Interlock is a ransomware_group tracked across 14 threat clusters and 40 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity June 30, 2026.
Russian state-backed hackers from APT28 are actively exploiting a high-severity stored cross-site scripting vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite (ZCS) to target Ukrainian government entities.…
Cisco Systems has disclosed a critical authentication bypass vulnerability, CVE-2026-20093, affecting its Integrated Management Controller (IMC) with a CVSS score of 9.8. This flaw allows unauthenticated remote…
LeakNet, a ransomware group, has adopted new tactics involving ClickFix social engineering and a Deno-based fileless loader. This shift allows them to gain initial access through compromised websites, prompting users to…
A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to…
Two separate ransomware incidents have impacted dental organizations in the U.S. The Qilin ransomware gang claims to have breached 1-800-Dentist, threatening to leak sensitive health data of millions unless a ransom is…
Resilience's recent report reveals that the healthcare sector is facing significant financial losses due to cyber threats, with social engineering accounting for 88% of material losses in the first half of 2025. The…
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…
Kettering Health has notified patients about a ransomware attack that occurred on May 20, 2025, affecting their systems. The attack, carried out by the InterLock ransomware gang, caused a significant technology outage…
Kettering Health, a 14-hospital system, was targeted by the Interlock ransomware group in May 2025, leading to significant disruptions in patient care. As a result of the cyberattack, the organization is now facing 44…
Recent analysis reveals that Rhysida and Interlock ransomware groups are interconnected through a shared ecosystem of malware tools, including the Supper backdoor. Both groups utilize initial access brokers and a…