AI Coding Assistant Now a Ransomware Weapon
Aurora ransomware actors use Cursor Agent AI to automate post-exploitation tasks, per Gambit Security research.
30 results for “ransomware”
Aurora ransomware actors use Cursor Agent AI to automate post-exploitation tasks, per Gambit Security research.
CRPx0's victim count rose from under 10 to 48 organizations since June, but experts urge caution over unverified claims.
A weekly roundup: 296K-device botnet, 100+ water systems targeted, and a SharePoint RCE chain.
ATF confirms a standalone system was breached, described as a "major incident" amid Qilin ransomware claims.
Unit 42 finds most AI-linked malware never reaches real targets, but speed of development is rising.
Medtech firm discloses cyberattack disrupting global operations, with no timeline for full restoration.
Chubb's 2026 Cyber Claims Report finds fewer claims but soaring average costs, driven by litigation and business interruption.
SecurityWeek’s weekly roundup covers a Ray bug, Threema DDoS, T-Mobile’s cable cut, Evooo1Bot, and more.
Ransom Busters, a fake recovery firm, steals victims' ransom payments that were meant for the original criminals.
CISA adds four actively exploited vulnerabilities affecting macOS, SharePoint, vCenter, and Windows IKE to its KEV catalog.
A ransomware affiliate is contacting victims, offering to delete stolen data for $20,000–$60,000. Experts call it a scam.
CISA confirms ransomware gangs are exploiting a Windows Task Host privilege escalation flaw added to KEV in April.
Researchers say a suspected China-nexus APT used a VMware flaw to deploy ransomware as a smoke screen.
GE and Philips confirm probing Clop breach claims as the gang's PTC Windchill attacks ripple through enterprise giants.
Flashpoint logs 7.4M infostealer infections and 1.7B credentials stolen in H1 2026, up 27%.
Akira ransomware used Windows Safe Mode to disable endpoint defenses, revealing a growing evasion trend.
A weekly summary of key cybersecurity events, from a Boeing 737 hack demo to refrigeration flaws and Rapid7 layoffs.
An Akira affiliate rebooted a victim's PC into Safe Mode, breaking its own encryptor but still stealing data.
DeadLock ransomware stores config data on Polygon blockchain, complicating infrastructure takedowns by law enforcement.
DeadLock uses Polygon smart contracts to make extortion infrastructure harder to disrupt, Microsoft reports.
CISA adds CVE-2026-45659 to KEV catalog, confirming ransomware abuse of a Microsoft SharePoint RCE flaw.
Suisan City declared a state of emergency after a malicious software infection disrupted emergency services, highlighting a pattern of local government attacks.
Microsoft says China-linked Storm-1175 shifts from Medusa to the new StormEncryptor ransomware, likely via N-central flaw CVE-2026-18577.
Microsoft tracks Storm-1175's shift to StormEncryptor, following exploitation of an N-central flaw.
Ransomware incident counts climbed in July as attackers shifted focus toward financial, technology, and healthcare sectors.
New data indicates a sharp rise in ransomware incidents throughout July 2026, breaking a multi-month period of lower activity.
Threat actors are actively chaining two critical SonicWall vulnerabilities to deploy ransomware and escalate privileges to root.
Researchers report a rise in AI-driven malware and evolving social engineering, marking a shift in how attackers scale operations.
From AI-powered infostealers and automotive vulnerabilities to massive kernel patch requirements, recent threats span multiple sectors.
Threat actors are increasingly leveraging vulnerabilities in VPNs and firewalls to gain direct access to corporate networks.