Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
Tag: ransomware
Panzer Ransomware Targets Italian Manufacturers and Telecom Firms With ESXi-Ready RaaS
Panzer ransomware has entered Italy amid a sharp rise in attacks. The ransomware-as-a-service, or RaaS, operation surfaced on August 5 and listed a…
Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support
A newly identified ransomware-as-a-service operation, Panzer, has surfaced with advertised payload support for Windows, Linux, VMware ESXi and FreeBSD,…
Ransomware negotiation tactics have turned into a business process
In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during…
Berlin Ransomware Leak Exposes State Secrets
Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a…
New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption
Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS) operation, publishing 16 alleged victims across 11 countries while combining data…
PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
Hackers Turn Trusted Node.js Runtime Into Malware Launcher in Ransomware-Linked Attacks
Cybercriminals are increasingly hijacking Node.js, the widely used JavaScript runtime, to slip malicious code past security defenses, according to new…
The Gentlemen Ransomware Hackers Disable EDR and Backups Before Encrypting Networks in Under 24 Hours
The Gentlemen ransomware operation is moving from access to full network encryption at striking speed. In some intrusions, attackers disabled defenses and…
Ransomware Hackers Can Go From Network Access to Encryption in Less Than 24 Hours
The Gentlemen ransomware-as-a-service operation can move from confirmed access inside a victim network to encryption in under 24 hours. Demonstrating how…
AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
Adding insult to injury
Ransomware Hackers Use New TukTuk Malware to Steal Credentials and Disable Security Tools
Ransomware operators are using a previously undocumented remote-control framework called TukTuk to steal credentials, watch compromised machines, and…
The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security
The Gentlemen ransomware operation has been linked to a previously undocumented, cross-platform command-and-control framework named TukTuk, alongside…
PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
DaVita Settles $15M Ransomware Breach Lawsuit
Healthcare provider DaVita has reached a $15 million settlement to resolve class action litigation stemming from an April 2025 ransomware attack that…
Ransomware Gang Claims Nutex Health Data Breach
The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information.
Aurora Ransomware Hackers Use Cursor AI Agent for Hands-On Exploitation and ESXi Attacks
Aurora ransomware operators have been observed using Cursor Agent, powered by Claude Sonnet, to support hands-on intrusion activity across ten victim…
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX’s artificial intelligence (AI)-powered coding assistant…
Storm-1175 Deploys StormEncryptor Ransomware After N-able N-central Vulnerability Exploitation
Financially motivated hackers believed to be based in China are using a new ransomware for the first time after targeting a vulnerability in the N-central…
Rhysida Ransomware Group Targets Berlin Government Ahead of Vote
Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft.…