AI Coding Assistant Now a Ransomware Weapon
Aurora ransomware actors use Cursor Agent AI to automate post-exploitation tasks, per Gambit Security research.
30 results for “cybercrime”
Aurora ransomware actors use Cursor Agent AI to automate post-exploitation tasks, per Gambit Security research.
CRPx0's victim count rose from under 10 to 48 organizations since June, but experts urge caution over unverified claims.
Treasury targets Iran-linked hackers behind critical infrastructure breaches in 'Operation Economic Outcast'.
A phishing platform gives attackers live control over victim sessions, adapting prompts as credentials are harvested.
Operation Jackal IV arrests 58, targets Black Axe syndicate across 22 countries over eight months.
Researchers find Kriminal AI service routes requests through Grok, Claude, and others via jailbreaks for as little as $12.99 a month.
A ransomware affiliate is contacting victims, offering to delete stolen data for $20,000–$60,000. Experts call it a scam.
Akira ransomware used Windows Safe Mode to disable endpoint defenses, revealing a growing evasion trend.
Ukraine shuts down 94 fraudulent call centers, seizes $2M and equipment, targeting investment scams and bank fraud.
SecurityA presidential memo lets vetted US companies run offensive cyber ops against foreign crime rings.
A momentary face-swap failure helped Spanish police identify a man accused of obtaining digital certificates under stolen identities.
Marcus Hutchins, who halted WannaCry, recounts his path from malware author to security researcher.
Threat actors are bypassing standard enterprise security by using vishing attacks to compromise personal mobile devices.
Ransomware incident counts climbed in July as attackers shifted focus toward financial, technology, and healthcare sectors.
A sophisticated phishing campaign uses adversary-in-the-middle tactics to compromise Microsoft 365 accounts for financial espionage.
Google Threat Intelligence Group links the retired BlackFile extortion brand to the active Redact group through shared infrastructure.
A Canadian national has admitted to his role in a massive 2024 campaign that compromised over 165 major corporate Snowflake accounts.
Threat actors are breaking malicious projects into small, fragmented tasks to circumvent AI safety guardrails, according to research.
Threat actors are repurposing publicly leaked data to launch targeted sextortion campaigns demanding Bitcoin payments from breach victims.
New research details how threat actors are ditching delayed credential harvesting for live, session-based account hijacking.
A centralized portal upgrade aims to standardize affiliate workflows and tighten operational management for the DevMan ransomware group.
Law enforcement has flagged over 4,000 URLs linked to a network that recruits minors for digital extortion and physical violence.
New State Department policy revokes visa access for cybercriminals and their families to combat cross-border investment scams.
The Swiss train manufacturer confirms it rejected a multi-million dollar extortion attempt following a third-party data breach.
Researchers uncovered an exposed server revealing how attackers use AI to industrialize the creation of malware delivery campaigns.
A sophisticated crypter service is leveraging process ghosting and kernel-driver abuse to cloak various commodity malware strains.
A threat actor used Google Gemini CLI to automate botnet management and infrastructure migration, bypassing traditional defenses.
Law enforcement officials are advocating for Cybercrime Risk Orders following the sentencing of two Scattered Spider hackers.
A Russian tourist remains in Armenian custody as legal experts claim he was misidentified as a notorious ransomware operative.
A newcomer has displaced established groups to become the most active ransomware threat, fueled by aggressive recruitment and AI.