Berlin's Stand Against Rhysida Puts Data at Risk
Berlin refused a €2m ransom; Rhysida leaked 5.7 TB, including emergency plans.
30 results for “ransom”
Berlin refused a €2m ransom; Rhysida leaked 5.7 TB, including emergency plans.
New research maps North Korea's Lazarus umbrella into six distinct cyber clusters with specialized roles.
Microsoft's cloud patches, Dropbox account breaches, and Guardio's $1.1B funding round headline this week's security news.
Manchester Airports Group data leak exposes 8.8M records after refusing ransom.
A human attacker used AI agents to breach a network in under 10 hours, leaving an 80-page audit.
Acronis data shows 143 MSP victims in 2025. A six-point checklist helps providers verify real recovery capability.
Microsoft's false 'Defender off' alerts risk training users to disregard real security warnings, experts say.
ATF confirms a cyber incident on a standalone system after the Qilin ransomware group claimed an attack.
Berlin refuses to pay Rhysida after data theft from its state network, saying it won't yield to blackmail.
Aurora ransomware actors use Cursor Agent AI to automate post-exploitation tasks, per Gambit Security research.
CRPx0's victim count rose from under 10 to 48 organizations since June, but experts urge caution over unverified claims.
A weekly roundup: 296K-device botnet, 100+ water systems targeted, and a SharePoint RCE chain.
ATF confirms a standalone system was breached, described as a "major incident" amid Qilin ransomware claims.
Unit 42 finds most AI-linked malware never reaches real targets, but speed of development is rising.
Medtech firm discloses cyberattack disrupting global operations, with no timeline for full restoration.
Chubb's 2026 Cyber Claims Report finds fewer claims but soaring average costs, driven by litigation and business interruption.
SecurityWeek’s weekly roundup covers a Ray bug, Threema DDoS, T-Mobile’s cable cut, Evooo1Bot, and more.
Ransom Busters, a fake recovery firm, steals victims' ransom payments that were meant for the original criminals.
CISA adds four actively exploited vulnerabilities affecting macOS, SharePoint, vCenter, and Windows IKE to its KEV catalog.
A ransomware affiliate is contacting victims, offering to delete stolen data for $20,000–$60,000. Experts call it a scam.
CISA confirms ransomware gangs are exploiting a Windows Task Host privilege escalation flaw added to KEV in April.
Researchers say a suspected China-nexus APT used a VMware flaw to deploy ransomware as a smoke screen.
GE and Philips confirm probing Clop breach claims as the gang's PTC Windchill attacks ripple through enterprise giants.
Flashpoint logs 7.4M infostealer infections and 1.7B credentials stolen in H1 2026, up 27%.
Akira ransomware used Windows Safe Mode to disable endpoint defenses, revealing a growing evasion trend.
A weekly summary of key cybersecurity events, from a Boeing 737 hack demo to refrigeration flaws and Rapid7 layoffs.
An Akira affiliate rebooted a victim's PC into Safe Mode, breaking its own encryptor but still stealing data.
DeadLock ransomware stores config data on Polygon blockchain, complicating infrastructure takedowns by law enforcement.
DeadLock uses Polygon smart contracts to make extortion infrastructure harder to disrupt, Microsoft reports.
CISA adds CVE-2026-45659 to KEV catalog, confirming ransomware abuse of a Microsoft SharePoint RCE flaw.