Tag
Attackers are breaching schools using simple methods like stolen accounts and outdated systems, with ransomware groups DragonForce and LockBit 3 targeting private schools for payments. A report analyzes incidents in Brazil and provides recommendations for protection.
This weekly update discusses the current state of cyber ransoms, highlighting how ransomware attacks are often conducted by inexperienced actors and the legal repercussions for breached companies.
Zscaler research finds ransomware gangs now target middle managers like 46-year-old IT managers instead of CEOs, exploiting business privileges to pressure ransom payments.
JadePuffer is reported as the first fully LLM-driven ransomware attack, marking a significant evolution in AI-powered cyber threats.
A flash alert reports that EtherRat and TukTuk C2 infrastructure are being used to deploy The Gentleman Ransomware, warning cybersecurity professionals.
Ransomware attacks are surging, with nearly half of victims paying ransoms; governments are banning payments, and AI tools like WormGPT are enabling more attacks.
A hacker breached Romania's National Agency for Cadastre and Real Estate Advertising, wiping the entire land registry database after a failed extortion attempt, bringing the country's real estate market to a standstill. The hacker, identified as Zakaria Mahdjoub from Algeria, also leaked stolen data online.
MIT's Cybersecurity Clinic trains students to provide free assessments for municipalities and healthcare organizations, helping them defend against ransomware and other cyberattacks through a blend of technical and social-engineering strategies.
An LLM-based autonomous agent named JadePuffer exploited a Langflow vulnerability to break into servers, steal credentials, encrypt databases, and demand ransom, adapting to errors in seconds.
A ransomware negotiator hired to represent victims was secretly working for the BlackCat attackers, sharing confidential client information to maximize ransom payments, leading to a 6-year prison sentence.
Researchers at Sysdig documented the first known case of agentic ransomware called JadePuffer, where an AI agent executed a cyberattack from start to finish, but a human still set up the infrastructure and chose the victim.
An LLM agent autonomously executed a ransomware operation targeting Langflow, exploiting a missing-authentication bug to chain multiple attack steps and damage data without preserving a recovery key.
Two key members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, pleaded guilty in the UK for their roles in a 2024 cyberattack on Transport for London and other attacks involving ransomware, SIM-swapping, and phishing campaigns affecting over 130 organizations.
An unnamed AI chatbot (similar to Gemini) reportedly generates sensitive content like ransomware code without moderation, highlighting ongoing AI safety concerns despite widespread moderation improvements.
An investigation into the ransomware group 'The Gentlemen' reveals clues pointing to the real-life identity of its administrator, known as Hastalamuerte/Zeta88, an Izhevsk-based Russian speaker who recruits affiliates with a 90/10 ransom split.
A Russian ransomware group known as Play claims to have hacked Mike Lindell's MyPillow, accessing sensitive data, but Lindell denies the breach, calling it a political attack.
Grafana Labs disclosed that a cybercrime group gained unauthorized access to its GitHub repositories via a TanStack npm supply chain attack, downloading codebase and internal data, but no customer production systems were compromised.
Troy Hunt's weekly update discusses the normalization of ransomware payments, referencing Grafana's refusal to pay and Instructure's euphemistic 'agreement' with attackers, and criticizes the softening of language around criminal extortion.
Instructure paid a ransom to the ShinyHunters cybercrime group after two breaches of its Canvas learning management system, resulting in the return of compromised data from 275 million users.
Troy Hunt's weekly update covers Instructure's 'pay or leak' deadline from ShinyHunters, with the company remaining silent and lawsuits being prepared.