Visualização normal

Ontem — 7 de Setembro de 2026Stream principal
  • ✇Security Affairs
  • Berlin Ransomware Leak Exposes State Secrets Pierluigi Paganini
    Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out this exact threat against Berlin after local authorities refused to pay a thirty Bitcoin ransom. At the end of August, Berlin’s state government confirmed
     

Berlin Ransomware Leak Exposes State Secrets

7 de Setembro de 2026, 04:19

Berlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web.

When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem go away. The Rhysida ransomware group recently carried out this exact threat against Berlin after local authorities refused to pay a thirty Bitcoin ransom.

At the end of August, Berlin’s state government confirmed it was dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included.

Rhysida claimed it stole 5.79 TB of data, covering around 1.44 million files. The alleged dataset includes:

  • Personal data: 12,076 individuals, 16,389 email addresses, 11,963 phone numbers and 148 IBANs.
  • Sensitive records: more than 5,000 personnel files, more than 5,000 administrative-offence files, payroll data and leadership information.
  • Credentials: plaintext passwords and credentials for systems including GebäudAtlas, the ePayment PAYONE database and Z_ADMIN accounts.
  • Government and legal material: disciplinary proceedings, court cases, supervisory documents, NDA records and Bundesrat committee protocols.
  • Classified information: data related to classified-material handling and documents allegedly containing state secrets.
  • Critical infrastructure: vulnerability analyses concerning Berlin’s water supply.
  • Identity documents: passports and ID cards from personnel records.
  • Other material: contracts, financial documents, HR records, infrastructure files, health data, password stores and SQL/PST archives.

The group also claimed that the material could involve violations of GDPR, German classified-information rules, criminal law and KRITIS/BSIG requirements. These are Rhysida’s claims and have not been independently verified.

The scale of the breach is staggering. Investigators are now looking at roughly 1.4 million files containing personal details of civil servants, internal infrastructure records, and critical government data.

The fallout goes far beyond routine data theft. Investigative journalist Lars Winkelsdorf pointed out the gravity of the situation on social media.

Die absolute Vollkatastrophe ist eingetreten

Dieses Datenleck ist schlimmer als alle bisherigen Terroranschläge zusammen 1/xhttps://t.co/epU4mCYgew

— Lars Winkelsdorf (@winkelsdorf) September 4, 2026

“In addition to LKA documents related to investigations, the files also include plans concerning national defense—ranging from the federal government’s secret communication channels in the event of an apocalypse to defense-related companies and emergency plans developed by government agencies,” Winkelsdorf wrote.

Exposing crisis response plans and secret communication channels turns a financial shakedown into a national security headache.

Worse still, the leaked material includes files concerning chemical, biological, radiological, and nuclear threats.

“Among the published files is a folder titled “AG CBRN-Rahmenplanung.” CBRN stands for chemical, biological, radiological and nuclear threats,” notes the Euronews report

Having that kind of operational data floating around public forums gives hostile actors a blueprint for disaster.

Refusing to pay ransoms is the right policy, but it rarely stops the bleeding once the network is compromised. Governments keep treating cybersecurity like an IT expense rather than an existential line of defense.

Until boards start treating network segmentation with the same seriousness as physical security, we will keep watching expensive countdown timers tick down to zero.

Berlin’s state government announced the launch of a crisis response after the threat actors published the stolen data.

“A ‌central ⁠crisis unit will oversee the review, verification and assessment of the leaked data and support efforts to inform affected citizens and ​businesses, said the ​city.” Reuters reports.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Berlin)

Antes de ontemStream principal
  • ✇Cybersecurity News
  • The Gentlemen Ransomware Deploys in Under 24 Hours Do Son
    The Gentlemen ransomware, run by GOLD SHERWOOD, encrypts networks in under 24 hours. See the affiliate playbook and how to defend against it. Related Posts: PHP Web Server Rootkit Targets F5 BIG-IP Devices StreamRat Banking Trojan Targets Spanish Android Users Silver Fox Fake Software Installers Disable Windows Defender The post The Gentlemen Ransomware Deploys in Under 24 Hours appeared first on Daily CyberSecurity.
     
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 1, September 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026           ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale
     

Ransom & Dark Web Issues Week 1, September 2026

Por:ATCP
2 de Setembro de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026           ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale

The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security

The Gentlemen ransomware operation has been linked to a previously undocumented, cross-platform command-and-control framework named TukTuk, alongside EDR-disabling tooling, DLL sideloading research, and datasets apparently stolen from technology and healthcare organizations. Analysis of a Finland-hosted server identified what researchers assess as the complete TukTuk development project, providing an unusually detailed view into the group’s post-compromise capabilities. […]

The post The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

  • ✇Security Affairs
  • Rhysida Ransomware Group Targets Berlin Government Ahead of Vote Pierluigi Paganini
    Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft. Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” a
     

Rhysida Ransomware Group Targets Berlin Government Ahead of Vote

29 de Agosto de 2026, 07:55

Berlin ‘s government faces a Rhysida ransomware attack weeks before elections, with officials refusing to pay despite a claimed 5.79 TB data theft.

Berlin’s state government confirmed this week it’s dealing with an extortion attempt following an August cyberattack on the city-state’s administrative network, and officials have already refused the requested ransom. The ransomware group Rhysida claimed responsibility on its leak site August 28, posting an entry titled simply “Berlin, Germany” and claiming 5.79 terabytes of data across roughly 1.44 million files, with personal information on 12,076 individuals allegedly included.

Rhysida claims it stole 5.79 TB of data, covering around 1.44 million files. The alleged dataset includes:

  • Personal data: 12,076 individuals, 16,389 email addresses, 11,963 phone numbers and 148 IBANs.
  • Sensitive records: more than 5,000 personnel files, more than 5,000 administrative-offence files, payroll data and leadership information.
  • Credentials: plaintext passwords and credentials for systems including GebäudAtlas, the ePayment PAYONE database and Z_ADMIN accounts.
  • Government and legal material: disciplinary proceedings, court cases, supervisory documents, NDA records and Bundesrat committee protocols.
  • Classified information: data related to classified-material handling and documents allegedly containing state secrets.
  • Critical infrastructure: vulnerability analyses concerning Berlin’s water supply.
  • Identity documents: passports and ID cards from personnel records.
  • Other material: contracts, financial documents, HR records, infrastructure files, health data, password stores and SQL/PST archives.

The group also claims that the material could involve violations of GDPR, German classified-information rules, criminal law and KRITIS/BSIG requirements. These are Rhysida’s claims and have not been independently verified.

The timing makes this attack especially sensitive. Berlin will elect its state parliament on September 20, less than a month after the breach, so an attack on government systems just before the vote was bound to raise questions. Interior Senator Iris Spranger said the election remains secure and that, so far, the attackers haven’t taken any election-related data. Security officials support that assessment.

Broadcaster RBB first reported on Thursday that Berlin had received ransom demands.

“The state ​of Berlin will not submit to extortion,” Berlin Mayor Kai Wegner and Berlin’s interior senator, ​Iris Spranger, said in a joint statement on Friday, before the ransomware group claimed the attack ‌on ⁠their Tor data leak site.

That position follows long-standing advice from US federal agencies, which warn that paying a ransom doesn’t guarantee data recovery and can encourage more attacks. Saying no to the ransom is one thing; dealing with the consequences if the attackers publish the stolen data is another.

Berlin first disclosed the compromise on August 17, isolating the Senate Department for Mobility, Transport, Climate Protection and Environment along with a second department from the network. Forensic investigators later found the actual data exfiltration happened earlier than the public disclosure, sometime between August 7 and August 12, with the affected department having flagged an initial outflow internally on August 7, a full week before the network got cut off. That gap between first internal detection and actual network isolation is the kind of detail that tends to get scrutinized hardest once the immediate crisis passes.

Rhysida isn’t a new name to anyone tracking ransomware against government targets. The group has claimed roughly 280 victims since emerging in 2023, according to tracking services cited by Reuters, including nine in Germany alone and headline targets like the British Library and Chile’s army. Roughly half its victims sit in the US, with the UK, Canada, and Italy rounding out the next tier, a spread that suggests Rhysida isn’t picking targets based on geography so much as opportunity.

A joint advisory from CISA, the FBI, and the Multi-State Information Sharing and Analysis Center, first published in November 2023, lays out exactly how Rhysida typically gets in: compromised VPN credentials at organizations without multi-factor authentication, exploitation of the Zerologon vulnerability that Microsoft patched back in 2020, and old-fashioned phishing. None of those entry points are exotic or new, which is precisely the point; Rhysida doesn’t need novel techniques when so many organizations still haven’t closed gaps that have been publicly known for years.

Berlin reconnected all Senate departments to the network on August 23, but forensic teams are still checking the systems. The state’s data protection commissioner and Germany’s federal cybersecurity agency, the BSI, are following the investigation.

As of publication, neither Berlin’s data protection office nor the Senate Chancellery had given specific advice to the roughly 12,000 people whose data Rhysida claims to have stolen. If you’re among them and haven’t received any official message yet, don’t assume that means you’re safe. Investigators are still working to establish exactly what the attackers accessed and took.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Rhysida Ransomware)

  • ✇Cybersecurity News
  • PaperCut NG/MF Vulnerability Exploited in the Wild, Emergency Patch Released Do Son
    PaperCut confirms a NG/MF vulnerability exploited in the wild. Restrict server access now and apply the emergency patch for versions 25 and 26. Related Posts: Critical MongoDB Security Vulnerabilities Require Immediate Patching CVE-2026-73125: Ebyte NA111-M Flaws Let Attackers Fully Compromise the Device D-Link DIR-X1860Z Flaw Lets Attackers Change the Admin Password Without Login The post PaperCut NG/MF Vulnerability Exploited in the Wild, Emergency Patch Released appeared first on Daily Cyb
     

TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation

A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify stolen corporate data, identify regulatory risk. Founded on April 4, 2026, TITAN has been active since May and has listed 24 alleged victims across 10 countries. Italy accounts for 10 published victims, followed by Czechia with […]

The post TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

  • ✇Securelist
  • Threat landscape for industrial automation systems. Q2 2026 Kaspersky ICS CERT
    All threats In Q2 2026, the percentage of ICS computers on which malicious objects were blocked continued to decrease, falling to 19.15%, its lowest level since 2022. Percentage of ICS computers on which malicious objects were blocked, Q3 2023–Q2 2026 Regionally, the percentages ranged from 8.1% in Northern Europe to 27.9% in Africa. Regions ranked by percentage of attacked ICS computers The figures increased in five regions over the quarter, most notably in East Asia (by 2.0 pp) and Africa (by
     

Threat landscape for industrial automation systems. Q2 2026

27 de Agosto de 2026, 07:05

All threats

In Q2 2026, the percentage of ICS computers on which malicious objects were blocked continued to decrease, falling to 19.15%, its lowest level since 2022.

Percentage of ICS computers on which malicious objects were blocked, Q3 2023–Q2 2026

Percentage of ICS computers on which malicious objects were blocked, Q3 2023–Q2 2026

Regionally, the percentages ranged from 8.1% in Northern Europe to 27.9% in Africa.

Regions ranked by percentage of attacked ICS computers

Regions ranked by percentage of attacked ICS computers

The figures increased in five regions over the quarter, most notably in East Asia (by 2.0 pp) and Africa (by 0.5 pp).

East Asia saw increases in percentages for all threats except miners. The region ranked first in terms of growth for malicious scripts and phishing pages, spyware, and viruses. East Asia also led in terms of growth in threats from the internet. The percentage of ICS computers on which email threats were blocked also increased.

Selected industries

The biometrics sector (26.44%) has traditionally led the rankings of industries and OT infrastructures surveyed in this report in terms of the percentage of ICS computers on which malicious objects were blocked. Biometric systems are characterized by the availability of internet access, extensive email use for data exchange and approvals (e.g. access granting), and, in many cases, minimal cybersecurity controls within the organizations that use them.

Industries ranked by percentage of ICS computers on which malicious objects were blocked

Industries ranked by percentage of ICS computers on which malicious objects were blocked

The biometrics sector ranked first among industries in terms of the following threat categories: malicious scripts and phishing pages, malicious documents, spyware, ransomware, and worms. The sector is also leading among industries in terms of email threats. At the same time, unlike other industries, the percentage of affected ICS computers for email threats in biometrics exceeds that for internet threats.

In all selected industries, the global average follows a downward trend.

Threat categories

In Q2 2026, Kaspersky security solutions blocked malware from 10,904 different malware families of various categories on industrial automation systems.

Over the quarter, the percentage of ICS computers on which malicious objects of the following categories were blocked increased: denylisted internet resources, malicious documents, worms, ransomware, and malware for AutoCAD.

Percentage of ICS computers on which the activity of malicious objects from various categories was blocked

Percentage of ICS computers on which the activity of malicious objects from various categories was blocked

Malicious scripts and phishing pages (JS and HTML)

Malicious scripts and phishing pages remained in first place in the threat category rankings based on the percentage of ICS computers on which the respective threats were blocked. In Q2 2026, the global average dropped to 5.42%.

Over the quarter, the figure for this category only increased in East Asia, rising by 0.93 pp to 4.86%. This is the second-highest figure in the region in the last three years.

In East Asia, the percentage of ICS computers affected by malicious scripts and phishing pages increased in all the industries surveyed, except construction. The highest figures were recorded for biometrics (9.01%) and building automation (6.49%).

Denylisted internet resources

In Q2 2026, denylisted internet resources rose in the threat category rankings from third to second place, displacing spyware. Globally, the percentage of ICS computers on which denylisted internet resources were blocked has been increasing for two quarters in row and reached 4.31%.

The figures increased in all regions over the quarter, most notably in Russia (by 1.33 pp). Moreover, Russia ranked first (5.17%) among the regions in terms of denylisted internet resources. Since 2022, the region has topped these rankings twice before, both times in Q2: in 2022 and 2024.

Among the selected industries in Russia, the highest figures for the denylisted internet resources were in the electric power (6.61%) and engineering and ICS integration (5.62%) industries.

Malicious documents (MSOffice + PDF)

Malicious documents ranked fourth in the threat category rankings by the percentage of ICS computers on which they were blocked. The percentage for this category decreased over the previous three quarters, reaching its lowest level in three years. However, in Q2 2026, it increased to 1.77%.

Over the quarter, the figures for malicious documents increased in seven regions, most notably in South America (by 1.35 pp) and Southern Europe (by 0.48 pp). These two regions are among the top three in terms of malicious documents, malicious scripts and phishing pages, as well as threats from email clients.

South America ranked second in the rankings of regions in terms of malicious documents. In Q2 2026, the percentage of ICS computers in the region on which this threat was blocked was 3.56%, which was the fourth highest in three years.

Among the selected industries in South America, the highest percentage of ICS computers on which malicious documents were blocked was in biometrics (6.67%).

Southern Europe ranked first in the rankings of regions in terms of malicious documents. In the previous quarter, the percentage of ICS computers in the region on which this threat was blocked was the lowest in three years, but in Q2 2026 it increased to 3.63%.

Among the selected industries in Southern Europe, the highest percentage of ICS computers on which malicious documents were blocked was once again in biometrics (11.48%).

Spyware

Spyware ranked third in the threat category rankings based on the percentage of ICS computers on which it was blocked. The percentage for this category (3.30%) is the lowest since 2022.

Over the quarter, the figures increased in three regions, most notably in East Asia (by 0.53 pp) and Southeast Asia (by 0.42 pp).

East Asia ranked third based on the figures for spyware (4.77%), behind Africa and Southeast Asia. This is the region’s highest rate since Q2 2025. Among the countries and territories in the region, the highest percentage of ICS computers on which spyware was blocked was in mainland China (6.61%). Among the selected industries in East Asia, the highest figures for spyware were in the electric power (11.75%) and manufacturing (5.87%) industries. In all the industries surveyed, the figures are higher than the regional average.

Southeast Asia ranked second after Africa in the ranking of regions in terms of spyware, with 5.32%. Among the selected industries in Southeast Asia, the highest figures for spyware were in biometrics (8.93%) and manufacturing (7.32%). The figures increased in all industries over the quarter.

Ransomware

The percentage of ICS computers on which ransomware was blocked decreased in the previous three quarters but increased to 0.16% in Q2 2026.

During the quarter, the percentage increased in all regions, except Western and Southern Europe and North America (Canada). Africa led the ranking in terms of growth for this metric.

In Q2 2026, Africa ranked first among the regions in terms of the percentage of ICS computers on which ransomware was blocked (0.29%). The only time the figure in the region was higher in the past three years was Q2 2025 (0.31%).

Among the selected industries in Africa, the highest figures for ransomware were in the electric power industry (0.72%) and biometrics (0.52%). Over the quarter, the figures increased in all industries, except manufacturing and construction. The biggest increase was recorded in the electric power industry.

In Russia, the percentage of ICS computers on which ransomware was blocked in biometric systems has increased for three consecutive quarters, reaching 1.22%. This is the highest level of ransomware across all industries in all regions.

Miners

In Q2 2026, the percentage of ICS computers on which miners were blocked was the lowest since 2021, for both miners in the form of executable files for Windows (0.48%) and web miners running in browsers (0.14%).

The figures for both categories decreased in all regions, except for Africa where figures for miners in the form of executable files for Windows increased slightly.

On average, the oil and gas industry led the rankings among the selected industries both in terms of miners in the form of executable files for the Windows OS (0.66%) and in terms of web miners (0.34%).

Worms

In Q2 2026, the percentage of ICS computers on which worms were blocked increased to 1.43%.

In Q2 2026, the Middle East (2.11%) was second (after Africa) in the rankings of regions in terms of worms, displacing Central Asia and the South Caucasus.

Among the selected industries in the Middle East, the highest percentage of ICS computers on which worms were blocked was in building automation (2.90%). Over the quarter, the figures increased in all industries.

Australia and New Zealand ranked 12th among the regions in terms of the percentage of ICS computers on which worms were blocked (0.41%). Over the past three years, the figure in this region was only higher in Q2 2024 (0.42%). The figures increased in all the surveyed industries in the region, most notably in manufacturing and electric power. As a result, for these industries they exceeded the regional average by 2.9 and 2.3 times, respectively.

Viruses

In Q2 2026, the percentage of ICS computers on which viruses were blocked decreased to 1.29%.

The top three regions for this metric remain unchanged: Southeast Asia (6.03%), Africa (4.22%), and East Asia (3.14%). These same regions lead the rankings in terms of malware for AutoCAD.

The figures increased in three regions: East Asia, Australia and New Zealand, and Africa, where it has been growing for four consecutive quarters and reached its highest value since 2022.

Among the selected industries in Africa, the highest percentage of ICS computers on which viruses were blocked was in construction (5.47%).

East Asia ranked third among the regions in terms of viruses, reaching the highest level in the region for the past three years. Among the countries and administrative regions of East Asia, mainland China is the clear leader in terms of viruses (5.07%).

Among the selected industries in East Asia, the highest percentage of ICS computers on which viruses were blocked was in construction (5.93%).

In Australia and New Zealand, the increase in the percentage of ICS computers on which viruses were blocked was primarily due to a 4.3-fold increase in the figure for the electric power industry: from 0.29% to 1.24%. For a region where the percentage of attacked ICS computers for all threats is 0.12%, this is a very high value.

Malware for AutoCAD

In Q2 2026, the percentage of ICS computers on which malware for AutoCAD was blocked increased to 0.31%.

The most notable increase over the quarter was observed in Africa. After more than doubling in the previous quarter, the figure for the region continued to rise (although not so dramatically), reaching 1.02%.

Among the selected industries across all regions, the highest percentage of ICS computers on which malware for AutoCAD was blocked was in construction in East Asia (6.38%) and in Southeast Asia (4.05%).

Main threat sources

In Q2 2026, of all the threat sources, the percentage increased only for email.

Percentage of ICS computers on which malicious objects from various sources were blocked

Percentage of ICS computers on which malicious objects from various sources were blocked

Internet

The percentage of ICS computers on which threats from the internet were blocked decreased to 7.61%, reaching its lowest level since 2021.

Over the quarter, the percentage increased in three regions: East Asia by 0.8 pp (to 6.3%), South Asia by 0.3 pp (to 10.4%), and Russia by 0.3 pp (to 6.4%).

Among the selected industries across all regions, the highest percentage of ICS computers on which threats from the internet were blocked was in biometrics (13.03%) and engineering and ICS integration (12.16%) in South Asia.

Email

The percentage of ICS computers on which email threats were blocked increased to 2.84%.

In Q2 2026, the percentage of ICS computers on which email threats were blocked increased in South America by 1.0 pp (to 5.2%) and in Africa by 0.7 pp (to 4.3%).

Among the selected industries across all regions, the highest percentage of ICS computers on which email threats were blocked was in biometrics (19.14%) and building automation (12.49%) in Southern Europe.

Removable media

The percentage of ICS computers on which threats from removable media were blocked continued to decrease, reaching 0.24%, the lowest value for the period under review.

Among the selected industries across all regions, the highest percentage of ICS computers on which threats from removable media were blocked was in the electric power industry in East Asia (1.34%) and biometrics in Africa (1.29%).

Network folders

The percentage of ICS computers on which threats from network folders were blocked continued to decrease. In Q2 2026, it was the lowest for the period under review, at 0.023%.

The only region to see an increase in the percentage of ICS computers on which threats from network folders were blocked during the quarter was Africa. This was mainly due to an increase in the building automation figure to 0.05%.

Among the selected industries across all regions, the highest percentage of ICS computers on which threats from network folders were blocked was in biometrics (0.23%), building automation (0.17%), and engineering and ICS integration (0.13%) in East Asia.

For more information on industrial threats see the full version of the report.

  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 4, August 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026           Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations and Companies [1] [2] [3] […]
     

Ransom & Dark Web Issues Week 4, August 2026

Por:ATCP
26 de Agosto de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 4, August2026           Saudi Arabian Digital Entertainment Streaming Service User Data Offered for Sale SAFEPAY Ransomware Attack on a South Korean Industrial Gas Manufacturer and Supplier NoName057(16) and BD Anonymous Claim DDoS Attacks Against Major Japanese Organizations and Companies [1] [2] [3] […]

Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations

A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine countries between April and July 2026, using the AI coding assistant Cursor to plan intrusion activity and Active Directory escalation. The exposed server offered an unusually complete view of a ransomware affiliate’s operational workflow. It contained victim-specific directories, shell history, […]

The post Ransomware Hacker Uses AI to Plan Attacks and Compromises More Than 20 Organizations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

  • ✇Krebs on Security
  • Two Alleged ‘TeamPCP’ Hackers Arrested in Australia BrianKrebs
    Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses
     

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

27 de Agosto de 2026, 08:04

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.

In a statement released today, the Australian Federal Police (AFP) said two men from Western Australia, aged 21 and 23, were arrested in connection with a “sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.”

The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect’s real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP’s self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.

TeamPCP vaulted onto the cybercrime scene in late 2025, embedding malicious code in hundreds of open source software tools and extorting victims for profit. Members of the group made headlines by compromising corporate cloud environments using a self-propagating worm dubbed Shai-Hulud, which added malicious code to open source programs maintained by developers whose credentials at public code repositories like GitHub or NPM were phished or stolen.

Writing for Wired, journalist Andy Greenberg described TeamPCP’s core tactic as a kind of cyclical exploitation of software developers.

“The hackers gain access to a network where an open source tool commonly used by coders is being developed,” Greenberg wrote in May. “The hackers plant malware in the tool that ends up on other software developers’ machines, including some who are writing other tools intended to be used by coders. The malware allows TeamPCP’s hackers to steal credentials that let them publish malicious versions of those software development tools, too. The cycle repeats, and TeamPCP’s collection of breached networks grows.”

TeamPCP also has practiced something akin to cyclical recruitment. In May, the source code for the third iteration of Shai-Hulud was published online, and TeamPCP soon after launched a contest offering $1,000 in virtual currency to whichever participant could conduct the largest supply chain operation using the worm’s code. According to the contest rules, participants were scored based on the number of weekly and monthly downloads of packages they compromised — directly incentivizing them to target the most popular code libraries.

A screenshot of a message from TeamPCP’s Telegram account, announcing the supply chain hacking contest. Image: dataminr.com.

“TeamPCP has stated the competition is a recruiting opportunity and they intend to purchase all meaningful access harvested from participants’ campaigns,” the security firm Dataminr wrote. “The $1,000 XMR (Monero) prize is a recruitment floor and has been dismissed by the actor as ‘just like participation trophy,’ adding ‘if you find something good you will be paid way more,’ confirming the contest’s true function as talent identification and malicious access acquisition at scale.”

In March, TeamPCP executed a supply chain attack targeting AI infrastructure by compromising the code for LiteLLM, an open source AI gateway that connects users to more than 100 different large language models. A recent analysis by the security firm CloudSEK found TeamPCPs attack on LiteLLM harvested cloud service keys and other secrets from more than 2,500 organizations, including many of the world’s top technology companies.

In May, TeamPCP claimed credit for compromising at least 3,800 code repositories at the Microsoft-owned GitHub, after a GitHub developer installed a code extension that was compromised by TeamPCP’s malware.

MEET THE CYBERCATS

Security experts say TeamPCP is less of a hacker group than an amalgamation of threat actors from multiple cybercriminal gangs who sometimes work together toward similar goals.

“It is not a structured criminal crew with a single operator,” said Austin Larsen, a principal threat analyst with the Google Threat Intelligence Group. “It is a peer community of individually-skilled actors, with one clear center of gravity.”

That center of gravity is George Prepakis, an accomplished security researcher and self-described exploit developer who operates the Twitter/X profile @kernelstub. Earlier this year, @kernelstub tweeted a public invite link to a Matrix chat server he created and dubbed “Cybercats,” and TeamPCP and several other cybercrime entities have been using this server to communicate daily for the past several months.

A screenshot of the Matrix chat server “Cybercats,” whose members used hacker handles associated with multiple distinct cybercrime groups that have occasionally collaborated on a series of supply chain and data ransom attacks over the past nine months.

Kernelstub, like other administrators in the Cybercats chat, has been using his Twitter/X profile name as his handle in these Matrix communications, frequently tweeting references to other members and to conversations taking place in the Cybercats chat. In a number of cases, the corresponding X accounts for members of the Cybercats chat taunted cybercrime victims publicly before the incidents were reported in the news media.

The Cybercats administrator listed at the top of the screenshot above — “Boxturtle” — is a close associate of TeamPCP who has been tweeting about the group’s conquests under the name @xpl0itrsturtle. This handle corresponds to a data breach broker active on Breachforums and Darkforums who has been selling data stolen in a wave of recent breaches at automobile manufacturers, including BMW Group, Audi, Honda, Mercedes-Benz, Volvo and Toyota, as well as data allegedly taken from Snapchat and SportRadar.

The data leak site for the extortion group or handle “xpl0itrs.”

The Cybercats administrator “SeesawSec” in the screenshot above is the alias of whoever is behind the cybercrime group known as Fulcrumsec, which recently claimed credit for data extortion attacks against the pharmaceutical giant Novo Nordisk, the data broker LexisNexis, and Avnet, a Fortune 500 distributor of electronic components.

The data leak site of Fulcrum Security, a.k.a. Fulcrumsec.

The Cybercats administrator “@pcpcasper” also has been using a similar name on X to discuss TeamPCP’s attacks and victims. This person has an extensive message history on Telegram, where their messages and shared videos show @pcpcasper is an active and vocal member of the National Socialist Network, a neo-Nazi political organization based in Australia.

At one point in these chats, @pcpcasper shared videos and images of what they claimed was their cat, and several of those videos place this user in Western Australia. One source close to the investigation told KrebsOnSecurity that @pcpcasper was one of the two arrested, a claim supported by messages that @kernelstub posted online this morning.

The Cybercats member roster pictured above also features an administrator with the username “T,” which is short for the now-banned Twitter/X profile @pcpcats, the account operated by the self-described TeamPCP spokesperson who was arrested today. As we’ll see in a moment, @pcpcats also is from Western Australia.

By the time @kernelstub tweeted a public invite link to the Cybercats Matrix server, T/@pcpcats was posting only infrequently to the group chat, with other members often inquiring as to his whereabouts and well-being. The group’s collective concern related to @pcpcats’s tendency to blame his increasingly extended absences on the use of hallucinogens and other narcotics that kept him awake for days on end, but also caused him to crash in bed for several days after the highs wore off.

WHO IS THE TEAMPCP LEADER?

The Cybercats member @pcpcats has used multiple nicknames on the cybercrime forums, including EllisD25/LSD on Darkforums, BulkDMT on Breachstars, and Express on Breachforums. These accounts are linked because they all advertised the same Tox ID and/or Session ID as instant message contact handles in their cybercrime forum posts. BulkDMT was also known on the forums as DMT Host, which was a virtual private server (VPS) hosting service that was peddled on Darkforums and Breachstars.

DMT Host/EllisD25, posting on the English-language cybercrime community DarkForums in September 2025. Image: ke-la.com.

According to the cyber intelligence firm Intel 471, Express registered on Breachforums using the email address shitstickpp@gmail.com. Intel 471 finds Express posted on Breachforums across a two-month period in 2025 using four different Internet addresses located in South Africa. On July 30, 2025, Express announced on Breachforums they were selling access to 14 gigabytes of data stolen from South Africa’s State Information Technology Agency.

The threat intelligence platform Flashpoint recorded more than a year’s worth of messages from the TeamPCP leader’s alter ego on Telegram — Persy_PCP —  who claimed they split their life living between two countries [full disclosure: Flashpoint is an advertiser on this blog]. “I have these [files] as well, problem is these are in another country,” Persy_PCP explained to another user inquiring about a stolen data set in November 2025.

Later that month, Persy_PCP complained, “My whole country is racist and they want people like me dead.” Flashpoint records show BulkDMT shared in September 2025 that “this country is going to fucking starve when they take the farmers land,” a likely reference to white landowners in South Africa who claim to be targeted by an ongoing genocide campaign.

This tracks with public reporting on TeamPCP. Cyberscoop reported in June that Google had traced TeamPCP’s residential and mobile Internet address connections to South Africa, “indicating the primary operator was located there during at least some of its attacks.”

BulkDMT also shared on the group chat at Breachforums that they were recovering from an addiction to methamphetamine. “My life is kinda fucked rn [right now], but that’s fine and there isn’t really a point in pouring so much emotional energy into that fact, my parents had money but I unfortunately got really addicted to some things so I don’t get to benefit from that. As long as I continue to survive, stay sober, and move closer towards my goals that’s enough drive and meaning.”

The identity threat protection company SpyCloud finds shitstickpp@gmail.com shows up in the registration of an account called ChristmasSnow on the cybercrime community Raidforums in 2022. Nearly all of the Internet addresses used to access that account came from ISPs in Perth, Australia, SpyCloud found.

KrebsOnSecurity looked up all of those Perth IP addresses in passive DNS records maintained by DomainTools.com, and found one of them — 211.27.196.111 — for several years was used as a private file server by a family in Perth with the last name of Thomson. Those records show at least three hosts — ithomson.direct.quickconnect.to (a remote Synology server), kthomson0061.direct.quickconnect.to, and joshuawthomson39.myqnapcloud.com (a QNAP network storage device) — persisted at that address between 2022 and 2025.

Searching on “joshuathomson39” in the breach tracking service Constella Intelligence reveals an account at the freight forwarding company kwe.com created in the name of Joshua Thomson from Perth, Australia. The open source intelligence platform Epieos finds the phone number attached to that kwe.com account was used to register a Facebook profile for Josh Thomson, which says his family includes a brother named Ruben, his father Ian, and his mom Cindy.

That Facebook profile also says Josh and his family are originally from Pietermaritzburg, in KwaZulu-Natal, South Africa, but currently living in Cottesloe, a beach-side suburb of Perth. A search in DomainTools for Ian Thomson and Australia unearthed five domains by the same registrant, including securecomputing.au, thomson.org.au, and thomsonfamily.net.au. Ian Thomson is a dentist in Cottesloe, and a biography says he graduated from The University of the Witwatersrand in Johannesburg, South Africa.

Constella finds a joshua@thomson.org.au registered a number of accounts online, but Josh doesn’t seem to have much of a connection to dodgy cybercrime forums. His brother Ruben, on the other hand, has quite the presence on these communities, dating back to at least 2018. Constella reports ruben@thomson.org.au frequently reused the password “joshuathomson1,” and Constella further finds that password was used by just a handful of accounts, including yolosolo17@gmail.com and surfinup8@gmail.com.

According to Intel 471, surfinup8@gmail.com was used to register the user Yolosolo17 on the crime forum Altenen in 2018, and that user account was registered from the Perth address 110.141.230.15. On Altenen, Yolosolo17 advertised free web proxies, as well as the domain rubenthomson.com, which was at one point used to sell steeply discounted iPhones. DomainTools says rubenthomson.com was hosted at 110.141.230.15 and registered to surfinup8@gmail.com.

A cached copy of the domain rubenthomson.com from 2017 shows a login page underneath a banded stack of money. Image: archive.org.

SpyCloud reports 10.141.230.15 was used by the email address sheepstealing@gmail.com on Raidforums and surfinup8@gmail.com on Nulled, and that the same IP was used by the email addresses ian@thomsonfamily.net.au, jasper@yakuza.cc, and rubenthomson1@gmail.com. SpyCloud also shows that sheepstealing Gmail address is tied to the accounts Sheep420, YoloSolo117 and Yakuza.cc on Raidforums, and to the account “Sheep Stealing” on Hackforums. Intel 471 says sheepstealing@gmail.com was used to register the account DingoFlour on Breachforums in October 2023, as well Sheepx on Altenen.

Epieos reports that ruben@securecomputing.au is tied to an Airbnb account for Ruben, who described himself as a Web developer who went to school at the University of Western Australia and was living outside the country. “Hey, I’m Ruben, my friends call me Ellis. I’m a Perth creative who occasionally books rooms when visiting family and for photography.”

Epieos also finds sheepstealing@gmail.com registered an upwork.com profile under the name Ruben, who said his main skills are setting up secure server hosting solutions and PHP full-stack Web development.

“I’m familiar with Linux, working with relational databases (SQL),” the Upwork profile reads. “I also script in Python mainly for writing social media bots.”

The Upwork profile for Ruben Thomson in Cottesloe, Australia.

Epieos further discovered sheepstealing@gmail.com is connected to a Microsoft account for Ruben Thomson, and to a now-defunct GitHub account called XmasSnow/XmasSnowisBack that scammed people on the forums in 2022 by claiming to sell exclusive exploits for recently-released software patches (recall that shitstickpp@gmail.com was used to register a forum account named ChristmasSnow).

This same sheepstealing email address registered a Twitter/X account in 2026 called “Gone Fishing” that lists its location as South Africa. That Gmail account also left several reviews for businesses listed on Google Maps over the past seven years, but all of those establishments are located on the west coast of Australia.

Business reviews in Western Australia left by the Google account sheepstealing at gmail.com.

The people search service Pipl finds a 21-year-old Ruben Thomson in Western Australia who has a phone number ending in 979. A lookup on that number at Epieos reveals it is connected to a TikTok account under the name Ellis, and to a PayPal account in the name of Ruben Thomson.

Finally, a search on the name Ruben Thomson from Cottesloe at the Australian government’s record of registered businesses finds he has incorporated or served as an official in multiple companies created since 2024, including Secure Computing Solutions, Tensor Industries, and another entity ironically named OPSEC Express. Recall that Express was BulkDMT’s nickname on Breachforums.

Australian companies connected to Ruben Thomson. Image: abr.business.gov.au.

It’s ironic because OPSEC is short for the term “operational security,” which refers to techniques and behaviors used to obfuscate and compartmentalize one’s real-life identity online, and using your cybercrime handle as part of your own company name is very much the antithesis of that practice.

There is at least one other major opsec failure by Ruben that exposed a link to TeamPCP. In June 2025, someone using the name Ruben Thomson registered on HackerOne, a popular “bug bounty” program that seeks to reward and recognize researchers who agree to work with affected software vendors to help fix the flaws before publishing about their findings. What was Ruben Thomson’s chosen HackerOne username? Deadcatx3, a nickname that has been flagged by multiple security firms as an alias used by TeamPCP.

The HackerOne profile for “Ruben Thomson” uses the nickname Deadcatx3, which multiple security firms have concluded is an alias used by TeamPCP. Image credit: flare.io.

INTERVIEW WITH ELLIS

In early July 2026, not long after having discovered clues about Ellis’s real life identity, KrebsOnSecurity interviewed the TeamPCP leader via Signal, where he was remarkably open about his activities and personal struggles [for the sake of simplicity, the TeamPCP spokesperson will be referred to from here on as Ellis].

Ellis claims he stopped doing cybercrime for TeamPCP in March 2026 — just before the attacks that compromised LiteLLM — and that at least one other individual has taken over the group’s leadership since then. Ellis shared that a year earlier he had just completed the latest in a series of detox and sobriety programs, and was two months sober when he reconnected with some old friends from the malware development scene.

“One year ago I needed help monetizing some [GitHub credentials], I was two months sober and needed a distraction and something to keep busy as well as people to speak to,” Ellis said. “I had largely disconnected from my old circle, they had become very toxic and I needed to get away from the substances. Previously I had done some mass exploitation campaigns and grew up doing [malware development] and [capture the flag] contests. There were some friends who were also vending but had stopped a while, and one of them introduced me to some chats where I posted access for sale.”

Prior to that, Ellis said, he was homeless and hopping between “some very unstable places.”

“Blackhatting is fun,” he said. “There are actual rewards and incentives to learn and you grow with your team. Without qualifications, no employer will even take the time to hear you out.”

Ellis claims he’s earned a grand total of about $20,000 for his activities with TeamPCP, and that it was never about the money or fame for him. Asked whether his experiences with TeamPCP might prepare him for gainful employment in a legitimate IT job, Ellis said he doubted it.

“I am nowhere close to a skill level where I am comfortable, and this would take maybe half a decade of further experience,” he said. “I no longer have to choose between rent and food for that I’m grateful and so are the team members.”

Ellis expressed no remorse over his cybercrime activities, and said he was grateful for the friendships and relationships built throughout his engagement with TeamPCP. The young hacker also seemed resigned to his fate, and told KrebsOnSecurity that he’ll accept the consequences if he’s ever arrested.

“If I’ve already been found out then its out of my control, I’ll make peace with that,” he said. “Honestly, I think someone like me needs a lot of help that prison just can’t provide. If I had the funds to study different parts of the field and closer guidance, this would have turned out differently. But that’s a pipe dream and we both know this.”

It is clear from reading Ellis’s posts to the group’s Matrix server chats that his struggles with sobriety are ongoing. On Thursday, June 25, Ellis told @kernelstub he was about to “trip” with his “homie.”

“What kind,” @kernelstub inquired.

“Ketty and some DMT,” Ellis replied, referring to the dissociative anesthetic ketamine and dimethyltryptamine (DMT), a powerful psychedelic compound that is found naturally in some plants but is also synthetically produced in underground lab environments. “There’s a little 2cb so we might throw that in the mix,” he continued, referring to another psychedelic compound by its chemical shorthand.

Roughly two weeks before his arrest, Ellis told KrebsOnSecurity he was ready to leave his life of crime behind and was prepared to turn himself in, but that in the meantime he was making plans to tie up loose ends.

Less than 24 hours later, the TeamPCP leader posted an image on Telegram showing a yellowish powdered substance in a baggie and on a scale, possibly synthetic DMT. The image shows the powder being weighed next to a series of small vape cartridges, two of which are open on the table in front of the photographer.

An image posted by the TeamPCP leader to Telegram, advertising his acquisition of some type of psychoactive substance, most likely a synthetic version of the powerful hallucinogen known as DMT.

The two defendants were arrested Wednesday morning. The AFP said the men face a combined 14 cybercrime offenses and are scheduled to appear in Perth Magistrates Court today.

Charlie Eriksen is a security researcher at Aikido Security who has closely followed TeamPCP’s cybercrime campaigns. Eriksen said TeamPCP are a good example of a new kind of threat actor that does not fit neatly into the usual categories.

“They are not a state actor, not quite organized cybercrime, and not purely ideological,” he said. “Their motivations seem to mix money, disruption, attention, and ideology.”

Eriksen said that historically there has always been a meaningful gap between reading about an attack technique and being able to reliably turn it into an operational campaign, but that large language models (LLMs) and artificial intelligence increasingly are helping threat actors to bypass that knowledge gap.

“You had to understand the research, adapt the code, troubleshoot it, build infrastructure around it, and then repeat that process across different targets,” he said. “LLMs have compressed that gap significantly.”

According to Eriksen, this creates an environment where threat actors suddenly have the ability to operate at significant scale without having developed the operational discipline that traditionally accompanies that level of capability. Put another way, it sets the stage for cybercriminals who are capable enough to cause significant damage, but not necessarily careful enough to understand or care about the consequences.

“They can be noisy, they can make mistakes,” he said. “They can leave evidence everywhere. They can take risks that a professional criminal group or intelligence service would consider completely unacceptable. But that does not necessarily make them less dangerous. In some ways, it can make them more dangerous.”

In a recent blog post, Eriksen called TeamPCP’s Shai-Hulud worm the “best thing to happen to supply chain security,” because it forced GitHub and other public coding platforms to erect new security safeguards.

In direct response to TeamPCP’s broad success at pushing poisoned versions of popular software packages, GitHub in late July introduced a three-day “cooldown” mechanism for Dependabot, the platform’s tool for auto-fetching newly shipped updates for any package dependencies. Cooldown periods are designed to help buy time for security tools and package maintainers to identify and remove any compromised versions. Other coding ecosystems like Python and various JavaScript platforms also added support for cooldown periods this year amid growing calls from security experts about the need for more widespread adoption of the safety feature.

Eriksen said TeamPCP’s legacy is that they achieved in the span of a few months what the supply chain security community has been unable to do for years.

“They managed to wake up Microsoft to the fact that they had become negligent in terms of security,” Eriksen said. “By compromising GitHub and stealing their source code, they humiliated Microsoft into action, making them finally act on what we had been asking them to do and take seriously for a while now.”

Update, 10:08 a.m. ET: A story this morning from ABC News in Australia confirms Ruben Ian Thomson of Cottesloe was one of the two arrested. The 23-year-old suspect thought to be @pcpcasper, Michael Gaebler, also was arrested in Perth. ABC News reports that Thomson was denied bail (Mr. Gaebler’s attorney reportedly did not request bail for his client), and that both men will be held in custody until their next court appearance on September 18.

  • ✇Blog – Cyble
  • From ‘High/Medium/Low’ to Dollars: Making Cyber Risk Legible to Your CFO  Ashish Khaitan
    For years, cybersecurity teams have communicated risk through labels such as “High,” “Medium,” and “Low.” Those ratings can help security teams prioritize vulnerabilities, but they often leave CFOs with a more important question unanswered: What does the risk actually mean for the business financially?  That question has become harder to ignore as the threat landscape accelerates. Cyble’s 2025 threat predictions, published as the year unfolded, provide a useful illustration. More than 80% of
     

From ‘High/Medium/Low’ to Dollars: Making Cyber Risk Legible to Your CFO 

25 de Agosto de 2026, 06:45

Financial Exposure, cyber risk quantification,

For years, cybersecurity teams have communicated risk through labels such as “High,” “Medium,” and “Low.” Those ratings can help security teams prioritize vulnerabilities, but they often leave CFOs with a more important question unanswered: What does the risk actually mean for the business financially? 

That question has become harder to ignore as the threat landscape accelerates. Cyble’s 2025 threat predictions, published as the year unfolded, provide a useful illustration. More than 80% of the threats Cyble forecast—including AI-driven ransomware and complex supply-chain attacks—materialized as anticipated.  

It was observed that dark-web discussions about using large language models for phishing, automated social engineering, and ransomware negotiation as early as six months before AI-powered ransomware became a mainstream concern. 

From Threat Signals to Financial Exposure 

Cyble’s 2025 research identified several trends that demonstrate why qualitative risk scores are no longer enough. 

Ransomware incidents increased by 52% in 2025, according to Cyble's analysis. Cyble's full-year 2025 report recorded 6,604 ransomware attacks, compared with 4,346 in 2024. December 2025 alone recorded nearly 731 attacks, the second-highest monthly total of the year, surpassed only by February. 

The FBI and CISA also issued joint warnings regarding Medusa ransomware, including the use of AI to streamline intrusion, escalate privileges, and evade detection. The EU SOCTA 2025 report similarly identified an increase in ransomware activity. Cyble also documented 57 new ransomware groups, 27 new extortion groups, and more than 350 new ransomware strains during 2025 alone. 

At the same time, ransomware affiliates proved remarkably adaptable. Cyble also documented 57 new ransomware groups, 27 new extortion groups, and more than 350 new ransomware strains during 2025 alone. 

International disruption operations targeted several ransomware ecosystems, but as RansomHub went offline in April 2025 and Black Basta became largely inactive following internal chat leaks and operational disputes, displaced affiliates migrated between operators and adopted distributed criminal models rather than withdrawing from the market. The United States remained the primary target, accounting for 55% of attacks in 2025. 

Qilin and DragonForce absorbed the bulk of those displaced affiliates, reinforcing the resilience that has made ransomware a persistently growing threat. 

Public-facing applications and zero-days remained another major entry point. The data supported its prediction that exposed applications would remain attractive targets. Incidents involving Multer for Node.js, Microsoft SharePoint, CVE-2025-20337, and CVE-2025-5777 reinforced that concern. 
 
Identity and credential compromise became the dominant initial-access vector: Unit 42 attributed 65% of intrusions to compromised credentials, stolen infostealer logs, and abused VPN access. ClickFix social-engineering lures — which manipulate users into executing malicious commands — increased 517% year over year in the first half of 2025. 

Cloud and hybrid environments also became increasingly important targets. Campaigns associated with Silk Typhoon, attacks against cloud-based identity systems, and growing software supply-chain activity demonstrated how attackers were expanding beyond traditional infrastructure. 

Supply-chain ransomware followed the same trajectory. Cyble recorded a 93% increase in supply-chain attacks, from 154 incidents in 2024 to 297 in 2025. LockBit 5.0 emphasized third-party compromise, while activity associated with Qilin, SafePay (which claimed 58 victims in May 2025 alone), and DevMan demonstrated how IT providers and technology vendors can become pathways to multiple victims. 

Critical infrastructure also faced heightened pressure amid geopolitical tensions. Hacktivist campaigns targeted energy, transportation, and government systems, while the UAE reported successfully blocking a major cyberattack against critical infrastructure, and China accused Taiwan of targeted cyber intrusions. 

Meanwhile, underground ecosystems remained resilient. Forums including XSS, Exploit, and RAMP continued to support malware development, initial-access brokerage, affiliate recruitment, and the exchange of stolen data. The HelloKitty-to-HelloGookie transition provided another example of how underground communities support ransomware operations. 

Cyble’s Cyber Risk Quantification (CRQ) addresses the gap between technical severity and business impact. The cloud-native SaaS platform combines real-time threat intelligence, asset visibility, and predictive analytics to quantify cyber risk in financial terms, calculate Return on Security Investment (RoSI), and align security decisions with enterprise value. 

See how Cyble CRQ turns cyber exposure into financial insight. Discover your financial exposure now! 

What the CFO Needs to Know 

A CFO does not necessarily need another dashboard showing hundreds of vulnerabilities. The finance function needs to understand questions such as: 

  • What could this threat cost? 

  • Which business assets create the greatest financial exposure? 

  • What is the likelihood of a loss event? 

  • Which security control reduces the most risk? 

  • How much would that control cost? 

  • What is the expected return on the investment? 

That is where CRQ changes the conversation. Instead of reporting that a vulnerability is “critical,” security teams can model its potential effect on operations and financial performance. 
 
Recent incidents illustrate the stakes: Marks & Spencer estimated an impact of approximately £300 million on its 2025/26 annual profit from a single ransomware incident, and the Cyber Monitoring Centre assessed the combined losses for M&S and Co-op at £270 million to £440 million, excluding any ransom payments. Meanwhile, only 28% of victims paid a ransom in 2025 — down from 62.8% in 2024 — yet the median payment increased 368%, reflecting a shift toward higher-value, targeted demands. 

Cyble CRQ provides enterprise- and asset-level risk quantification, financial risk modeling, RoSI analysis, real-time dashboards, and operational metrics including MTTD, MTTN, MTTR, FPR, and IRR. Cyble's capabilities can help reduce breach containment time by up to 23%. The platform can also integrate with Cyble CSPM, Threat Intelligence, and Asset Management through APIs and real-time feeds. 

Its AI-driven risk engine ingests security and business data, evaluates potential loss scenarios, models the effect of different controls, and continuously updates exposure as conditions change. The result is a risk picture that both the CISO and CFO can interpret. 

The Executive Risk Equation 

Financial exposure is not limited to infrastructure. Executives themselves are increasingly valuable targets because compromising a trusted leader can provide access to sensitive information, systems, and relationships. 

Spear-phishing, executive impersonation, credential theft, dark-web exposure, and social engineering can create direct financial, regulatory, and reputational consequences. A compromised CFO account, for example, could be abused to distribute fraudulent financial information, while a compromised CEO identity could be used to manipulate employees, customers, or business partners. 

Cyble’s Executive Monitoring capability extends visibility into these risks by monitoring for impersonation, leaked information, dark web exposure, and emerging threats targeting organizational leadership. 

This becomes particularly important when executives operate outside the traditional corporate perimeter through personal devices, external platforms, social media, travel environments, and other channels. A mature risk strategy, therefore, needs to connect technology risk, human risk, and business impact. 

From Security Budget to Business Investment 

Cyble Saratoga takes this approach further by combining cyber risk quantification with investment optimization, human and process risk analysis, scalable assessment models, and executive-ready dashboards. Built on Cyble’s AI-native foundation and evolving toward agentic intelligence, the platform is designed to continuously adapt to changing environments and threat conditions. 

The objective is not simply to produce a better risk score. It helps organizations determine where to invest first and why. 

For financial services organizations, that can mean quantifying ransomware, fraud, credential compromise, and operational disruption. For manufacturing and supply chains, it can mean assessing third-party exposure and potential downtime. In 2025, manufacturing accounted for 65% of all industrial ransomware activity, with 1,660 victims, making it the most heavily targeted sector of the year.  

Healthcare organizations can evaluate risks to patient data and critical systems - 423 healthcare ransomware attacks were recorded in the first nine months of 2025, with average ransom demands of USD 514,000 to USD 532,000, while government and critical-infrastructure operators can translate complex cyber exposure into measurable financial and operational consequences. 

Conclusion 

Cyber risk is no longer a static “High, Medium, or Low” assessment—it is a dynamic business exposure that can directly impact revenue, operations, reputation, and resilience. With more than 80% of Cyble’s 2025 threat predictions materializing, organizations need to move beyond severity scores and understand what cyber risk could actually cost.  

Cyble CRQ helps security and finance leaders quantify cyber exposure in financial terms, prioritize the investments that matter most, and measure how effectively each security dollar reduces risk. 

Stop telling the board your cyber risk is “High.” Tell them what it could cost. 

Turn cyber risk into financial clarity with Cyble CRQ. Request a personalized demo today. 

References: 

The post From ‘High/Medium/Low’ to Dollars: Making Cyber Risk Legible to Your CFO  appeared first on Cyble.

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

25 de Agosto de 2026, 07:00

Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.

The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.

  • ✇Cybersecurity News
  • Clop Deploys Custom Web Shell in PTC Windchill Extortion Attacks Do Son
    The Clop web shell targets PTC Windchill via CVE-2026-12569, stealing credentials and engineering data in a mass-extortion campaign. Related Posts: WordlistLoader Delivers Amatera Stealer Through ClearFake Campaigns C2Looper: Rust Backdoor Uses GitHub for C2 Control Manic Android Malware Steals Data Without Active Internet The post Clop Deploys Custom Web Shell in PTC Windchill Extortion Attacks appeared first on Daily CyberSecurity.
     

Gunra ransomware: what you need to know

24 de Agosto de 2026, 09:52
The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog.
  • ✇Cybersecurity News
  • StopAndProtect Malware Turns Hacked WordPress Sites Into a Botnet Do Son
    StopAndProtect malware turns hacked WordPress sites into a botnet for ransomware and data theft. Check Point exposed 5,000+ victims. Related Posts: Cisco Talos Exposes UAT-10147 Agentic AI Attacks Operation ASTERIX: Crypto Scam Used AI and Fake Wallets Operation QUICSILVER Targets Myanmar Government With Go Backdoor The post StopAndProtect Malware Turns Hacked WordPress Sites Into a Botnet appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • C2Looper: Rust Backdoor Uses GitHub for C2 Control Do Son
    Zscaler details the C2Looper backdoor, a Rust backdoor tied to ransomware that uses GitHub for C2 and likely spreads through ClickFix lures. Related Posts: WordlistLoader Delivers Amatera Stealer Through ClearFake Campaigns Manic Android Malware Steals Data Without Active Internet Android Head Unit Malware Recruits Vehicles into Botnet The post C2Looper: Rust Backdoor Uses GitHub for C2 Control appeared first on Daily CyberSecurity.
     
  • ✇ASEC BLOG
  • Security Issues in the Korean & Global Financial Sector in July 2026 ATCP
    Statistics on Malware Distributed to the Financial Sector In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month. In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from […]
     

Security Issues in the Korean & Global Financial Sector in July 2026

Por:ATCP
9 de Agosto de 2026, 12:00
Statistics on Malware Distributed to the Financial Sector In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month. In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from […]
  • ✇Blog – Cyble
  • Endpoint Blind Spots: The 5 Places Ransomware Hides Before It Detonates Ashish Khaitan
    Ransomware rarely appears out of nowhere. Before encryption, extortion, or data theft begins, attackers often spend time establishing access, stealing credentials, moving laterally, and identifying valuable systems. These activities occur during the ransomware pre-execution phase, when malicious activity may be difficult to distinguish from legitimate administration.  For security teams, understanding ransomware attack vectors, ransomware initial access methods, and how ransomware evades det
     

Endpoint Blind Spots: The 5 Places Ransomware Hides Before It Detonates

21 de Agosto de 2026, 04:51

ransomware attack vectors

Ransomware rarely appears out of nowhere. Before encryption, extortion, or data theft begins, attackers often spend time establishing access, stealing credentials, moving laterally, and identifying valuable systems. These activities occur during the ransomware pre-execution phase, when malicious activity may be difficult to distinguish from legitimate administration. 

For security teams, understanding ransomware attack vectors, ransomware initial access methods, and how ransomware evades detection is critical. Endpoint security blind spots can give attackers the time they need to prepare an attack without triggering an obvious alarm. 

Here are five areas where ransomware activity can remain hidden before detonation. 

1. Remote Access Tools: A Favorite Ransomware Attack Vector 

VPNs, RDP, and remote management tools are essential for distributed organizations, but they are also among the most important ransomware attack vectors. 

Qilin affiliates have abused tools including WinSCP, AnyDesk, and ScreenConnect to facilitate lateral movement. Attackers who obtain valid credentials can potentially use legitimate remote-access software without immediately deploying obvious malware. 

This is one reason why ransomware evasion cannot be reduced to antivirus evasion alone. Attackers can blend into normal administrative activity. 

Organizations should enforce MFA on remote-access systems, monitor unusual login behavior, and restrict remote administration privileges. 

2. Compromised Endpoints and Credential Stores 

A compromised laptop or workstation may be only the beginning. Attackers can use credential-stealing tools to obtain additional passwords and authentication material, allowing them to move toward servers, backups, and privileged accounts. 

CRIL has tracked ransomware operators using credential-harvesting techniques associated with tools such as NirSoft and Mimikatz. BYOVD, or Bring Your Own Vulnerable Driver, is another technique security teams should monitor because vulnerable drivers can help attackers bypass security controls. 

These activities represent major endpoint security blind spots when organizations monitor servers but have limited visibility across employee workstations. 

EDR coverage across every endpoint can help identify unusual processes, credential access, and other indicators during the ransomware pre-execution phase. 

3. Vendor Connections and Supply Chain Access 

Manufacturers rarely operate alone. Suppliers, contractors, logistics providers, and software vendors can all connect to corporate environments. 

Attackers may compromise a smaller vendor with weaker defenses and use that trusted relationship to reach a larger target, a technique commonly known as island hopping. 

A shared credential, remote connection, vulnerable integration, or compromised software update can become one of the most dangerous ransomware initial access methods. 

Organizations therefore need visibility beyond their own infrastructure. Vendor access should be reviewed regularly, unnecessary connections should be removed, and third-party privileges should follow least-privilege principles. 

4. Operational Technology and Industrial Systems 

Manufacturing environments face additional endpoint security blind spots because operational technology (OT) and industrial control systems (ICS) often have long lifecycles and cannot be patched as easily as conventional computers. 

Many industrial systems were designed for reliability rather than modern cybersecurity requirements. Connecting previously isolated systems to corporate networks, cloud platforms and remote-management tools has expanded their attack surface. 

A ransomware attack affecting production systems can disrupt manufacturing lines, robotics, quality controls and logistics. Attackers can also steal product designs, supplier contracts, pricing information, and other intellectual property before encryption. 

Network segmentation, vulnerability monitoring, and strict access controls can reduce the risk while allowing production environments to remain operational. 

5. Phishing and Business Email Accounts 

Phishing remains one of the most effective ransomware initial access methods, but modern campaigns are often highly targeted. 

Attackers may research procurement, finance, and supplier relationships before sending messages that closely resemble legitimate business communications. Once credentials are stolen, attackers can monitor conversations before attempting fraud or using the account to gain further access. 

This activity can remain hidden because the attacker may initially use legitimate credentials rather than obviously malicious software. 

MFA, payment verification, email monitoring, and employee awareness training can reduce exposure. Security teams should also investigate unusual authentication patterns and unexpected account behavior. 

RaaS Makes Endpoint Blind Spots More Dangerous 

Ransomware-as-a-service has lowered the barrier for criminals seeking to conduct sophisticated attacks. Cyble identified 57 new ransomware groups and 27 new extortion groups in 2025, along with more than 350 new ransomware strains. 

Between January and April 2025, global ransomware incidents increased by 86%, with Cl0P accounting for 28% of activity during that period, according to Cyble. 

Double extortion has also become common. Attackers may steal data before encryption and threaten to leak it. Some groups have escalated to triple extortion by adding DDoS attacks or directly contacting victims' customers. 

For organizations with limited security resources, this makes early detection particularly important. 

Conclusion 

Effective ransomware defense starts before encryption begins. Organizations should patch exploited vulnerabilities, enforce MFA, segment networks, and maintain tested backups while continuously monitoring endpoint security blind spots.  

Cyble Titan Endpoint Security combines behavioral detection, threat intelligence from Cyble Vision, and Blaze-AI-powered autonomous response to detect and contain threats before they escalate. See Cyble Titan in action and strengthen endpoint protection today—request a demo

Frequently Asked Questions (FAQs)  

1. What are endpoint security blind spots? 

Endpoint security blind spots are areas where security teams have limited visibility into devices, applications, accounts, or activities. These gaps can allow attackers to establish access and move through an environment before ransomware is detected. 

2. How does ransomware evade detection? 
 
Ransomware can evade detection by using legitimate remote-access tools, stolen credentials, fileless techniques, and vulnerable drivers. Attackers may also remain inactive during the ransomware pre-execution phase to avoid triggering security alerts. 

3. What are common ransomware attack vectors? 

Common ransomware attack vectors include phishing emails, compromised credentials, vulnerable internet-facing systems, remote-access tools, third-party vendors, and exposed operational technology environments. 

4. How can organizations reduce ransomware risks on endpoints? 

Organizations can reduce risk by deploying EDR or advanced endpoint protection, enforcing MFA, applying least-privilege access, patching vulnerabilities, segmenting networks, and continuously monitoring endpoint activity. 

5. How can Cyble Titan help prevent ransomware attacks? 

Cyble Titan combines behavioral detection, next-generation antivirus, endpoint telemetry, and Cyble Vision cyber threat intelligence. Its Blaze AI engine can analyze threats, prioritize alerts, and support automated containment and remediation to help security teams respond faster. 

Media Disclaimer: This blog was compiled from publicly available advisories and open-source security reporting. It is provided for reference purposes only; readers bear full responsibility for their reliance on it. 

The post Endpoint Blind Spots: The 5 Places Ransomware Hides Before It Detonates appeared first on Cyble.

  • ✇Security Affairs
  • Cl0p Targets 40+ Organizations Through PTC Windchill Flaw Pierluigi Paganini
    Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability. Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack many companies, then publish the victims’ names if they refuse to pay. The group claims it has targeted more than 40 organizations through a vulnerability in PTC’s Windchill and FlexPLM platforms, which manufacturers and engineering companies use to manage product and design data. CVE-2026-
     

Cl0p Targets 40+ Organizations Through PTC Windchill Flaw

21 de Agosto de 2026, 04:15

Cl0p claims over 40 organizations fell victim to attacks exploiting a PTC Windchill and FlexPLM vulnerability.

Cl0p is using a familiar strategy again: exploit one flaw in enterprise software to attack many companies, then publish the victims’ names if they refuse to pay. The group claims it has targeted more than 40 organizations through a vulnerability in PTC’s Windchill and FlexPLM platforms, which manufacturers and engineering companies use to manage product and design data.

CVE-2026-12569 (CVSS score of 9.3) is a critical remote code execution (RCE) vulnerability in PTC Windchill PDMlink and PTC FlexPLM. An attacker can exploit this vulnerability through the deserialization of untrusted data. The flaw impacts all CPS versions and Windchill and FlexPLM releases prior to 11.0 M030.

In June, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog.

German police reportedly warned organizations directly that attacks were coming, which tells you the exploitation window here wasn’t exactly subtle to security researchers watching it unfold.

Cl0p group’s tooling for this campaign goes well beyond a basic web shell. Security firm ReliaQuest found the group deployed a custom implant built for full data theft on its own, no additional tools required to actually pull data out once inside.

A class loader like that turns a single web shell into an open-ended backdoor, useful for lateral movement, ransomware deployment, or just quietly sitting there for months.

“ReliaQuest identified the web shell as a fully equipped extortion platform: it maps sensitive vault data, decrypts every credential in the Windchill keystore, and includes a custom Java class loader that lets Clop execute any additional code inside the application process, extending the shell into an unlimited backdoor for follow-on activity such as lateral movement, ransomware, or persistence.” reads the report published by ReliaQuest. “The web shell gives attackers a direct path to credential theft and large-scale data exfiltration, with no additional tooling required. Unlike generic command shells, this implant decrypts credentials, delivers malware, and maps stored files for exfiltration.”

Cl0p’s naming strategy followed its usual slow build. The group initially posted partial company names on its leak site, then switched to full names starting August 12, and the victim count has climbed steadily since. For each organization, the listing includes what type of data got stolen and roughly how much, ranging anywhere from a single gigabyte up to multiple terabytes depending on the target.

The stolen data includes databases, project files, backups, engineering documents, blueprints, diagrams and corporate files, as well as images.

The victim list reads like a cross-section of major manufacturing and industrial names: Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, and Largan Precision, the company that supplies camera lenses for Apple’s devices. Researchers noticed that GE was on the list briefly before quietly disappearing from Cl0p’s site, a move that usually signals either a ransom payment or at least resumed negotiations behind closed doors. Shell, Philips, Fiserv, and GE have all publicly acknowledged awareness of the claims and said they’re investigating, though none has confirmed a significant breach so far.

None of this is a new pattern for Cl0p specifically; it’s the same mass-exploitation-then-extortion model the group has run repeatedly against Oracle E-Business Suite, MOVEit, Cleo, and GoAnywhere over the past few years. What’s different this time is the target: enterprise PLM software sits deep inside manufacturing supply chains, holding the exact kind of engineering data that competitors and nation-states alike would pay real money to see.

If your organization runs Windchill or FlexPLM and hasn’t checked for this specific CVE yet, that’s the item to move to the top of today’s list.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Cl0p )

❌
❌