Researchers found Aurora ransomware affiliates using the Cursor AI coding assistant to plan and run intrusions against at least ten organisations, exploiting the same Active Directory weaknesses pen testers have …
ransomware
-
-
A PaperCut vulnerability chain let attackers bypass login and run code on print servers, and the vendor needed a second emergency patch after the first one was bypassed.
-
Ransomware isn’t getting more sophisticated, it’s getting more industrialised. Here’s how the criminal supply chain behind it works, and why the same basic gaps keep letting it in.
-
WilmerHale paid at least $18 million and Goodwin Procter around $10 million to the Luna Moth extortion group, which broke in using phone calls and fake IT visits rather than …
-
A record 93 active ransomware groups sounds alarming, but Q2 2026 data suggests ransomware market fragmentation is a sign of pressure, not strength.
-
Cl0p-linked attackers are exploiting an unauthenticated flaw in PTC Windchill and FlexPLM. Here’s a practical checklist for finding out if you’re exposed.
-
A May 2026 GlobalProtect authentication bypass is still being used by Qilin ransomware affiliates. Here’s how to confirm you’re patched, mitigate if you’re not, and spot signs of prior compromise.
-
A US county paid roughly $1 million to a group that never encrypted a single file, exposing how far data-theft extortion has moved beyond classic ransomware.
-
Ransomware via search results is now a documented attack route. A Bing search for IT software led to full network encryption in 44 hours. Here is why your download policy …
-
Operation Endgame disrupted Amadey and StealC infrastructure on a significant scale. But with no arrests, the operators survive intact. Here is what that means for UK businesses building their security …