Ransomware in 2025: Blending in is the strategyCisco Talos·Mar 31, 10:00 UTC · Mar 31, 2026Ransomware57
A Multi-Method Approach to Identifying Rogue Cobalt Strike ServersRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Ransomware57
Storm-2603 Deploys DNS-Controlled Backdoor in Warlock and LockBit Ransomware AttacksThe Hacker News·Aug 6, 14:41 UTC · Aug 6, 2025RansomwareCVE-2025-49706CVE-2025-4970460
Talos IR ransomware engagements and the significance of timeliness in incident responseCisco Talos·Jul 16, 10:00 UTC · Jul 16, 2025RansomwareCVE-2024-57727160
What is UserAssist and how to use it in IR activities?Kaspersky Securelist·Jul 14, 10:00 UTC · Jul 14, 2025Malware30
Head Mare and Twelve: Joint attacks on Russian entitiesKaspersky Securelist·Mar 13, 10:07 UTC · Mar 13, 2025RansomwareCVE-2023-38831CVE-2021-2685560
Medusa ransomware hit over 300 critical infrastructure organizations until February 2025Security Affairs·Mar 13, 08:49 UTC · Mar 13, 2025RansomwareCVE-2024-1709CVE-2023-4878860
Analyzing the familiar tools used by the Crypt Ghouls hacktivistsKaspersky Securelist·Oct 18, 10:00 UTC · Oct 18, 2024Ransomware57
Analysis of the BlackJack group: techniques, tools, and similarities with TwelveKaspersky Securelist·Sep 25, 10:00 UTC · Sep 25, 2024Ransomware57
Twelve: from initial compromise to ransomware and wipersKaspersky Securelist·Sep 20, 13:33 UTC · Sep 20, 2024RansomwareCVE-2021-21972CVE-2021-2200560
New Rust-Based Ransomware Cicada3301 Targets Windows and Linux SystemsThe Hacker News·Sep 3, 13:16 UTC · Sep 3, 2024Ransomware57
LockBit 2.0: How This RaaS Operates and How to Protect Against ItPalo Alto Unit 42·Jun 5, 20:38 UTC · Jun 5, 2024Ransomware57
Talos IR trends: BEC attacks surge, while weaknesses in MFA persistCisco Talos·Apr 25, 12:00 UTC · Apr 25, 2024Phishing & fraudCVE-2021-27876CVE-2023-27532147
IR Q4 2023 trends: Significant increase in ransomware activity found in engagements, while education remains one of the mostCisco Talos·Jan 24, 13:00 UTC · Jan 24, 2024RansomwareCVE-2020-147260
FBI and CISA published a new advisory on AvosLocker ransomwareSecurity Affairs·Oct 13, 10:55 UTC · Oct 13, 2023Ransomware57
Think Your MFA and PAM Solutions Protect You? Think AgainThe Hacker News·Sep 18, 12:21 UTC · Sep 18, 2023Ransomware60
New Report Exposes Vice Society's Collaboration with Rhysida RansomwareThe Hacker News·Aug 10, 03:41 UTC · Aug 10, 2023Ransomware57
Overview of ransomware trends in 2023Kaspersky Securelist·May 10, 19:56 UTC · May 10, 2023RansomwareCVE-2022-26522CVE-2022-2652360
Iranian Hackers Compromised a U.S. Federal Agency’s Network Using Log4Shell ExploitThe Hacker News·Nov 17, 08:45 UTC · Nov 17, 2022Data breachCVE-2021-4422860
Server-side attacks, C&C in public clouds and other MDR cases we observedKaspersky Securelist·Nov 2, 08:00 UTC · Nov 2, 2022Vulnerability30
Quarterly Report: Incident Response Trends in Q3 2022Cisco Talos·Oct 25, 12:00 UTC · Oct 25, 2022RansomwareCVE-2020-147260
Kaspersky crimeware report: infection and propagation methodsKaspersky Securelist·Oct 5, 09:00 UTC · Oct 5, 2022Ransomware57
Quarterly Report: Incident Response Trends in Q2 2022Cisco Talos·Jul 26, 14:03 UTC · Jul 26, 2022RansomwareCVE-2021-44228CVE-2021-4504660
Removing the blind spots that allow lateral movementHelp Net Security·Jul 19, 00:00 UTC · Jul 19, 2022Threat actor60
Vice Society leverages PrintNightmare in ransomware attacksCisco Talos·Aug 12, 22:33 UTC · Aug 12, 2021RansomwareCVE-2021-1675CVE-2021-3452760
Quarterly Report: Incident Response trends from Winter 2020Cisco Talos·Mar 24, 12:26 UTC · Mar 24, 2021RansomwareCVE-2021-26855CVE-2020-5902CVE-2019-1893560
Microsoft February 2021 Patch Tuesday fixes 56 bugs, including an actively exploited Windows zeroSecurity Affairs·Feb 9, 22:27 UTC · Feb 9, 2021Vulnerability in the wildCVE-2021-1732CVE-2021-24078CVE-2021-24074+48 CVEs260
Red Team — Automation or Simulation?The Hacker News·Sep 28, 11:06 UTC · Sep 28, 2020AI safety & security30
Incident Response Analyst Report of 2019Kaspersky Securelist·Aug 6, 10:00 UTC · Aug 6, 2020Ransomware57
How attackers target and exploit Microsoft Exchange serversHelp Net Security·Jun 25, 00:00 UTC · Jun 25, 2020VulnerabilityCVE-2020-068835
Quarterly report: Incident Response trends in Summer 2020Cisco Talos·Jun 15, 14:55 UTC · Jun 15, 2020RansomwareCVE-2019-19781CVE-2019-1151060
CISA warns that Pulse Secure VPN issue CVE-2019Security Affairs·Jan 11, 06:57 UTC · Jan 11, 2020AdvisoryCVE-2019-11510CVE-2019-11539CVE-2018-1337960
New MegaCortex Ransomware targets enterprise networksSecurity Affairs·May 7, 08:46 UTC · May 7, 2019Ransomware57
Increasing security measures are driving cybercriminals to alter their techniquesHelp Net Security·Feb 27, 00:00 UTC · Feb 27, 2019Ransomware60
For many crooks, malware is out and PowerShell attacks are in, IBM saysCyberScoop·Feb 26, 14:22 UTC · Feb 26, 2019Malware in the wild60
Is Windows ShimCache a threat hunting goldmine?Help Net Security·Jul 10, 00:00 UTC · Jul 10, 2018Tools30