threat-intel Cybercrime service disrupted for abusing Microsoft platform to sign malware Microsoft disrupted a malware-as-a-service (MaaS) operation, dubbed Fox Tempest, that was abusing its Artifact Signing service to generate fraudulent code-signing certificates for ransomware gangs and other cybercriminal… BleepingComputer · May 19, 2026 High USCAmsaascode signingfraudulent certificates
ransomware IT threat evolution in Q1 2026. Non-mobile statistics In Q1 2026, Kaspersky products blocked over 343 million attacks, with significant ransomware activity including 2938 new ransomware variants and 77,000 ransomware attacks. Law enforcement actions disrupted the RAMP cyber… Securelist · May 18, 2026 High CVE-2026-20131POUNransomwarezero-dayraas
ransomware Congress Puts Heat on Instructure After Canvas Outage Following a high-profile cyberattack on its Canvas learning management system by the ShinyHunters group, Instructure is facing increased scrutiny from Congress. The House Committee on Homeland Security has requested a br… Dark Reading · May 15, 2026 High USedtechransomwaredata breach
ransomware State of ransomware in 2026 Kaspersky’s 2026 ransomware threat report highlights a shift in the landscape, with ransomware attacks declining overall but becoming more sophisticated. Key trends include the emergence of post-quantum cryptography rans… Securelist · May 12, 2026 High USransomwarequantum cryptographyedr
threat-intel Canvas Breach Disrupts Schools & Colleges Nationwide A cybercrime group, ShinyHunters, disrupted the Canvas education technology platform, impacting schools and colleges nationwide. The group defaced the login page with a ransom demand, threatening to leak data from 275 mi… Krebs on Security · May 8, 2026 High USeducationdata breachransomware
threat-intel The calm before the ransom: What you see is not all there is This article highlights a common cybersecurity pitfall: organizations can become overly confident in their security posture due to a period of stability, leading to complacency and a failure to adequately assess current… WeLiveSecurity · Apr 24, 2026 High UScomplacencyrisk assessmentcybersecurity
ransomware What the ransom note won’t say This article details the ongoing issues surrounding the BlackCat ransomware gang’s affiliate, who attempted to defraud the group after carrying out a significant attack on Change Healthcare. The incident highlights the i… WeLiveSecurity · Apr 20, 2026 High USransomwarefranchisesupply chain
ransomware Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab German authorities have identified ‘UNKN,’ the elusive figure behind the notorious GandCrab and REvil ransomware gangs, as 31-year-old Russian national Daniil Maksimovich Shchukin. Shchukin, alongside Anatoly Sergeevitsc… Krebs on Security · Apr 6, 2026 Critical DERUransomwareextortioncybercrime
malware EDR killers explained: Beyond the drivers This article analyzes the increasing use of "EDR killers" in modern ransomware attacks. These tools, often based on vulnerable drivers or custom scripts, are deployed by affiliates to disrupt endpoint detection and respo… WeLiveSecurity · Mar 19, 2026 High USransomwareedrdrivers