Man gets 15 years for extorting women with AI-generated porn videos
An Ohio man got 15 years for AI sextortion—a landmark sentence. AI removed barriers to this crime: attackers need only public photos to create fake explicit material for blackmail.
ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances ACTIVE THREATS: Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers • AI-powered attack exploited PaperCut flaws to hack 395 organizations • Microsoft Excel KB5002914 update breaks copy and paste for some users • Surfshark VPN says hackers breached internal testing, proxy servers • PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Latest cybersecurity ransomware news, analysis, and intelligence.
An Ohio man got 15 years for AI sextortion—a landmark sentence. AI removed barriers to this crime: attackers need only public photos to create fake explicit material for blackmail.
Nation-state actors are harvesting encrypted data today to decrypt later when quantum computers mature. CISA and G7's joint advisory warns that migrating to post-quantum cryptography is urgent—standards are finalized, the window to transition is closing, and adversaries are already betting on their
MSPs are ransomware's most efficient target—one compromise unlocks hundreds of clients. The fatal flaw: most haven't tested defenses during real incidents, so capabilities fail when needed.
File servers harbor years of unchecked permissions that enable ransomware lateral movement. Organizations rarely audit or clean up legacy access, creating an easily exploitable attack surface where one compromised credential cascades across sensitive data.
Russian ransomware group Aurora used Cursor AI to compromise 10+ networks, proving threat actors have moved AI-assisted attacks from theory to practice. Independent researchers confirmed the findings, revealing the group's sophisticated tooling adoption alongside operational security gaps.
Berlin confirmed Rhysida stole data from city administration. The ransomware gang uses data exfiltration threats to extort high-profile targets holding sensitive citizen records.
Android 17 will support Encrypted Client Hello (ECH), hiding which websites you visit from carriers and network observers. Currently, HTTPS encrypts page content but leaves the hostname visible in plaintext, exposing your browsing history to anyone monitoring network traffic.
Qilin ransomware hit the ATF in August—the third federal agency breach in 2026 after FBI (March) and DHS (July). Federal agencies' security apparently lags mid-market companies.
SynkLoader leverages legitimate Microsoft 365 tenants for phishing. Rather than impersonating the brand, attackers weaponize trusted infrastructure directly to bypass security awareness.
ClickFix fake CAPTCHAs have matured from novelty to industrialized malware delivery. Two new loaders—WordlistLoader and SynkLoader—show the technique now feeds ransomware groups with stolen credentials and access via commodity stealers like Amatera.
Adversaries are harvesting encrypted data today to decrypt later with quantum computers. While software companies quickly adopt post-quantum cryptography standards, hardware makers face a costly, slower challenge updating chips already deployed in the field.
The attackers themselves pose as "Ransom Busters," contacting victims mid-incident to sell fake decryption keys before disclosure. This double-dip scheme exploits the chaotic hours when desperate organizations are most vulnerable.
FBI/CISA revealed Medusa ransomware-as-a-service hit 500+ critical infrastructure targets since 2021, exploiting known vulnerabilities for double-extortion attacks demanding up to $15 million.
Ransom Busters, a fake recovery firm, is the ransomware affiliate double-extorting victims for $20k-60k to recover stolen data. They're caught by contacting targets before attacks go public.
Microsoft finally removed WMIC from Windows 11, eliminating a key ransomware tool. This legitimate Windows utility let attackers delete shadow copies and disable recovery before encryption—a tactic that persisted despite deprecation warnings since 2016.
Clop ransomware targets GE and Philips, stealing critical infrastructure data from military, nuclear, and healthcare systems. The gang exploits file-transfer software vulnerabilities for data extortion, threatening to publish stolen data unless ransom is paid.
Swiss encrypted messaging app Threema was knocked offline by DDoS attacks. When encryption can't break, attackers hit availability—targeting a platform popular with journalists and activists.
Google's post-quantum deadline is 2027 to counter 'harvest later' attacks on today's encrypted data. NIST finalized standards in 2024; migration of legacy RSA/ECDSA infrastructure is the challenge.
Shell confirms a Clop ransomware breach claiming 89GB exfiltrated—their second incident with the gang. Clop targets enterprise file-transfer tools like Accellion FTA, not perimeter defenses.
Akira ransomware discovered a free EDR bypass: rebooting into Windows Safe Mode disables security agents. A single bcdedit command leaves the system unmonitored during the attack.
WhatsApp is rolling out a Scam Alert feature that detects suspicious messages using on-device AI. Unlike traditional cloud-based detection, it preserves privacy and end-to-end encryption by never sending message content to Meta's servers.
City-Forum targets Salesforce and ServiceNow for data theft using custom tools, not ransomware. The campaign reflects a shift by sophisticated actors toward persistent access to customer data.
Colombia's Justice Ministry suffered ransomware strategically timed before a presidential transition. A threat warning came 24 hours prior, exposing the gap between detection and defensive action.
DeadLock ransomware shifts to blockchain infrastructure to evade seizures, distributing its command-and-control across thousands of nodes instead of using centralized servers vulnerable to FBI warrants. The strategy reflects lessons learned from law enforcement's successful takedowns of Hive, LockBi
Storm-1175 abandoned Medusa for custom StormEncryptor to eliminate RaaS dependencies and enable tailored evasion. The shift reveals the group's growing sophistication and operational independence.
A former Medusa operator launched StormEncryptor using insider attack knowledge. Threat: experienced ransomware actors deploying proven playbooks with new tools that bypass current defenses.
A Com affiliate received a 2-year sentence for sextorting 120 minors across multiple countries. The loose cybercrime network operates via Discord and Telegram, coercing children to share explicit images before demanding payment through blackmail.
UNC6671 operates a multi-brand vishing extortion operation using phone social engineering to steal credentials and data, then demands ransom—no malware, making it harder to detect. The threat actor group, operating under names like BlackFile, Redact, and Falcon, has built a multimillion-dollar extor
UNC6671 extorts finance firms via social engineering, rotating brand names (BlackFile, Redact, Pink, Helix) to fragment attribution. The group has collected $10.6M+ in Bitcoin since early 2026.
Ransomware kingpin Maksim Silnikau was sentenced to 16 years for running Ransom Cartel, which caused $6.7M+ in losses. After two decades in cybercrime and evading Spanish authorities, the Belarusian operator's run finally ended in federal court.