Medusa is a ransomware_group tracked across 18 threat clusters and 45 intelligence report mentions on ThreatCluster. First observed November 10, 2025; most recent activity July 16, 2026.
In January 2026, the Chronus Group executed a significant data breach against the Mexican government, compromising 2.3 terabytes of sensitive data from at least 25 agencies. The breach exposed personal information of up…
A new Android malware named Perseus has been identified, actively targeting user notes to extract sensitive information such as passwords and financial data. Distributed via unofficial app stores disguised as IPTV…
Kaspersky's research reveals that The Gentlemen ransomware group, active since mid-2025, is expanding its operations with new custom-built malware tools. This group targets various industries, including healthcare and…
Resilience's recent report reveals that the healthcare sector is facing significant financial losses due to cyber threats, with social engineering accounting for 88% of material losses in the first half of 2025. The…
Cryptocurrency theft operations have evolved into structured underground services known as Drainer-as-a-Service (DaaS). These services rely on social engineering tactics to lure victims to fake crypto-related websites,…
Microsoft has identified a new cybercriminal group, Storm-1175, responsible for swift Medusa ransomware attacks targeting the healthcare and education sectors in the UK, US, and Australia. The group exploits zero-day…
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
Kaspersky's 2026 report indicates a decline in ransomware incidents, yet the threat remains significant. Attackers are increasingly using EDR killers and BYOVD techniques to bypass security measures. The PE32 ransomware…
In 2025, ransomware groups Medusa and DragonForce targeted UK organizations by exploiting three critical vulnerabilities in the SimpleHelp Remote Monitoring and Management platform. These vulnerabilities…
In 2025, ransomware groups Medusa and DragonForce targeted UK organizations by exploiting vulnerabilities in the SimpleHelp Remote Monitoring and Management platform. They leveraged three critical vulnerabilities…