agoRansomware in the wild