Blackbyte is a ransomware_group tracked across 14 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed October 31, 2025; most recent activity July 24, 2026.
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
FamousSparrow, a China-aligned APT group, launched a multi-wave cyberespionage campaign against an Azerbaijani oil and gas company from late December 2025 to February 2026. The attackers employed an evolved DLL…
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…
Towne Mortgage Company confirmed a data breach resulting from a ransomware attack detected on June 7, 2025. The breach compromised personal information, including Social Security numbers and financial accounts,…
Oleksii Oleksiyovych Lytvynenko, a 44-year-old Ukrainian national, pleaded guilty to conspiracy to commit wire fraud related to the Conti ransomware operation. This group was responsible for over 1,000 attacks…
Mexico's National Cybersecurity Strategy, initiated in 2017, has seen stalled progress under President Andrés Manuel López Obrador (AMLO). The country faces significant cybersecurity threats, including ransomware,…
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
The Everest ransomware gang has claimed to have stolen 159 GB of data from SIAD Group, a major Italian industrial gas producer. The gang has threatened to publicly release the data within eight days, although SIAD Group…