ransomware Gunra ransomware: what you need to know The Gunra ransomware gang is aggressively targeting organizations across multiple sectors, leveraging unpatched VPNs and firewalls to gain access and deploy their ransomware. They are demanding payments to decrypt stolen data and restore system functionality, causing significant disruption and financial damage. Graham Cluley · 6d ago High vpnfirewallransomware
ransomware Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout A ransomware group, believed to be “The Gentlemen,” has hijacked the Facebook page of AnMed, a nonprofit medical system in Georgia and South Carolina, to demand ransom after a prolonged cyberattack. The group claims to h… The Record · Aug 11, 2026 High USransomwarehealthcarecyberattack
ransomware DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt The DeadLock ransomware group is utilizing a sophisticated, blockchain-backed infrastructure to enhance operational resilience and evade takedown efforts. They leverage decentralized proxy servers managed via Polygon sma… The Hacker News · Aug 11, 2026 High ITSPPOransomwareblockchainsmart contracts
ransomware Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks The Gunra ransomware group, linked to state-sponsored actors, is aggressively targeting critical infrastructure and organizations globally, leveraging vulnerabilities in Fortinet and Schneider Electric appliances to gain… The Hacker News · Aug 11, 2026 High CVE-2024-5559CVE-2025-24472SOBRSPransomwarevulnerabilitysupply-chain
ransomware ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors This week’s security news is dominated by AI-related threats, including a vulnerability exploited in Metabase, a new Shai-Hulud worm leveraging the MCP Registry, and a Chinese review of Palo Alto Networks. Alongside the… The Hacker News · Aug 10, 2026 High CVE-2026-34348CVE-2026-18497CVE-2026-63508CHransomwaresupply-chainvishing
ransomware #StopRansomware: Gunra Ransomware The FBI, CISA, and other agencies have issued a joint advisory regarding the Gunra ransomware threat, a sophisticated double-extortion variant derived from the Conti ransomware. Gunra has rapidly expanded through a RaaS… CISA Advisories · Aug 10, 2026 Critical CVE-2024-55591CVE-2025-24472USREransomwaredouble extortionr0aas
ransomware River Bank Says Hackers Deleted Data Stolen in Ransomware Attack River Bank & Trust suffered a ransomware attack that resulted in stolen data, which the company subsequently worked to have deleted through a possible ransom payment. The company is still investigating the full scope of… SecurityWeek · Aug 3, 2026 Medium ransomwaredata breachfinancial services
ransomware Toy Ghouls’ new toy: the GenieLocker ransomware The Toy Ghouls group, also known as Bearlyfy, Labubu, and Laboo.boo, has released GenieLocker, a custom ransomware family targeting organizations in Russia, primarily in the manufacturing sector. This new ransomware is a… Securelist · Jul 30, 2026 High
ransomware Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack Coca-Cola’s Fairlife subsidiary suffered a ransomware attack from the Anubis group, resulting in a data breach and the potential release of 1TB of stolen data. Production has largely resumed, but the group is threatening… SecurityWeek · Jul 27, 2026 High ransomwaredata breachdouble extortion
ransomware Don’t swing at everything This week’s Threat Source newsletter highlights a new Rust-based remote access trojan (RAT), “msaRAT,” deployed by the Chaos ransomware group. The RAT leverages Chrome DevTools Protocol (CDP) to establish a covert comman… Cisco Talos · Jul 23, 2026 High CVE-2026-60137CVE-2026-63030
ransomware Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife The Anubis ransomware group is threatening to release stolen data from Coca-Cola’s Fairlife subsidiary unless a ransom is paid. The group has a history of double-extortion tactics, including wiping data to force payment,… SecurityWeek · Jul 22, 2026 High ransomwaredata breachdouble extortion
ransomware Anubis ransomware: what you need to know The Anubis ransomware, delivered as a service, is targeting healthcare organizations, but its reach extends beyond this sector. This RaaS operation is causing significant disruption and data loss for affected entities, h… Graham Cluley · Jul 16, 2026 High ransomwareraashealthcare
ransomware ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More This week’s security news is dominated by a concerning trend: vulnerabilities are being exploited faster than patches can be applied, leading to a surge in attacks. Notable events include a ShareFile threat urging users… The Hacker News · Jul 13, 2026 High CVE-2026-50746CVE-2026-50747CVE-2026-50748
ransomware No Manners Here: The Ruthless Rise of The Gentlemen Ransomware The Gentlemen, a rapidly growing Ransomware-as-a-Service (RaaS) program, has significantly increased its victim count in 2026, becoming the second most active RaaS program globally. Leveraging a 90% affiliate payout stru… Palo Alto Unit 42 · Jul 10, 2026 High CVE-2024-55591CVE-2025-32433CVE-2025-33073USCAGBransomware-as-a-serviceracksedge-device-attack
ransomware Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence Two major ransomware figures have been brought to justice in separate U.S. court cases. Karen Vardanyan, a Ryuk ransomware operator, pleaded guilty to conspiracy and computer fraud, while Angelo Martino, a ransomware neg… The Record · Jul 10, 2026 High FRUKUNransomwarenegotiatorextortion
ransomware GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses The GodDamn ransomware family, a rebrand of Beast ransomware (originally based on Monster), is utilizing a newly discovered malicious driver called PoisonX to disable endpoint defenses and gain access to systems. Threat… The Hacker News · Jul 9, 2026 High ransomwarepoisonxbyovd
ransomware Mount Royal University Confirms Data Stolen in Ransomware Attack Mount Royal University in Canada suffered a ransomware attack that resulted in the theft of employee and student data. The attackers, identified as CMD Organization, exfiltrated over 10 terabytes of information and are d… SecurityWeek · Jul 9, 2026 High CAransomwaredata breachtor
ransomware New Avalon Malware Framework Packs CrownX Ransomware Capabilities Researchers at Blackpoint Cyber discovered Avalon, a new modular malware framework used to deploy the CrownX ransomware. The framework utilizes a multi-stage phishing campaign to bypass security controls and performs cre… The Hacker News · Jul 3, 2026 High CVE-2025-3248USphishingcredential theftlateral movement
ransomware Agentic AI Used to Conduct Ransomware Attack via Langflow A threat actor, tracked as JadePuffer, exploited a critical vulnerability (CVE-2025-3248) in the Langflow LLM framework to conduct a ransomware attack. The attacker leveraged an LLM agent to perform reconnaissance, steal… SecurityWeek · Jul 3, 2026 Critical CVE-2025-3248CVE-2021-29441CHllmagenticransomware
ransomware FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs The FortiBleed operation, initially focused on stealing credentials from thousands of Fortinet FortiGate firewalls, has expanded to involve ransomware-as-a-service (RaaS) gangs Inc Ransom and Lynx. SOCRadar researchers d… Dark Reading · Jul 2, 2026 High USGBcredential theftransomware-as-a-servicezero-day