-
Hackers leveraged a compromised Microsoft IIS server to gain initial access and deploy a previously unseen ransomware payload across an enterprise network within 24 hours, highlighting a highly coordinated and operationally mature intrusion chain obser…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Former ransomware negotiator Angelo Martino gets 70 months in prison for helping BlackCat extort US victims and misuse confidential client data in cyberattacks.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are exploiting the CitrixBleed 2 vulnerability, tracked as CVE-2025-5777, to hijack active NetScaler sessions protected by multi-factor authentication and gain a foothold in enterprise environments. The activity indicates a standardized o…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Angelo Martino, a former ransomware negotiator from Florida, has been sentenced to 70,707 months in federal prison for conspiring with ALPHV/BlackCat ransomware operators to extort victims whom he was supposed to help during incident-response engagemen…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A targeted GodDamn ransomware incident shows the payload is not entirely new but the latest rebrand of a long-running family. Analysis reveals strong code overlap with Beast (the 2024 rebrand of Monster), and the operational playbook mirrors earlier Hy…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A recent technical analysis of an Everest ransomware encryptor reveals a purpose-built, ConfuserEx-protected .NET 4.0 binary that combines heavy obfuscation, misleading cryptographic declarations, and uncommon network tactics to maximize impact and imp…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
TeamPCP’s wide-scale supply-chain compromises have materially fueled VECT ransomware operations by supplying a vast archive of stolen CI/CD credentials, reshaping how organizations should measure ransomware exposure. Rather than choosing victims in adv…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Gentlemen, a Go-based ransomware-as-a-service (RaaS) active since mid-2025, has distinguished itself with a potent combination of modern cryptography, aggressive worm-like propagation, and a broad toolkit for remote execution. Operators offer the platf…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A previously undocumented malware framework, tracked as Avalon, that uses a spoofed legal-document lure and a multi-stage, fileless-oriented chain to deliver a ransomware component internally labeled CrownX. The campaign demonstrates a shift toward con…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A new Sysdig report traces how an LLM agent abused a Langflow flaw, stole credentials, reached production MySQL, and destroyed Nacos config data in minutes flat.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


